Independent DIB implementation resource — not affiliated with or endorsed by the U.S. Department of WarView the official DoW campaign ↗
CHECKLIST · IT / OTv1.0 · REVIEWED 2026-07-28

Brilliant at the Basics 20-Practice Executive Checklist

Brilliant at the Basics Resource Center · brilliantatthebasics.us · published by inDirectIT, Inc.

Independent educational material. Not affiliated with, sponsored by, approved by, or endorsed by the U.S. Department of War. Does not establish compliance, certification, or contractual standing.

Purpose

A single sheet an executive can carry into a review: all twenty practices in the order we recommend tackling them, who should own each one, roughly what it costs in effort, and the one question that separates real implementation from a purchase order.

How to use it

Read down the sequence column. For each practice, ask the question in the final column and score the answer against the maturity ladder. Anything below 'Deployed' is not yet protecting you; anything below 'Measured' cannot be reported honestly.

The maturity ladder

Use the same ladder for every practice so scores are comparable across the programme.

Score each practice against this ladder. The distinction that matters most is between having a tool, deploying it to the correct scope, and operating it consistently.

LevelNameWhat it meansThe question that separates it from the level below
0AbsentThe capability does not exist in any form.Is there anything at all — a tool, a document, a person who owns it?
1DocumentedIntent exists on paper. Deployment has not happened or is incomplete.Is the intent written down, with a named owner and a scope?
2ConfiguredThe technology or process is configured, but not yet applied to the intended scope.Is it switched on and set up somewhere — even if only in part of the estate?
3DeployedIt is applied across the scope it was meant to cover.Does it cover everything in scope, with the exceptions written down?
4OperatingIt functions consistently during normal operations, not only when someone is watching.Does it keep working through a normal month without manual rescue?
5MeasuredCoverage and effectiveness are measured, monitored, and exception-handled.Can you state a number for coverage or effectiveness, and show the trend?
6GovernedOwnership, scheduled review, continuous improvement, and evidence retention are established.Is there an accountable owner, a review cadence, and retained evidence?

All twenty practices, in recommended sequence

Official campaign numbering is authoritative. This ordering is the Resource Center's independent recommendation for resource-constrained teams and carries no official status.

#PracticeTrackStageSuggested ownerEffortThe question to ask
1IT-01 — Phishing-resistant MFAIT1 · Know and controlIdentity administratorMediumCan we state a number for phishing-resistant coverage — privileged?
2IT-02 — Asset inventoryIT1 · Know and controlIT leaderMediumCan we state a number for managed coverage?
3OT-01 — OT identity and access controlOT1 · Know and controlPlant / OT leaderMediumCan we state a number for devices on default credentials?
4OT-02 — Validated OT asset inventoryOT1 · Know and controlPlant / OT leaderMediumCan we state a number for walk-down coverage?
5IT-05 — Logical segmentationIT2 · Contain compromiseNetwork administratorHighCan we state a number for any-any rules?
6OT-03 — OT network segmentationOT2 · Contain compromiseOT / network administratorHighCan we state a number for unbrokered it-to-ot paths?
7OT-06 — OT remote access pathwaysOT2 · Contain compromiseOT / network administratorMediumCan we state a number for brokered access share?
8IT-03 — Technical debt reductionIT3 · Reduce exposureIT leaderHighCan we state a number for unsupported systems in production?
9IT-06 — Risk-based vulnerability managementIT3 · Reduce exposureIT leader / MSPMediumCan we state a number for scan coverage?
10OT-05 — OT vulnerability managementOT3 · Reduce exposureOT engineerMediumCan we state a number for high-risk findings addressed?
11IT-09 — Backup and disaster recoveryIT4 · Recover operationsIT leaderMediumCan we state a number for backup coverage?
12OT-04 — OT incident response and recoveryOT4 · Recover operationsPlant / OT leaderMediumCan we state a number for plan currency?
13OT-08 — OT system resiliencyOT4 · Recover operationsPlant / OT leaderHighCan we state a number for controller backup coverage?
14IT-04 — Flexible technology stackIT5 · Engineer securelyIT leaderMediumCan we state a number for baseline coverage?
15IT-07 — Security in the development lifecycleIT5 · Engineer securelyEngineering leadMediumCan we state a number for pipeline gate coverage?
16IT-08 — Secure AI adoptionIT5 · Engineer securelyEngineering leadMediumCan we state a number for sanctioned-tool share?
17OT-09 — OT supply chain securityOT5 · Engineer securelyProcurement + OTMediumCan we state a number for agreements with security terms?
18OT-10 — OT change reviewOT5 · Engineer securelyPlant / OT leaderLowCan we state a number for reviewed change rate?
19IT-10 — Technical workforce readinessIT6 · Sustain performanceExecutive sponsorLowCan we state a number for single-person dependencies?
20OT-07 — OT continuous monitoringOT6 · Sustain performanceOT engineerMediumCan we state a number for monitored zone coverage?

Limitations

Brilliant at the Basics 20-Practice Executive Checklist · version 1.0 · reviewed 2026-07-28 · file name batb-20-practice-executive-checklist

Generated from IT Top 10, OT Top 10 at brilliantatthebasics.us. The live pages carry the current version of this guidance.

Independent educational material published by inDirectIT, Inc. Not affiliated with, sponsored by, approved by, or endorsed by the U.S. Department of War. Cybersecurity practices must be tailored to each organization’s technical, operational, contractual, regulatory, and safety requirements.

All downloads

Printing produces a paginated document. Choose “Save as PDF” in the print dialog and name it batb-20-practice-executive-checklist to keep filenames consistent across your team.