Independent DIB implementation resource — not affiliated with or endorsed by the U.S. Department of WarView the official DoW campaign ↗

Resource Library

In-depth knowledge base articles plus authoritative DoW, NIST, CISA, NSA, DC3, and Project Spectrum sources — identified, dated, and linked to the original publisher.

KNOWLEDGE BASE

In-depth articles

Independent, plain-language explainers on the standards and controls behind the Top 10.

Browse the knowledge base →
Identity & Authentication8 MIN READ

Replay-Resistant vs. Phishing-Resistant Authentication

Replay-resistant and phishing-resistant are different security properties — and phishing-resistant is stronger. Replay resistance is a numbered control in both NIST SP 800-171 Rev 2 (3.5.4) and Rev 3 (03.05.04); phishing-resistant is defined in SP 800-63B and mandated by OMB M-22-09, not by a base 800-171 control.

UPDATED 2026-07-21Read the article →
Compliance Frameworks9 MIN READ

CMMC vs. NIST SP 800-171: What’s the Difference?

NIST SP 800-171 is the security control set for protecting CUI; CMMC is the DoD program that verifies you actually implemented it. Level 2 CMMC is the same 110 requirements from 800-171 Rev 2 — the difference is who checks, how often, and what proof is required.

UPDATED 2026-07-21Read the article →
Incident Response & DFARS8 MIN READ

DFARS 7012’s 72-Hour Rule: What It Actually Requires

DFARS 252.204-7012 requires contractors to report a discovered cyber incident to DoD within 72 hours via DIBNet, preserve affected media for at least 90 days, and submit malicious software to DC3 — plus flow the clause down to subcontractors. The report itself is only part of the obligation.

UPDATED 2026-07-21Read the article →
Cloud & Architecture9 MIN READ

GCC High vs. Commercial Microsoft 365: Do You Actually Need It?

GCC High is Microsoft 365 in a US-sovereign, screened-US-persons cloud with FedRAMP High and DoD IL4/IL5 authorization. You need it for ITAR/export-controlled data and CUI Specified; Commercial or GCC may suffice for lighter CUI — but confirm with your prime. It costs more and migration is a real project.

UPDATED 2026-07-21Read the article →
Getting Started6 MIN READ

The Top Mistakes DIB Teams Make When Starting the Basics

Most Top 10 programs don't fail on hard technology — they stall on avoidable patterns: boiling the ocean, mistaking 'we bought it' for 'it works,' and never testing recovery. Here are the common mistakes DIB teams make starting out, and the simple fixes.

UPDATED 2026-07-21Read the article →
Getting Started5 MIN READ

What Good Looks Like: The IT Top 10 at a Glance

A high-level 'done looks like' for each IT Top 10 practice — the validation test that shows a control actually works, not just that it was purchased. Use it as a quick self-check, then open the full guides for the how-to.

UPDATED 2026-07-21Read the article →
Scoping & Architecture14 MIN READ

Scoping Your CUI Boundary: Discovery Methods, Remediation Paths, and the Numbers That Decide

Scope size is the master cost driver in a CMMC Level 2 program — it sets how many premium licenses you pay for, how big your assessment is, and how much CUI you're liable for. How you find your CUI (a top-down traceability cascade, staff interviews, or automated digital discovery) determines how accurately you can size the boundary, and four remediation paths — surgical file cleanup, a user-account enclave, program segmentation, or enterprise migration — are chosen mostly by two ratios: what share of users touch CUI, and how sprawled it already is.

UPDATED 2026-07-21Read the article →
Cloud & Architecture10 MIN READ

What Should a GCC High Migration Cost?

A GCC High migration priced honestly has three parts: a fixed base to stand up and harden the environment (around $15,500), migration tooling like AvePoint (there is no native commercial-to-GCC-High path), and roughly $250 per user to move and validate mail, files, and Teams. Total ≈ $15,500 + tooling + ($250 × users). The cost nobody quotes correctly is the risk in the mapping and cutover — get those wrong and you pay again in spillage, broken permissions, and downtime.

UPDATED 2026-07-21Read the article →
Cloud & Architecture9 MIN READ

Windows Pro vs. Enterprise for NIST 800-171 Rev 3: The Endpoint Parity Gap

For NIST 800-171 Rev 3, the endpoint controls quietly require Windows Enterprise. Rev 3 sharpened application allowlisting (03.04.08), and the licensed, manageable engine — AppLocker — needs a Windows Enterprise E3/E5 or Education license; Pro isn't entitled. App Control for Business (WDAC) runs on Pro but is the harder engine and no substitute for the rest: Credential Guard (Enterprise-only), Defender for Endpoint EDR (E5), and more. In GCC High, getting those Enterprise licenses onto devices is partner-mediated and portal-fragmented.

UPDATED 2026-07-21Read the article →
SOURCE REGISTRY

Authoritative sources

Official campaign, framework, and program links — each with its publisher, provenance, and most recent verification date.

9 RESOURCES

DoD Zero Trust Strategy

The department-level target architecture that the IT Top 10 supports.

OFFICIAL SOURCEITDoD CIO · Strategy · IT-01 IT-05

Project Spectrum

No-cost cybersecurity readiness resources for DIB small businesses.

OFFICIAL SOURCEITOTDoW OSBP · Program · IT-10

Teramis — Automated CUI Discovery

A commercial tool that automatically discovers and continuously monitors CUI across files and endpoints — including formats many scanners miss, like CAD drawings, PDFs, and scanned images — and flags CUI that has drifted outside its authorized boundary. Useful for the digital-discovery step of scoping.

VENDOR TOOLITTeramis · Tool · IT-02