Independent DIB implementation resource — not affiliated with or endorsed by the U.S. Department of WarView the official DoW campaign ↗
IMPLEMENTATION-ARTIFACT LIBRARY

Templates, worksheets, and registers

30 professional implementation artifacts — inventories, registers, trackers, plans, and worksheets — each with an owner, a review cadence, completion instructions, labeled example content, and the practices and NIST SP 800-171 requirements it has a mapped relationship to. Print to PDF, copy as Markdown, or export working tables as CSV. Complete everything offline.

What these are — and are not

Independent educational material: starting points that document your work, not compliance artifacts. Completing a template does not implement a safeguard or satisfy any requirement, and every document says so on its face. Nothing you type into a completed copy should ever touch a public website — including this one.

30 OF 30 ARTIFACTS
WORKSHEETPrint / PDF · Markdown

System Boundary Definition Worksheet

A structured worksheet for drawing the line that every security decision depends on: which systems, people, locations, and services are inside the environment that stores, processes, or transmits sensitive contract information — and what is deliberately outside it, and why.

  • Suggested owner: IT leader or compliance lead
  • Review: Semiannual, and at every significant system or contract change
  • Relates to 3 Rev. 2 and 3 Rev. 3 requirements
IT-02IT-05IT-08
Open →
QUESTIONNAIREPrint / PDF · Markdown

CUI & FCI Applicability Questionnaire

A contract-by-contract questionnaire for answering the question everything else depends on: does this organization handle federal contract information or controlled unclassified information at all — and under which contracts, based on which clauses and markings, decided by whom.

  • Suggested owner: Contracts or compliance lead
  • Review: At every new contract award or modification, and at least annually across the full contract list
  • Relates to 1 Rev. 2 and 1 Rev. 3 requirements
IT-02IT-08
Open →
WORKSHEETPrint / PDF · Markdown

System Security Plan Development Worksheet

A preparation worksheet that gathers, in one place, the raw material a system security plan is written from — system identification, the boundary reference, environment description prompts, per-family implementation notes, and interconnections — so the SSP drafting session starts from facts instead of a blank page.

  • Suggested owner: IT leader or compliance lead
  • Review: Quarterly while the SSP is being drafted; thereafter refreshed before every SSP update
  • Relates to 1 Rev. 2 and 1 Rev. 3 requirements
IT-02IT-05
Open →
MATRIXPrint / PDF · Markdown · CSV

Security Roles and Responsibilities Matrix

A named-person accountability matrix across the security outcomes a small contractor must actually run — identity, inventory, patching, backup, log review, incident reporting, supplier security, training, evidence — so that every area has one accountable human, not a team name, a vendor, or a shrug.

  • Suggested owner: IT leader
  • Review: Quarterly, and within two weeks of any departure or role change among the named persons
  • Relates to 1 Rev. 2 and 1 Rev. 3 requirements
IT-10IT-02
Open →
REGISTERPrint / PDF · Markdown · CSV

Risk Register

A working register of the organization's security risks — each one stated as condition and consequence, rated on a fixed scale, given an explicit treatment decision and a named owner, linked to the POA&M entry that carries its mitigation, and reviewed on a cadence that keeps the ratings honest.

  • Suggested owner: IT leader or compliance lead
  • Review: Monthly for open High-rated risks; the full register quarterly and after every incident or assessment
  • Relates to 1 Rev. 2 and 2 Rev. 3 requirements
TRACKERPrint / PDF · Markdown · CSV

Plan of Action & Milestones (POA&M) Template

A tracker for the weaknesses the organization has committed to fix: each entry a deficiency with a named responsible person, the resources it actually needs, dated milestones, a scheduled completion that is managed rather than wished at, and closure only against retained evidence.

  • Suggested owner: IT leader or compliance lead
  • Review: Monthly working review of all open entries; executive review quarterly and at every scheduled-completion slip
  • Relates to 1 Rev. 2 and 1 Rev. 3 requirements
IT-06IT-03
Open →
REGISTERPrint / PDF · Markdown · CSV

Security Metrics and KPI Register

A register of the handful of numbers leadership actually watches — each metric with a formula, a system-of-record data source, a directional target, a collection frequency, and an owner — so 'are we getting better?' is answered by trend lines instead of impressions.

  • Suggested owner: IT leader
  • Review: Each metric collected at its own stated frequency; the register itself reviewed quarterly, retiring any metric that no longer informs a decision
  • Relates to 1 Rev. 2 and 1 Rev. 3 requirements
IT-10IT-01IT-02
Open →
REGISTERPrint / PDF · Markdown · CSV

Evidence Index

The master list of the organization's evidence artifacts — what each one is, which practice and requirement reference it relates to, where it lives, who owns it, how fresh it is, and when it gets regenerated — so that producing proof is a lookup, not an archaeology dig.

  • Suggested owner: Compliance lead or IT leader
  • Review: Monthly freshness sweep of dates against cadences; full index review quarterly
  • Relates to 1 Rev. 2 and 1 Rev. 3 requirements
IT-02IT-10
Open →
WORKSHEETPrint / PDF · Markdown

Internal Assessment Worksheet

A structured worksheet for examining your own environment against a chosen scope — a stated method, a sampling plan, item-by-item observations, and a results summary that routes every gap somewhere — so the self-check produces findings you can act on rather than reassurance you wanted.

  • Suggested owner: IT leader or compliance lead
  • Review: Run at least semiannually, rotating scope so the whole environment is examined across a year; the worksheet format itself reviewed annually
  • Relates to 1 Rev. 2 and 1 Rev. 3 requirements
IT-06IT-10
Open →
RECORDPrint / PDF · Markdown

Artifact Review and Approval Record

A one-page standing record for reviewing any other artifact in the library: which artifact and version, who reviewed it, which checks were performed — currency, named ownership, example rows replaced, evidence pointers valid — and an explicit outcome with a next review date.

  • Suggested owner: Compliance lead
  • Review: Completed at every artifact review the library's cadences call for; the record format itself reviewed annually
  • Relates to 1 Rev. 2 and 1 Rev. 3 requirements
INVENTORYPrint / PDF · Markdown · CSV

Hardware and Software Asset Inventory

Two working tables — one for every device, one for every installed application — plus the reconciliation routine that keeps them honest: endpoint manager against identity provider against purchase records, with every mismatch explained or investigated.

  • Suggested owner: IT leader
  • Review: Monthly reconciliation against source systems; full verification annually and at every acquisition, disposal, or site change
  • Relates to 1 Rev. 2 and 1 Rev. 3 requirements
IT-02IT-03OT-02
Open →
INVENTORYPrint / PDF · Markdown · CSV

Cloud Service and SaaS Inventory

One row per cloud or SaaS service the business actually uses — sanctioned or not — with owner, authentication method, data types, and terms status, plus the discovery routine that finds the services nobody procured.

  • Suggested owner: IT leader or compliance lead
  • Review: Quarterly full review; new services added within a week of discovery or procurement
  • Relates to 2 Rev. 2 and 2 Rev. 3 requirements
IT-02IT-08
Open →
INVENTORYPrint / PDF · Markdown · CSV

Privileged Account Inventory

Every account that can change systems, security settings, or other people's access — human and service — with a named owner, an MFA method, a last-used date, and a written justification. The accounts attackers want most, on one reviewable page.

  • Suggested owner: Identity admin
  • Review: Quarterly, and within one business day of any admin departure or role change
  • Relates to 2 Rev. 2 and 2 Rev. 3 requirements
IT-01IT-02OT-01
Open →
WORKSHEETPrint / PDF · Markdown · CSV

Periodic Access Review Worksheet

A run-and-file worksheet for the recurring question every environment must answer: does everyone who has access still need it? Scope header, per-account keep / reduce / remove decisions, a completion attestation, and the metrics row that shows the review actually removed something.

  • Suggested owner: IT leader
  • Review: Quarterly for standard access; monthly for privileged, remote, and vendor access
  • Relates to 2 Rev. 2 and 2 Rev. 3 requirements
OT-01IT-01IT-02
Open →
TRACKERPrint / PDF · Markdown · CSV

MFA Deployment Tracker

A population-by-population rollout tracker for multi-factor authentication: totals, phishing-resistant versus other enrollment, enforcement status, dated-and-owned exceptions, and the legacy-authentication blocking checklist that closes the back door MFA leaves open.

  • Suggested owner: Identity admin
  • Review: Weekly during rollout; monthly once every population is enforced, to catch enrollment drift and expired exceptions
  • Relates to 1 Rev. 2 and 1 Rev. 3 requirements
WORKSHEETPrint / PDF · Markdown

Configuration Baseline Worksheet

A per-platform record of what 'correctly configured' means here: the vendor benchmark it derives from, which settings categories were reviewed, and a deviations table — setting, baseline value, actual value, justification, owner, expiry — that becomes the platform's exception register.

  • Suggested owner: System administrator
  • Review: Annually per platform, and at every major OS or platform version change
  • Relates to 2 Rev. 2 and 2 Rev. 3 requirements
IT-04IT-02OT-10
Open →
RECORDPrint / PDF · Markdown

Change Request and Validation Package

One package per change: the request (what, why, systems affected, risk class, rollback, approvals), a required safety and operations sign-off for anything touching production, a post-change validation checklist, and an emergency-change variant with retroactive review built in.

  • Suggested owner: IT leader
  • Review: A package is completed for every change; the template itself is reviewed annually and after any change-related incident
  • Relates to 3 Rev. 2 and 3 Rev. 3 requirements
OT-10IT-04
Open →
REGISTERPrint / PDF · Markdown · CSV

Vulnerability Register

The single working list of known weaknesses: each finding with its scanner severity and your own risk rank, an explicit patch / compensate / accept decision, an SLA-driven due date, and — for OT findings — whether a maintenance window is required and what compensates until then.

  • Suggested owner: IT leader
  • Review: Weekly triage of new findings; monthly aging review of everything open past its SLA
  • Relates to 2 Rev. 2 and 1 Rev. 3 requirements
IT-06OT-05
Open →
TRACKERPrint / PDF · Markdown · CSV

Patch Deployment Tracker

A cycle-by-cycle record of patching as it actually lands: per platform ring, how many patches applied, deployed, failed or deferred (with reasons and compensation), the completion percentage, and how completion was verified — including the window-scheduled OT lane.

  • Suggested owner: System administrator
  • Review: Updated every patch cycle (monthly for most platforms); ring definitions reviewed semiannually
  • Relates to 1 Rev. 2 and 1 Rev. 3 requirements
IT-06OT-05IT-03
Open →
MATRIXPrint / PDF · Markdown · CSV

Logging and Monitoring Coverage Matrix

One row per log source — identity provider, email, endpoints, firewall, servers, cloud audit, OT network sensor — answering the questions that matter when an incident starts: is it enabled, where does it go, how long is it kept, who actually looks at it, and what alerts fire.

  • Suggested owner: IT leader
  • Review: Quarterly, and within a week of any logging-platform, retention, or major system change
  • Relates to 2 Rev. 2 and 2 Rev. 3 requirements
OT-07IT-02
Open →
PLANPrint / PDF · Markdown

Incident Response Plan Template

A working incident response plan skeleton with real substance already in it: activation criteria and severity levels, named roles with backups, concrete actions for each response phase, a verified contact table, evidence-preservation basics, and an OT coordination section that puts the process owner in the room and safety ahead of forensics.

  • Suggested owner: IT leader or incident response lead
  • Review: Annual, after every incident or exercise that uses it, and at every provider or key-person change
  • Relates to 2 Rev. 2 and 3 Rev. 3 requirements
OT-04IT-09
Open →
RECORDPrint / PDF · Markdown · CSV

Incident Timeline Worksheet

A contemporaneous, timezone-consistent record of what happened, what was observed, and what was decided during an incident — the factual backbone for severity calls, containment choices, and the 72-hour reporting decision.

  • Suggested owner: Incident response lead
  • Review: Reviewed at every incident close-out, and exercised in at least one tabletop a year
  • Relates to 1 Rev. 2 and 1 Rev. 3 requirements
WORKSHEETPrint / PDF · Markdown

72-Hour Reporting Decision Worksheet

A structured decision aid for the hardest three days in defense contracting: does an affected contract carry DFARS 252.204-7012, is covered defense information or operationally critical support affected, when did the discovery clock start, and who decided what on which evidence. It organizes the decision; the contract and counsel make it.

  • Suggested owner: Compliance lead or contracts manager
  • Review: Annual, at every new contract award or modification, and after every use
  • Relates to 1 Rev. 2 and 1 Rev. 3 requirements
WORKSHEETPrint / PDF · Markdown · CSV

Backup Inventory and Restore-Test Worksheet

Two tables that turn 'we have backups' into a verifiable claim: an inventory of what is backed up, where, and with what protections, and a restore-test record measuring actual recovery times against targets. Built on one rule — an untested backup is an assumption.

  • Suggested owner: IT leader
  • Review: Quarterly for the inventory; restore tests on the schedule each row sets, at least annually per critical system
  • Relates to 1 Rev. 2 and 1 Rev. 3 requirements
IT-09OT-08
Open →
PLANPrint / PDF · Markdown

Network Segmentation Plan Worksheet

A plan for dividing the network into zones an intruder cannot freely cross: zone definitions, a from/to allowed-flows matrix in which every cell is a decision, an enforcement inventory, validation tests that prove boundaries hold, and a phased rollout that keeps production running while the walls go up.

  • Suggested owner: Network admin
  • Review: Semiannual, and at every firewall replacement, new zone, or significant architecture change
  • Relates to 2 Rev. 2 and 2 Rev. 3 requirements
IT-05OT-03
Open →
INVENTORYPrint / PDF · Markdown · CSV

Remote Access Pathway Inventory

A complete, dated inventory of every way into the environment from outside — VPNs, RDP gateways, vendor tools, cloud portals — with authentication, brokering, logging, and time-bounding recorded per pathway, plus a kill list for the pathways nobody authorized.

  • Suggested owner: Network admin
  • Review: Quarterly, and at every new vendor, tool, or provider change
  • Relates to 3 Rev. 2 and 2 Rev. 3 requirements
OT-06IT-01
Open →
QUESTIONNAIREPrint / PDF · Markdown

Supplier Security Questionnaire

A plain-language questionnaire a small supplier can actually answer — one question per practice area, a Yes / Partial / No scale, and an evidence-requested column — with guidance on reading the answers honestly: a dated Partial beats an unsupported Yes.

  • Suggested owner: Procurement lead
  • Review: Annual re-issue for critical suppliers; at onboarding for every new supplier
  • Relates to 1 Rev. 2 and 2 Rev. 3 requirements
WORKSHEETPrint / PDF · Markdown · CSV

Vendor Risk Assessment Worksheet

A per-vendor decision record that ties together what the vendor touches, what their questionnaire said, what the contract commits them to, and which access pathways they hold — ending in an owned decision: approve, approve with conditions, or decline.

  • Suggested owner: IT leader or compliance lead
  • Review: At vendor onboarding, at contract renewal, and annually for critical vendors
  • Relates to 1 Rev. 2 and 2 Rev. 3 requirements
WORKSHEETPrint / PDF · Markdown · CSV

AI Use-Case and Data-Handling Worksheet

A register of every AI tool and use case actually in play — with data classes, account models, vendor retention terms, approvals, and exception expiries — anchored by one standing prohibition: CUI and export-controlled data go into no tool that has not been explicitly approved for them.

  • Suggested owner: IT leader
  • Review: Quarterly, and at every new tool request or vendor terms change
  • Relates to 2 Rev. 2 and 2 Rev. 3 requirements
IT-08IT-01
Open →
MATRIXPrint / PDF · Markdown · CSV

Security Training Matrix

A role-by-role training matrix — everyone, admins, developers, OT operators, incident responders, executives — with topics, frequency, delivery method, and completion evidence per row, built for organizations where a documented toolbox talk at the line counts as training because it is training.

  • Suggested owner: Executive sponsor or HR lead
  • Review: Annual for the matrix itself; completion tracking monthly until every row shows current
  • Relates to 3 Rev. 2 and 2 Rev. 3 requirements

Filtering happens in this browser. Complete every artifact offline — never in a public web tool.

Library version 1.0, reviewed . Every artifact carries its own version history section; filenames are stable so a saved copy can be matched to the version it came from.