Independent DIB implementation resource — not affiliated with or endorsed by the U.S. Department of WarView the official DoW campaign ↗
BRILLIANT AT THE BASICS · CLOUD SETUPGoogle Cloud
Cloud Infrastructure

Key Settings One-Pager

The essential goal, the features that carry it, the mistake to avoid, and the proof to keep — for each of the ten Brilliant at the Basics requirements. A quick reference to pin up, not a substitute for the full step-by-step guide. Confirm every setting against Google Cloud’s own documentation.

Where you work
Google Cloud console (console.cloud.google.com)
Content reviewed
2026-07-21
Before you store CUI here

For CUI, deploy inside Assured Workloads with the correct US government / Impact Level compliance regime.

01

Phishing-Resistant Multi-Factor Authentication

IT-013.5.3IA.L2-3.5.3

Make a stolen password useless on its own.

Configure in
Cloud IdentityGoogle Admin consoleTitan Security Key2-Step Verification
Don’t miss

Register a backup security key for every user before you enforce, or a single lost key can lock someone out of the whole account.

Evidence to keep

Screenshot of 2-Step Verification enforcement setting · List of users with security keys enrolled · Admin console audit log of the policy change

02

Least-Privilege Access Control

3.1.5AC.L2-3.1.5

Give each person only the access their job needs — and no more.

Configure in
Cloud IAMIAM RecommenderService AccountsOrganization Policy Service
Don’t miss

Avoid the basic Owner and Editor roles for daily work; they are huge and are the most common cause of over-privileged accounts.

Evidence to keep

Export of IAM policy bindings per project · IAM Recommender history showing applied changes · Organization policy report on service account key constraints

03

Asset & Account Inventory

IT-023.4.1CM.L2-3.4.1

Keep a live list of every device, identity, and app you defend.

Configure in
Cloud Asset InventoryResource ManagerIAM & Admin
Don’t miss

The console only shows the RESOURCE view; use the gcloud CLI or an export if you need IAM policy or deeper details for a full audit.

Evidence to keep

Exported asset list from Asset Inventory · Resource Manager hierarchy diagram or screenshot · List of all user and service accounts

04

Logging, Monitoring & Audit

3.3.1AU.L2-3.3.1

Record important events and watch for trouble.

Configure in
Cloud LoggingCloud Audit LogsSecurity Command CenterLogs Explorer
Don’t miss

Data Access audit logs are off by default; many teams think everything is logged and only find out otherwise during an incident.

Evidence to keep

Screenshot of enabled Data Access audit log config · Log Router sink pointing to retained storage · Security Command Center findings report

05

Network Segmentation & Boundary Protection

IT-053.13.5SC.L2-3.13.5

Keep one compromised thing from reaching everything else.

Configure in
Virtual Private Cloud (VPC)VPC firewall rulesVPC Service ControlsShared VPC
Don’t miss

Always run a new VPC Service Controls perimeter in dry-run mode first; enforcing it blind can suddenly break legitimate access.

Evidence to keep

VPC and subnet configuration export · Firewall rule list showing default-deny · VPC Service Controls perimeter configuration

06

Vulnerability & Patch Management

IT-063.11.2RA.L2-3.11.2

Find weak spots and fix the risky ones first.

Configure in
VM ManagerSecurity Command CenterArtifact AnalysisOS Config
Don’t miss

Findings appear only after the OS Config agent is running; a VM without the agent looks 'clean' simply because nothing is checking it.

Evidence to keep

VM Manager vulnerability report export · Patch deployment job history · Security Command Center findings list with remediation status

07

Data Protection & Encryption

3.13.11SC.L2-3.13.11

Scramble sensitive data so only the right people can read it.

Configure in
Cloud Key Management Service (KMS)CMEKCloud StorageTLS
Don’t miss

Your KMS key ring must be in the same location as the data it protects, or you won't be able to attach it to that resource.

Evidence to keep

Cloud KMS key ring and key configuration · Resource settings showing CMEK enabled · Key rotation schedule record

08

Backup & Recovery

IT-093.8.9MP.L2-3.8.9

Be able to restore your data after an attack or outage.

Configure in
Backup and DR ServiceBackup vaultsCompute Engine snapshotsPersistent Disk
Don’t miss

A backup you have never restored is only a hope; schedule real restore tests so you find problems before a disaster does.

Evidence to keep

Backup plan and vault configuration · Snapshot schedule showing recent successful backups · Documented restore test results

09

Secure Configuration Baseline

3.4.2CM.L2-3.4.2

Start every service from a known-good, hardened setting.

Configure in
Security Command CenterOrganization Policy ServiceAssured WorkloadsSecurity Health Analytics
Don’t miss

Turn on new org policy constraints in a test folder first; a strict constraint can unexpectedly block legitimate deployments across projects.

Evidence to keep

Security posture definition and compliance report · Organization policy constraint settings · Security Health Analytics findings showing resolved items

10

Secure AI Adoption & Data Loss Prevention

IT-083.1.3AC.L2-3.1.3

Use AI and share files without leaking sensitive information.

Configure in
Sensitive Data ProtectionVertex AIVPC Service ControlsCloud Audit Logs
Don’t miss

De-identify data before it reaches the model, not after; once sensitive text is in a prompt or training set it is very hard to pull back out.

Evidence to keep

Sensitive Data Protection scan results and de-id templates · VPC Service Controls perimeter covering Vertex AI · Vertex AI audit logs and written AI use policy

This one-pager is independent education from the Brilliant at the Basics Resource Center, published by inDirectIT. It is a condensed reference — the full guide has the click-by-click steps. It does not by itself establish compliance, satisfy a contract clause, or confer CMMC certification. Cloud consoles change often — verify each setting against the provider’s documentation. The official DoW campaign remains authoritative: https://dowcio.war.gov/BrilliantBasics/