Independent DIB implementation resource — not affiliated with or endorsed by the U.S. Department of WarView the official DoW campaign ↗
BRIEFING · IT / OTv1.0 · REVIEWED 2026-07-28

Executive / Board Briefing One-Pager

Brilliant at the Basics Resource Center · brilliantatthebasics.us · published by inDirectIT, Inc.

Independent educational material. Not affiliated with, sponsored by, approved by, or endorsed by the U.S. Department of War. Does not establish compliance, certification, or contractual standing.

Purpose

A briefing for a board or leadership team that has heard 'Brilliant at the Basics' and needs to know what it is, what it obliges, and what to ask for.

How to use it

Read the first two sections aloud if you need to settle a room. Use the questions section as the agenda for a thirty-minute review with whoever runs IT and operations.

What it is

Brilliant at the Basics is a U.S. Department of War CIO campaign that names ten information-technology and ten operational-technology cybersecurity practices as priorities for the Defense Industrial Base. It is a statement of priority and emphasis — a clear signal about where the department believes attention belongs.

What it is not

It is not, by itself, a contract clause, a certification, or a substitute for NIST SP 800-171, DFARS 252.204-7012, or CMMC obligations. Implementing the twenty practices does not make an organization compliant with any of those, and no part of this briefing should be represented as saying otherwise. Your obligations come from your contracts.

QuestionHonest answer
Is this contractually required?Not in itself. Verify what your contracts and flowdowns actually require.
Does implementing it make us CMMC compliant?No. It contributes to several requirements and provides evidence relevant to others.
Does it replace a System Security Plan?No. An SSP describes your system and how each requirement is met; this is a priority list.
Is it still worth doing?Yes. These are the practices that reduce the most risk for the least money in most DIB environments.

The six-stage sequence

Official numbering is authoritative. This is the Resource Center's independent recommendation for the order in which resource-constrained teams should attempt the work.

StageNameWhy it comes herePractices
1Know and controlSee every identity and asset you defend.IT-01, IT-02, OT-01, OT-02
2Contain compromiseKeep one breached device from becoming ten.IT-05, OT-03, OT-06
3Reduce exposureClose the gaps attackers reach first.IT-03, IT-06, OT-05
4Recover operationsProve you can restore before you need to.IT-09, OT-04, OT-08
5Engineer securelyBuild new capability without new risk.IT-04, IT-07, IT-08, OT-09, OT-10
6Sustain performanceKeep your people and monitoring sharp.IT-10, OT-07

Questions worth asking

  • Which of the twenty practices do we consider deployed, and what is the evidence?
    • 'We bought the tool' is not an answer. 'Here is the coverage number and the last validation result' is.
  • What is our phishing-resistant MFA coverage for privileged accounts, as a number?
  • When did we last restore a critical system from backup, and how long did it take?
  • Can a compromised laptop on the office network reach production or our sensitive data?
  • Who is accountable for each practice — by name, not by department?
  • Which of these are we paying a service provider to do, and who retains the evidence?
  • What would we not be able to recover from today?

Limitations

Executive / Board Briefing One-Pager · version 1.0 · reviewed 2026-07-28 · file name batb-executive-briefing-one-pager

Generated from Home, About and independence at brilliantatthebasics.us. The live pages carry the current version of this guidance.

Independent educational material published by inDirectIT, Inc. Not affiliated with, sponsored by, approved by, or endorsed by the U.S. Department of War. Cybersecurity practices must be tailored to each organization’s technical, operational, contractual, regulatory, and safety requirements.

All downloads

Printing produces a paginated document. Choose “Save as PDF” in the print dialog and name it batb-executive-briefing-one-pager to keep filenames consistent across your team.