Independent DIB implementation resource — not affiliated with or endorsed by the U.S. Department of WarView the official DoW campaign ↗
Cloud InfrastructurePLAIN-LANGUAGE GUIDE

Google Cloud setup guide

Google's rent-by-the-hour compute, storage, and networking. Work through the ten requirements below — each has a diagram and a checklist you can follow click by click.

Print checklist ↧
Before you store CUI here

For CUI, deploy inside Assured Workloads with the correct US government / Impact Level compliance regime.

REQUIREMENT 01 OF 10

Phishing-Resistant Multi-Factor Authentication

IT-013.5.3IA.L2-3.5.3
IN PLAIN WORDS

Multi-factor authentication (MFA) means you need two things to log in: a password and a second proof it's really you. Phishing-resistant MFA uses a physical security key or a passkey that a fake website can't trick or copy. It's like a house that needs both a key and a special fingerprint scanner, so a stolen key alone won't get a thief inside.

WHY IT MATTERS

Passwords get stolen or guessed all the time, and without a strong second factor an attacker who has a password can walk right into your defense contractor's cloud.

TOOLS YOU WILL USE
Cloud IdentityGoogle Admin consoleTitan Security Key2-Step Verification
HOW THE SETUP FLOWS
  1. 1Open Admin console
  2. 2Turn on 2SV
  3. 3Require security keys
  4. 4Register Titan keys
  5. 5Enforce for admins
STEP-BY-STEP CHECKLIST
Pro tip

Register a backup security key for every user before you enforce, or a single lost key can lock someone out of the whole account.

Government cloud & CUI

For CUI and ITAR work, run identities in an Assured Workloads environment and enforce phishing-resistant 2SV, since FedRAMP High and DoD IL4/IL5 require strong multi-factor authentication.

EVIDENCE TO KEEP
Screenshot of 2-Step Verification enforcement settingList of users with security keys enrolledAdmin console audit log of the policy change
See the full IT-01 practice guide →
FAQ

Frequently asked questions

What does the Google Cloud setup guide cover?

It walks through ten security requirements — including phishing-resistant multi-factor authentication, least-privilege access control, asset & account inventory, and more — mapped to the DoW Brilliant at the Basics IT Top 10 and to NIST SP 800-171 / CMMC Level 2. Each requirement has a plain-language explanation, a process-flow diagram, and a click-by-click checklist.

Where do I perform these GCP steps?

In the Google Cloud console (console.cloud.google.com). Every step names the exact portal or console path to follow.

Is my checklist progress saved anywhere?

Your step checklist progress is saved only in your own browser (local storage). Nothing is sent to the site, and you can reset it at any time.

How do I handle CUI in Google Cloud?

Deploy inside Assured Workloads with the appropriate US government / Impact Level compliance regime, so data location and personnel access stay within the compliant boundary.

Does Google Cloud encrypt data by default?

Yes. Google Cloud encrypts all data at rest by default; use Cloud KMS customer-managed encryption keys (CMEK) to add your own key control for sensitive workloads.