Search the resource center
Practice guides, knowledge base articles, cloud setup steps, downloads, framework mappings, official sources, and policy updates — 224 records, filtered in your browser.
- PRACTICE GUIDEReviewed
IT-01 — Phishing-Resistant Multi-Factor Authentication (MFA)
Passwords alone are not enough. Phishing-resistant MFA — FIDO2 security keys, platform passkeys, or PIV — removes the shared secret an attacker can steal. Start with privileged and remote-access accounts, then expand…
- PRACTICE GUIDEReviewed
IT-02 — Comprehensive Asset Inventory Management
You defend what you can see. A comprehensive inventory covers hardware, cloud and on-prem software, and — increasingly — identities and service accounts. Build it from authoritative sources, reconcile the sources…
- PRACTICE GUIDEReviewed
IT-03 — Strategic Technical Debt Reduction
Technical debt is a security liability. End-of-life operating systems, unpatched appliances, and legacy protocols are the footholds adversaries count on you keeping. Treat retirement as a planned program: find the…
- PRACTICE GUIDEReviewed
IT-04 — Flexible Technology Stack
Lock-in is a risk multiplier. A flexible stack — built on documented baselines, standard interfaces, and portable data — lets you replace a weak or end-of-life component without re-architecting the business. The goal…
- PRACTICE GUIDEReviewed
IT-05 — Logical Segmentation to Limit Adversary Lateral Movement
A flat network turns one compromised laptop into access to everything. Logical segmentation — VLANs, host firewalls, identity-based access, and separated management planes — breaks the network into zones so an…
- PRACTICE GUIDEReviewed
IT-06 — Risk-Based Vulnerability Management
You will never fix every vulnerability, so fix the ones that matter first. Risk-based vulnerability management pairs regular scanning with prioritization by exploitability and exposure — known-exploited…
- PRACTICE GUIDEReviewed
IT-07 — Integrate Security Early in the Development Lifecycle
Security bolted on at the end is expensive and leaky. Building it in — threat modeling, secure coding standards, automated testing in the pipeline, dependency and secret scanning, and reviewed changes — catches…
- PRACTICE GUIDEReviewed
IT-08 — Secure AI Adoption and Data Protection
AI is entering the workplace whether you plan for it or not. Secure adoption means deciding — before staff paste data into a chatbot — which tools are approved, what data may and may not go into them, and how AI use…
- PRACTICE GUIDEReviewed
IT-09 — Resilient Backup and Disaster Recovery Architecture
Ransomware assumes your backups fail. A resilient architecture keeps at least one copy offline or immutable, protects backups with separate credentials and MFA, and — most importantly — proves recovery by testing…
- PRACTICE GUIDEReviewed
IT-10 — Continuous Technical Workforce Readiness
Tools do not defend anything on their own — people operate them. Continuous readiness means role-based training for the staff who run identity, endpoints, cloud, and response; hands-on exercises that build muscle…
- PRACTICE GUIDEReviewed — pending SME sign-off
OT-01 — Identity and Access Control
OT access is often shared logins, default passwords, and standing vendor accounts nobody tracks. Bringing identity and access control to production means unique accountability, least privilege, controlled use of…
- PRACTICE GUIDEReviewed — pending SME sign-off
OT-02 — Validated Asset Inventory
You cannot protect equipment you have not counted. A validated OT inventory is built passively, confirmed by physical walk-downs, and maintained through change control — not by scanning fragile devices.
- PRACTICE GUIDEReviewed — pending SME sign-off
OT-03 — Strict Network Segmentation
The single most valuable OT control is keeping the plant network separate from the business network. Strict segmentation uses zones and conduits, a controlled boundary (ideally a DMZ) between IT and OT, and…
- PRACTICE GUIDEReviewed — pending SME sign-off
OT-04 — OT-Specific Incident Response and Recovery Plan
An IT incident-response plan does not fit the plant. OT response has to weigh safety and physical process first, involve engineers and operators alongside IT, and account for the reality that you may run degraded or…
- PRACTICE GUIDEReviewed — pending SME sign-off
OT-05 — Manage Known Vulnerabilities
You cannot patch OT like IT. Many devices can only be updated during rare maintenance windows, run vendor-certified firmware, or cannot be taken down at all. Managing known vulnerabilities in OT means knowing what…
- PRACTICE GUIDEReviewed — pending SME sign-off
OT-06 — Remote Access Pathways
Remote access is how vendors keep equipment running — and how attackers get to the plant floor. The safe pattern is brokered access: connections pass through a controlled jump host in a DMZ, require strong…
- PRACTICE GUIDEReviewed — pending SME sign-off
OT-07 — Continuous Monitoring
You cannot respond to what you cannot see. OT monitoring is built passively — from network taps and SPAN ports, not agents on fragile devices — to baseline normal traffic and flag the abnormal: new devices,…
- PRACTICE GUIDEReviewed — pending SME sign-off
OT-08 — System Resiliency
Resiliency is the ability to keep operating, or return quickly, when something fails — whether a disk, a controller, or an attack. In OT that means backups of controller logic and configurations, spares and…
- PRACTICE GUIDEReviewed — pending SME sign-off
OT-09 — Supply Chain Security
Every vendor, integrator, and component is a path into your environment. OT supply-chain security means knowing who your critical suppliers are, setting security expectations in agreements, checking equipment and…
- PRACTICE GUIDEReviewed — pending SME sign-off
OT-10 — Review Processes
In OT, an unreviewed change can trip a process or open a security hole — and the two concerns are inseparable. A change-review process ensures every modification to control systems, network, or configuration is…
- KNOWLEDGE BASE
Replay-Resistant vs. Phishing-Resistant Authentication
Replay-resistant and phishing-resistant are different security properties — and phishing-resistant is stronger. Replay resistance is a numbered control in both NIST SP 800-171 Rev 2 (3.5.4) and Rev 3 (03.05.04);…
- KNOWLEDGE BASE
CMMC vs. NIST SP 800-171: What’s the Difference?
NIST SP 800-171 is the security control set for protecting CUI; CMMC is the DoD program that verifies you actually implemented it. Level 2 CMMC is the same 110 requirements from 800-171 Rev 2 — the difference is who…
- KNOWLEDGE BASE
DFARS 7012’s 72-Hour Rule: What It Actually Requires
DFARS 252.204-7012 requires contractors to report a discovered cyber incident to DoD within 72 hours via DIBNet, preserve affected media for at least 90 days, and submit malicious software to DC3 — plus flow the…
- KNOWLEDGE BASE
GCC High vs. Commercial Microsoft 365: Do You Actually Need It?
GCC High is Microsoft 365 in a US-sovereign, screened-US-persons cloud with FedRAMP High and DoD IL4/IL5 authorization. You need it for ITAR/export-controlled data and CUI Specified; Commercial or GCC may suffice for…
- KNOWLEDGE BASE
The Top Mistakes DIB Teams Make When Starting the Basics
Most Top 10 programs don't fail on hard technology — they stall on avoidable patterns: boiling the ocean, mistaking 'we bought it' for 'it works,' and never testing recovery. Here are the common mistakes DIB teams…
- KNOWLEDGE BASE
What Good Looks Like: The IT Top 10 at a Glance
A high-level 'done looks like' for each IT Top 10 practice — the validation test that shows a control actually works, not just that it was purchased. Use it as a quick self-check, then open the full guides for the…
- KNOWLEDGE BASE
Scoping Your CUI Boundary: Discovery Methods, Remediation Paths, and the Numbers That Decide
Scope size is the master cost driver in a CMMC Level 2 program — it sets how many premium licenses you pay for, how big your assessment is, and how much CUI you're liable for. How you find your CUI (a top-down…
- KNOWLEDGE BASE
What Should a GCC High Migration Cost?
A GCC High migration priced honestly has three parts: a fixed base to stand up and harden the environment (around $15,500), migration tooling like AvePoint (there is no native commercial-to-GCC-High path), and…
- KNOWLEDGE BASE
Windows Pro vs. Enterprise for NIST 800-171 Rev 3: The Endpoint Parity Gap
For NIST 800-171 Rev 3, the endpoint controls quietly require Windows Enterprise. Rev 3 sharpened application allowlisting (03.04.08), and the licensed, manageable engine — AppLocker — needs a Windows Enterprise…
- KNOWLEDGE BASE
Your SPRS Score, Explained: How the DoD Assessment Methodology Works
Your SPRS score is a self-reported number from 110 down to -203 that tells the DoD how much of NIST SP 800-171 you have actually implemented. It starts at 110, and every unmet requirement subtracts a weighted value…
- KNOWLEDGE BASE
CMMC Phase II Is Suspended — What You Still Have to Do
On July 13, 2026 the Department of War suspended the CMMC Phase II transition during a 60-day program review. Third-party (C3PAO) and Level 3 designations are paused and November 10, 2026 is no longer an operative…
- KNOWLEDGE BASE
FCI, CUI, CDI — How the Rules Stack Together
The security stack is driven first by the information involved, then by the clauses, assessment level, and contract-specific requirements that apply to the system handling it. FCI, CUI, and CDI are overlapping…
- KNOWLEDGE BASE
The Foundation Clauses — FAR 52.204-21 and the DFARS 7012 Family
FAR 52.204-21 and DFARS 252.204-7012, -7019, -7020 and -7021 form the contractual backbone of defense cybersecurity. Each has a distinct trigger, obligation, and flowdown. Alongside them sits an independent…
- KNOWLEDGE BASE
CUI Is Not an Export License — ITAR and EAR as a Separate Overlay
Export control is a separate legal overlay from CUI safeguarding. The controlling authority, classification, destination, end user, nationality, access path, license or exemption, and technical facts determine…
- CLOUD SETUP
Microsoft 365 security setup guide
Email, files, Teams, and identity for the whole company. Commercial Microsoft 365 is generally NOT authorized to store CUI. Most ITAR / CUI contractors need Microsoft 365 GCC High.
- CLOUD SETUP
M365 — Phishing-Resistant Multi-Factor Authentication
Make a stolen password useless on its own. A password can be phished or guessed. Multi-factor authentication (MFA) adds a second proof of identity. 'Phishing-resistant' means the second proof — like a security key or…
- CLOUD SETUP
M365 — Least-Privilege Access Control
Give each person only the access their job needs — and no more. 'Least privilege' means everyone gets the smallest set of permissions that lets them do their work. Powerful admin rights are handed out carefully, and…
- CLOUD SETUP
M365 — Asset & Account Inventory
Keep a live list of every device, identity, and app you defend. You cannot protect what you do not know you have. An inventory is an always-current list of your accounts, devices, and cloud services, so nothing is…
- CLOUD SETUP
M365 — Logging, Monitoring & Audit
Record important events and watch for trouble. Logs are the security camera footage of your cloud. Turning them on — and keeping them — lets you see who did what, get alerted to attacks, and prove what happened after…
- CLOUD SETUP
M365 — Network Segmentation & Boundary Protection
Keep one compromised thing from reaching everything else. Segmentation splits your environment into zones with locked doors between them, so a break-in one place cannot spread everywhere. A boundary controls exactly…
- CLOUD SETUP
M365 — Vulnerability & Patch Management
Find weak spots and fix the risky ones first. Software has flaws that attackers exploit. Vulnerability management scans for those flaws, ranks them by real risk, and makes sure the important fixes (patches) actually…
- CLOUD SETUP
M365 — Data Protection & Encryption
Scramble sensitive data so only the right people can read it. Encryption turns readable data into a locked code. Only someone with the key can unlock it. Protect data both while it sits in storage (at rest) and while…
- CLOUD SETUP
M365 — Backup & Recovery
Be able to restore your data after an attack or outage. A backup is a safe, separate copy of your data. Recovery is proving you can actually bring it back. Ransomware and mistakes are survivable only if your backups…
- CLOUD SETUP
M365 — Secure Configuration Baseline
Start every service from a known-good, hardened setting. A baseline is a checklist of safe settings for your cloud. Instead of leaving things on the risky defaults, you turn on protections, measure your score, and…
- CLOUD SETUP
M365 — Secure AI Adoption & Data Loss Prevention
Use AI and share files without leaking sensitive information. AI assistants and easy file sharing are powerful — and easy to misuse. Data Loss Prevention (DLP) watches for sensitive data leaving where it should not,…
- CLOUD SETUP
Amazon Web Services security setup guide
Servers, storage, databases, and networking you rent by the hour. For CUI and ITAR data, use AWS GovCloud (US) with FedRAMP High and DoD Impact Level 4–5 authorized services.
- CLOUD SETUP
AWS — Phishing-Resistant Multi-Factor Authentication
Make a stolen password useless on its own. A password can be phished or guessed. Multi-factor authentication (MFA) adds a second proof of identity. 'Phishing-resistant' means the second proof — like a security key or…
- CLOUD SETUP
AWS — Least-Privilege Access Control
Give each person only the access their job needs — and no more. 'Least privilege' means everyone gets the smallest set of permissions that lets them do their work. Powerful admin rights are handed out carefully, and…
- CLOUD SETUP
AWS — Asset & Account Inventory
Keep a live list of every device, identity, and app you defend. You cannot protect what you do not know you have. An inventory is an always-current list of your accounts, devices, and cloud services, so nothing is…
- CLOUD SETUP
AWS — Logging, Monitoring & Audit
Record important events and watch for trouble. Logs are the security camera footage of your cloud. Turning them on — and keeping them — lets you see who did what, get alerted to attacks, and prove what happened after…
- CLOUD SETUP
AWS — Network Segmentation & Boundary Protection
Keep one compromised thing from reaching everything else. Segmentation splits your environment into zones with locked doors between them, so a break-in one place cannot spread everywhere. A boundary controls exactly…
- CLOUD SETUP
AWS — Vulnerability & Patch Management
Find weak spots and fix the risky ones first. Software has flaws that attackers exploit. Vulnerability management scans for those flaws, ranks them by real risk, and makes sure the important fixes (patches) actually…
- CLOUD SETUP
AWS — Data Protection & Encryption
Scramble sensitive data so only the right people can read it. Encryption turns readable data into a locked code. Only someone with the key can unlock it. Protect data both while it sits in storage (at rest) and while…
- CLOUD SETUP
AWS — Backup & Recovery
Be able to restore your data after an attack or outage. A backup is a safe, separate copy of your data. Recovery is proving you can actually bring it back. Ransomware and mistakes are survivable only if your backups…
- CLOUD SETUP
AWS — Secure Configuration Baseline
Start every service from a known-good, hardened setting. A baseline is a checklist of safe settings for your cloud. Instead of leaving things on the risky defaults, you turn on protections, measure your score, and…
- CLOUD SETUP
AWS — Secure AI Adoption & Data Loss Prevention
Use AI and share files without leaking sensitive information. AI assistants and easy file sharing are powerful — and easy to misuse. Data Loss Prevention (DLP) watches for sensitive data leaving where it should not,…
- CLOUD SETUP
Google Workspace security setup guide
Gmail, Drive, Docs, and Meet with a single admin console. Handling CUI in Workspace requires Assured Controls and careful scoping. Confirm an authorization path before you store CUI.
- CLOUD SETUP
Workspace — Phishing-Resistant Multi-Factor Authentication
Make a stolen password useless on its own. A password can be phished or guessed. Multi-factor authentication (MFA) adds a second proof of identity. 'Phishing-resistant' means the second proof — like a security key or…
- CLOUD SETUP
Workspace — Least-Privilege Access Control
Give each person only the access their job needs — and no more. 'Least privilege' means everyone gets the smallest set of permissions that lets them do their work. Powerful admin rights are handed out carefully, and…
- CLOUD SETUP
Workspace — Asset & Account Inventory
Keep a live list of every device, identity, and app you defend. You cannot protect what you do not know you have. An inventory is an always-current list of your accounts, devices, and cloud services, so nothing is…
- CLOUD SETUP
Workspace — Logging, Monitoring & Audit
Record important events and watch for trouble. Logs are the security camera footage of your cloud. Turning them on — and keeping them — lets you see who did what, get alerted to attacks, and prove what happened after…
- CLOUD SETUP
Workspace — Network Segmentation & Boundary Protection
Keep one compromised thing from reaching everything else. Segmentation splits your environment into zones with locked doors between them, so a break-in one place cannot spread everywhere. A boundary controls exactly…
- CLOUD SETUP
Workspace — Vulnerability & Patch Management
Find weak spots and fix the risky ones first. Software has flaws that attackers exploit. Vulnerability management scans for those flaws, ranks them by real risk, and makes sure the important fixes (patches) actually…
- CLOUD SETUP
Workspace — Data Protection & Encryption
Scramble sensitive data so only the right people can read it. Encryption turns readable data into a locked code. Only someone with the key can unlock it. Protect data both while it sits in storage (at rest) and while…
- CLOUD SETUP
Workspace — Backup & Recovery
Be able to restore your data after an attack or outage. A backup is a safe, separate copy of your data. Recovery is proving you can actually bring it back. Ransomware and mistakes are survivable only if your backups…
- CLOUD SETUP
Workspace — Secure Configuration Baseline
Start every service from a known-good, hardened setting. A baseline is a checklist of safe settings for your cloud. Instead of leaving things on the risky defaults, you turn on protections, measure your score, and…
- CLOUD SETUP
Workspace — Secure AI Adoption & Data Loss Prevention
Use AI and share files without leaking sensitive information. AI assistants and easy file sharing are powerful — and easy to misuse. Data Loss Prevention (DLP) watches for sensitive data leaving where it should not,…
- CLOUD SETUP
Google Cloud security setup guide
Google's rent-by-the-hour compute, storage, and networking. For CUI, deploy inside Assured Workloads with the correct US government / Impact Level compliance regime.
- CLOUD SETUP
GCP — Phishing-Resistant Multi-Factor Authentication
Make a stolen password useless on its own. A password can be phished or guessed. Multi-factor authentication (MFA) adds a second proof of identity. 'Phishing-resistant' means the second proof — like a security key or…
- CLOUD SETUP
GCP — Least-Privilege Access Control
Give each person only the access their job needs — and no more. 'Least privilege' means everyone gets the smallest set of permissions that lets them do their work. Powerful admin rights are handed out carefully, and…
- CLOUD SETUP
GCP — Asset & Account Inventory
Keep a live list of every device, identity, and app you defend. You cannot protect what you do not know you have. An inventory is an always-current list of your accounts, devices, and cloud services, so nothing is…
- CLOUD SETUP
GCP — Logging, Monitoring & Audit
Record important events and watch for trouble. Logs are the security camera footage of your cloud. Turning them on — and keeping them — lets you see who did what, get alerted to attacks, and prove what happened after…
- CLOUD SETUP
GCP — Network Segmentation & Boundary Protection
Keep one compromised thing from reaching everything else. Segmentation splits your environment into zones with locked doors between them, so a break-in one place cannot spread everywhere. A boundary controls exactly…
- CLOUD SETUP
GCP — Vulnerability & Patch Management
Find weak spots and fix the risky ones first. Software has flaws that attackers exploit. Vulnerability management scans for those flaws, ranks them by real risk, and makes sure the important fixes (patches) actually…
- CLOUD SETUP
GCP — Data Protection & Encryption
Scramble sensitive data so only the right people can read it. Encryption turns readable data into a locked code. Only someone with the key can unlock it. Protect data both while it sits in storage (at rest) and while…
- CLOUD SETUP
GCP — Backup & Recovery
Be able to restore your data after an attack or outage. A backup is a safe, separate copy of your data. Recovery is proving you can actually bring it back. Ransomware and mistakes are survivable only if your backups…
- CLOUD SETUP
GCP — Secure Configuration Baseline
Start every service from a known-good, hardened setting. A baseline is a checklist of safe settings for your cloud. Instead of leaving things on the risky defaults, you turn on protections, measure your score, and…
- CLOUD SETUP
GCP — Secure AI Adoption & Data Loss Prevention
Use AI and share files without leaking sensitive information. AI assistants and easy file sharing are powerful — and easy to misuse. Data Loss Prevention (DLP) watches for sensitive data leaving where it should not,…
- CLOUD SETUP
Azure Government security setup guide
A separate, sovereign Azure cloud built for U.S. government data. Azure Government, paired with GCC High identity, is a purpose-built home for CUI: FedRAMP High and DoD Impact Level 4/5, with data kept in the U.S.…
- CLOUD SETUP
Azure Gov — Phishing-Resistant Multi-Factor Authentication
Make a stolen password useless on its own. A password can be phished or guessed. Multi-factor authentication (MFA) adds a second proof of identity. 'Phishing-resistant' means the second proof — like a security key or…
- CLOUD SETUP
Azure Gov — Least-Privilege Access Control
Give each person only the access their job needs — and no more. 'Least privilege' means everyone gets the smallest set of permissions that lets them do their work. Powerful admin rights are handed out carefully, and…
- CLOUD SETUP
Azure Gov — Asset & Account Inventory
Keep a live list of every device, identity, and app you defend. You cannot protect what you do not know you have. An inventory is an always-current list of your accounts, devices, and cloud services, so nothing is…
- CLOUD SETUP
Azure Gov — Logging, Monitoring & Audit
Record important events and watch for trouble. Logs are the security camera footage of your cloud. Turning them on — and keeping them — lets you see who did what, get alerted to attacks, and prove what happened after…
- CLOUD SETUP
Azure Gov — Network Segmentation & Boundary Protection
Keep one compromised thing from reaching everything else. Segmentation splits your environment into zones with locked doors between them, so a break-in one place cannot spread everywhere. A boundary controls exactly…
- CLOUD SETUP
Azure Gov — Vulnerability & Patch Management
Find weak spots and fix the risky ones first. Software has flaws that attackers exploit. Vulnerability management scans for those flaws, ranks them by real risk, and makes sure the important fixes (patches) actually…
- CLOUD SETUP
Azure Gov — Data Protection & Encryption
Scramble sensitive data so only the right people can read it. Encryption turns readable data into a locked code. Only someone with the key can unlock it. Protect data both while it sits in storage (at rest) and while…
- CLOUD SETUP
Azure Gov — Backup & Recovery
Be able to restore your data after an attack or outage. A backup is a safe, separate copy of your data. Recovery is proving you can actually bring it back. Ransomware and mistakes are survivable only if your backups…
- CLOUD SETUP
Azure Gov — Secure Configuration Baseline
Start every service from a known-good, hardened setting. A baseline is a checklist of safe settings for your cloud. Instead of leaving things on the risky defaults, you turn on protections, measure your score, and…
- CLOUD SETUP
Azure Gov — Secure AI Adoption & Data Loss Prevention
Use AI and share files without leaking sensitive information. AI assistants and easy file sharing are powerful — and easy to misuse. Data Loss Prevention (DLP) watches for sensitive data leaving where it should not,…
- DOWNLOAD
Brilliant at the Basics 20-Practice Executive Checklist
One page per track covering all twenty practices with owner, effort, stage, and the single question an executive should ask about each. All 20 practices in recommended sequence. Suggested owner and effort band. The…
- DOWNLOAD
First 14 Days Action Plan
The first two weeks, sequenced — the 24-hour and 14-day actions from every practice in the first three stages, with space for owner and date. 24-hour actions. 14-day actions. Owner and target-date columns. First…
- DOWNLOAD
IT Top 10 Implementation Checklist
Every implementation step and validation check for the ten IT practices, in the site's recommended sequence. Implementation steps per practice. Validation checks. Operating metrics. Maturity ladder for scoring
- DOWNLOAD
OT Top 10 Implementation Checklist
Every implementation step and validation check for the ten OT practices, with the safety and change-control considerations attached to each. Implementation steps per practice. Validation checks. Safety…
- DOWNLOAD
IT Evidence Collection Checklist
The governance, configuration, operations, and validation artifacts worth retaining for each IT practice, with a column for where yours lives. Evidence by practice and category. Location and owner columns. Retention…
- DOWNLOAD
OT Evidence Collection Checklist
The governance, configuration, operations, and validation artifacts worth retaining for each OT practice, including maintenance-window and safety-review records. Evidence by practice and category. Location and owner…
- DOWNLOAD
NIST SP 800-171 Rev. 2 Crosswalk
Every practice mapped to Rev. 2 requirement identifiers with relationship type, confidence, and an explicit caveat for each row. Practice-to-requirement rows. Relationship type and confidence. Per-row caveat. Mapping…
- DOWNLOAD
NIST SP 800-171 Rev. 3 Crosswalk
Practices mapped to Rev. 3 requirement identifiers where a reviewed mapping exists, with the same relationship, confidence, and caveat structure. Rev. 3 identifiers. Relationship type and confidence. Per-row caveat.…
- DOWNLOAD
CMMC Level 2 Influence Matrix
Which practices influence which CMMC Level 2 practice identifiers — stated as influence, not as coverage or readiness. Practice-to-CMMC identifier rows. Influence strength and confidence. Explicit non-coverage…
- DOWNLOAD
NIST Cybersecurity Framework 2.0 Crosswalk
Practices mapped to CSF 2.0 outcome identifiers, useful for reporting the campaign against a framework leadership already recognizes. Practice-to-CSF outcome rows. Relationship type and confidence. Per-row caveat.…
- DOWNLOAD
CIS Controls v8.1 Crosswalk
Practices mapped to CIS Controls v8.1 safeguards — the most operationally concrete of the crosswalks, and a useful bridge for MSP conversations. Practice-to-safeguard rows. Relationship type and confidence. Per-row…
- DOWNLOAD
MSP / MSSP Responsibility Matrix
A blank-by-design matrix for agreeing, in writing, who implements, who operates, who evidences, and who is accountable for each practice. All 20 practices. Implement / operate / evidence / accountable columns.…
- DOWNLOAD
Executive / Board Briefing One-Pager
What the campaign is, what it is not, the six-stage sequence, the questions a board should ask, and the honest statement of what implementation does and does not do for contractual obligations. What Brilliant at the…
- DOWNLOAD
30-Day Implementation Plan Template
A structured template for a first-month plan: the 24-hour, 14-day, and 30-day actions with owner, date, validation check, and evidence to retain. Three action horizons. Owner and date columns. First validation check.…
- DOWNLOAD
90-Day Improvement Roadmap Template
A quarter-length roadmap organized by the six-stage sequence, with a current-and-target maturity column for each practice. Six-stage roadmap. Current and target maturity columns. Dependency prompts. Quarterly review…
- FRAMEWORK MAPPINGReviewed
NIST SP 800-171 Rev. 2 3.5.3 → IT-01
Direct relationship, high confidence. The requirement calls for multifactor authentication for local and network access to privileged accounts and network access to non-privileged accounts — the same population this…
- FRAMEWORK MAPPINGReviewed
NIST SP 800-171 Rev. 3 03.05.03 → IT-01
Direct relationship, high confidence. Rev 3 restates the multifactor requirement with the same scope; phishing resistance is a stronger method choice within it, not a separate control.
- FRAMEWORK MAPPINGReviewed
CMMC Level 2 IA.L2-3.5.3 → IT-01
Direct relationship, high confidence. The CMMC practice inherits the 800-171 requirement text directly.
- FRAMEWORK MAPPINGReviewed
NIST SP 800-63B AAL2 / AAL3 authenticators → IT-01
Contextual relationship, high confidence. 800-63B is where 'phishing resistance' is actually defined; it tells you which authenticator types qualify.
- FRAMEWORK MAPPINGReviewed
CIS Controls v8.1 6.3 / 6.4 / 6.5 → IT-01
Direct relationship, moderate confidence. CIS separates MFA for externally-exposed applications, remote access, and administrative access — the same prioritization this practice recommends.
- FRAMEWORK MAPPINGReviewed
NIST SP 800-171 Rev. 2 3.4.1 → IT-02
Direct relationship, high confidence. The requirement is to establish and maintain baseline configurations and inventories of organizational systems throughout the development life cycle.
- FRAMEWORK MAPPINGReviewed
NIST SP 800-171 Rev. 3 03.04.01 → IT-02
Direct relationship, high confidence. Rev 3 retains the baseline-configuration and inventory requirement with equivalent scope.
- FRAMEWORK MAPPINGReviewed
CMMC Level 2 CM.L2-3.4.1 → IT-02
Direct relationship, high confidence. The CMMC practice inherits the 800-171 requirement text directly.
- FRAMEWORK MAPPINGReviewed
NIST CSF 2.0 ID.AM-01 / ID.AM-02 → IT-02
Direct relationship, high confidence. The CSF asset-management outcomes cover hardware and software inventories explicitly.
- FRAMEWORK MAPPINGReviewed
CIS Controls v8.1 1.1 / 2.1 → IT-02
Direct relationship, high confidence. Enterprise and software asset inventories are the first two CIS controls and describe the same activity.
- FRAMEWORK MAPPINGReviewed
NIST SP 800-171 Rev. 2 3.4.1 / 3.14.1 → IT-03
Supporting relationship, moderate confidence. Retiring unsupported systems is how organizations keep baseline configurations maintainable and flaws remediable; neither requirement names end-of-life management directly.
- FRAMEWORK MAPPINGReviewed
CMMC Level 2 CM.L2-3.4.1 / SI.L2-3.14.1 → IT-03
Supporting relationship, moderate confidence. The same reasoning carries to the inherited CMMC practices.
- FRAMEWORK MAPPINGReviewed
NIST CSF 2.0 ID.AM-08 → IT-03
Supporting relationship, moderate confidence. The CSF asset lifecycle outcome covers systems through decommissioning, which is exactly this practice.
- FRAMEWORK MAPPINGReviewed
CIS Controls v8.1 2.2 / 2.3 → IT-03
Direct relationship, moderate confidence. CIS requires that unsupported software be addressed or documented with a mitigation, which is the substance of this practice.
- FRAMEWORK MAPPINGReviewed
NIST SP 800-171 Rev. 2 3.4.2 → IT-04
Supporting relationship, moderate confidence. Establishing and enforcing security configuration settings is the requirement; documented, portable baselines are how you make that maintainable.
- FRAMEWORK MAPPINGReviewed
CMMC Level 2 CM.L2-3.4.2 → IT-04
Supporting relationship, moderate confidence. The same reasoning carries to the inherited CMMC practice.
Showing the first 120 of 224 results. Add a filter or a search term to narrow it.