
The DoW has launched “Brilliant at Basics” in an attempt to help small and mid-sized businesses to protect sensitive defense information. This action follows suspension of Cybersecurity Maturity Model Certification (CMMC) Phase 2 for a review process. These actions have taken place because the Department of War has become aware of the burden cybersecurity requirements has placed on small businesses.
Brilliant at Basics Best Practices
The initiative provides ten Information Technology best practices that aim to provide rapid delivery of enhanced cybersecurity without administrative complexity and compliance overhead. The intent is to streamline compliance for smaller Defense Industrial Base (DIB) contractors and subcontractors while insuring protection of Controlled Unclassified Information (CUI).
Phishing Resistant MFA
This practice requires upgrading multi-factor authentication away from SMS text messages and push notifications. The guidance recommends combining explicit identity verification with least-privilege principles to reduce the risk of unauthorized access
Asset Inventory Management
Asset inventories comprise the backbone of a well structured cybersecurity program. Maintaining accurate inventories of hardware, software, identities, and data provides information on what needs to be protected so that resilient defenses can be operated.
Strategic Technical Debt Reduction
These actions include retiring unused or legacy infrastructure and software. Strategic technical debt reduction also includes archiving redundant data. The goal is to increase resilience by reducing an organization’s attack surface.
Flexible Technology Stack
This guidance emphasizes flexible and interoperable solutions that support modular technologies. This approach promotes operational agility and prevents an organization from being locked into single supplier solutions.
Logical Segmentation to Limit Adversary Lateral Movement
Segmenting your cyberenvironment into logical zones reduces vulnerabilities to lateral penetration after initial access. This limits the extent of compromise after a breach.
Risk-Based Vulnerability Management
Prioritizing remediation actions based on the actual exploitability of a vulnerability allows organizations to make best use of limited resources. The key is to maintain focus on real operational risks.
Integrate Security Early in the Development Lifecycle
Planning security as early in a lifecycle as possible is an important concept. However, this is usually not possible when designing or upgrading existing systems. Still, it is advisable to integrate all parties before upgrading security protocols.
Secure AI Adoption and Data Protection
The use of Artificial Intelligence is a growing risk to national security as it is employed by workforces. Organizational policies should explicitly prohibit the input of sensitive data into public, commercial AI systems. The guidance advocates implementing content filtering, endpoint controls, and contained enterprise AI environments.
Resilient Backup and Disaster Recovery Architecture
Emphasis should be placed on developing resilient backup architectures to protect sequestered data. This is essential when engaging in disaster recoveries. Backups should be secured using isolated credentials. They should be distinct from primary networks. Strict protections should be in place to prevent unauthorized modification or deletion. Additionally, organizations should conduct full-system restoration drills to validate recovery plans.
Continuous Technical Workforce Readiness
Organizations are advised to continually train technical and security staff members. This can be challenging given the speed at which technology solutions and threats are emerging.
Best Practices for Operational Technologies
The DoW initiative also provides similar guidance for Operational Technologies (OT). Items specific to this guidance include supply chain security, review of processes, and continuous monitoring. Supply chain security, addressed in NIST SP 800-161, is a vast undertaking requiring time and resources from multiple organizations concurrently.
Cyber Campaign Receives Mixed Reviews
The release of Brilliant at Basics just after the suspension of CMMC phase 2 creates many questions. Chief among them is what is the long term goal for small and medium contractors and subcontractors working with the Department of War. While most items mentioned in the publication are covered under various controls of NIST SP 800-171, some such as phishing resistant MFA and secure adoption of AI go beyond the bounds of the standard.
Perhaps the greatest issue for small and medium organizations striving to meet CMMC requirements is resources. Costs far exceed an auditors fee. Implementation also often requires hardware upgrades and contracting with third party service providers. Additionally, staffing requirements must be met for technical positions for which there is a shortage of qualified applicants.
CVG Strategy Cybersecurity Consultants
CVG Strategy can provide guidance and help your organization understand and implement contractually required NIST standards and CMMC. We are dedicated to helping small businesses navigate federal regulations and contract requirements for Quality Management, Cybersecurity, Export Compliance, and Test and Evaluation. We can help you meet your information security management system goals. CVG Strategy QMS experts can provide guidance for engaging in a ISMS and make it meet desired objectives.
Identify CUI Areas with CVG Strategy Signs
CVG Strategy provides signs to identify areas containing CUI and export controlled items. These signs should be posted at all facility entrances where access controlled or export controlled articles and technology are present.