Independent DIB implementation resource — not affiliated with or endorsed by the U.S. Department of WarView the official DoW campaign ↗
BRILLIANT AT THE BASICS · CLOUD SETUPGoogle Workspace
Productivity Suite

Key Settings One-Pager

The essential goal, the features that carry it, the mistake to avoid, and the proof to keep — for each of the ten Brilliant at the Basics requirements. A quick reference to pin up, not a substitute for the full step-by-step guide. Confirm every setting against Google Workspace’s own documentation.

Where you work
Google Admin console (admin.google.com)
Content reviewed
2026-07-21
Before you store CUI here

Handling CUI in Workspace requires Assured Controls and careful scoping. Confirm an authorization path before you store CUI.

01

Phishing-Resistant Multi-Factor Authentication

IT-013.5.3IA.L2-3.5.3

Make a stolen password useless on its own.

Configure in
2-Step VerificationSecurity keysPasskeysOrganizational units
Don’t miss

Register at least two keys per admin (one primary, one backup) so a lost key never locks you out of the whole tenant.

Evidence to keep

2-Step Verification enrollment report · Screenshot of 'Only security key' policy on Admins OU · List of issued security keys/passkeys

02

Least-Privilege Access Control

3.1.5AC.L2-3.1.5

Give each person only the access their job needs — and no more.

Configure in
Admin rolesOrganizational unitsDelegated admin (custom roles)Directory
Don’t miss

Never use a Super Admin account for daily email or browsing; keep it separate and use it only when a task truly requires it.

Evidence to keep

List of admin role assignments · Custom role definitions with privileges · Quarterly access review record

03

Asset & Account Inventory

IT-023.4.1CM.L2-3.4.1

Keep a live list of every device, identity, and app you defend.

Configure in
Endpoint managementDevices inventoryDirectory (Users)Connected apps / API controls
Don’t miss

Set third-party app access to 'blocked by default' and only allow apps you've reviewed, so shadow apps can't quietly connect.

Evidence to keep

Exported device inventory (dated) · User account list · Connected/third-party app report

04

Logging, Monitoring & Audit

3.3.1AU.L2-3.3.1

Record important events and watch for trouble.

Configure in
Audit and investigationSecurity center (Investigation tool)Alert centerBigQuery Export
Don’t miss

Enterprise-tier features unlock the full Security Center and Investigation tool; confirm your edition before promising an auditor those capabilities.

Evidence to keep

BigQuery log export configuration · Alert center rules and history · Weekly log-review records

05

Network Segmentation & Boundary Protection

IT-053.13.5SC.L2-3.13.5

Keep one compromised thing from reaching everything else.

Configure in
Context-Aware AccessAccess levelsIP allowlistsOrganizational units
Don’t miss

Test in monitor mode first; enforcing an IP or device rule cold can lock you out of your own Admin console.

Evidence to keep

Context-Aware Access level definitions · App assignment screenshots · Blocked-access log entries

06

Vulnerability & Patch Management

IT-063.11.2RA.L2-3.11.2

Find weak spots and fix the risky ones first.

Configure in
Chrome managementChromeOS auto-updateManaged Chrome browser updatesSecurity health page
Don’t miss

Don't pin devices to an old Chrome version 'for stability'; that leaves known security holes open far longer than any bug is worth.

Evidence to keep

Chrome/ChromeOS update policy settings · Managed browser version report · Security health page results

07

Data Protection & Encryption

3.13.11SC.L2-3.13.11

Scramble sensitive data so only the right people can read it.

Configure in
Client-side encryption (CSE)Encryption at rest and in transitExternal key service (KACLS)S/MIME for Gmail
Don’t miss

You control the CSE keys, so guard the key service carefully; if you lose those keys, the encrypted data is gone for good.

Evidence to keep

CSE key service configuration · List of OUs/apps with CSE enabled · Sample encrypted Drive file

08

Backup & Recovery

IT-093.8.9MP.L2-3.8.9

Be able to restore your data after an attack or outage.

Configure in
Google VaultRetention rulesHoldsVault exports / Takeout / third-party backup
Don’t miss

Vault retention is not the same as a true backup; keep an independent copy so a compromised admin can't destroy both the data and its history.

Evidence to keep

Vault retention rule configuration · Successful test export record · Multi-party approval setting screenshot

09

Secure Configuration Baseline

3.4.2CM.L2-3.4.2

Start every service from a known-good, hardened setting.

Configure in
Security center (Security dashboard/health)Recommended settingsOrganizational unitsAlert center
Don’t miss

Save your baseline as a dated document; 'it was set correctly' means nothing to an auditor without proof of what 'correct' is.

Evidence to keep

Security health page screenshot · Written configuration baseline document · Change/drift alert settings

10

Secure AI Adoption & Data Loss Prevention

IT-083.1.3AC.L2-3.1.3

Use AI and share files without leaking sensitive information.

Configure in
Data protection (DLP) rulesGemini data controlsClient-side encryptionInformation rights management (IRM)
Don’t miss

Start DLP rules in audit mode to avoid blocking legitimate work; only flip to enforce after you've reviewed and tuned the false positives.

Evidence to keep

DLP rule definitions for Drive and Gmail · Gemini data-access configuration · DLP incident/audit report

This one-pager is independent education from the Brilliant at the Basics Resource Center, published by inDirectIT. It is a condensed reference — the full guide has the click-by-click steps. It does not by itself establish compliance, satisfy a contract clause, or confer CMMC certification. Cloud consoles change often — verify each setting against the provider’s documentation. The official DoW campaign remains authoritative: https://dowcio.war.gov/BrilliantBasics/