DoW Launches “Brilliant at the Basics”

DoW Launches Brilliant at Basics
Image by DC Studio on Magnific

The DoW has launched “Brilliant at Basics” in an attempt to help small and mid-sized businesses to protect sensitive defense information.  This action follows suspension of Cybersecurity Maturity Model Certification (CMMC) Phase 2 for a review process.  These actions have taken place because the Department of War has become aware of the burden cybersecurity requirements has placed on small businesses.  

Brilliant at Basics Best Practices

The initiative provides ten Information Technology best practices that aim to provide rapid delivery of enhanced cybersecurity without administrative complexity and compliance overhead.  The intent is to streamline compliance for smaller Defense Industrial Base (DIB) contractors and subcontractors while insuring protection of Controlled Unclassified Information (CUI).

Phishing Resistant MFA

This practice requires upgrading multi-factor authentication away from SMS text messages and push notifications.  The guidance recommends combining explicit identity verification with least-privilege principles to reduce the risk of unauthorized access

Asset Inventory Management

Asset inventories comprise the backbone of a well structured cybersecurity program.  Maintaining accurate inventories of hardware, software, identities, and data provides information on what needs to be protected so that resilient defenses can be operated.

Strategic Technical Debt Reduction

These actions include retiring unused or legacy infrastructure and software.  Strategic technical debt reduction also includes archiving redundant data.  The goal is to increase resilience by reducing an organization’s attack surface.

Flexible Technology Stack

This guidance emphasizes flexible and interoperable solutions that support modular technologies.  This approach promotes operational agility and prevents an organization from being locked into single supplier solutions.

Logical Segmentation to Limit Adversary Lateral Movement

Segmenting your cyberenvironment into logical zones reduces vulnerabilities to lateral penetration after initial access.  This limits the extent of compromise after a breach.

Risk-Based Vulnerability Management

Prioritizing remediation actions based on the actual exploitability of a vulnerability allows organizations to make best use of limited resources.  The key is to maintain focus on real operational risks.

Integrate Security Early in the Development Lifecycle

Planning security as early in a lifecycle as possible is an important concept.  However, this is usually not possible when designing or upgrading existing systems.  Still, it is advisable to integrate all parties before upgrading security protocols. 

Secure AI Adoption and Data Protection

The use of Artificial Intelligence is a growing risk to national security as it is employed by workforces.  Organizational policies should explicitly prohibit the input of sensitive data into public, commercial AI systems. The guidance advocates implementing content filtering, endpoint controls, and contained enterprise AI environments.

Resilient Backup and Disaster Recovery Architecture

Emphasis should be placed on developing resilient backup architectures to protect sequestered data.  This is essential when engaging in disaster recoveries.  Backups should be secured using isolated credentials.  They should be distinct from primary networks.  Strict protections should be in place to prevent unauthorized modification or deletion. Additionally, organizations should conduct full-system restoration drills to validate recovery plans. 

Continuous Technical Workforce Readiness

Organizations are advised to continually train technical and security staff members.  This can be challenging given the speed at which technology solutions and threats are emerging.

Best Practices for Operational Technologies

The DoW initiative also provides similar guidance for Operational Technologies (OT).  Items specific to this guidance include supply chain security, review of processes, and continuous monitoring.  Supply chain security, addressed in NIST SP 800-161, is a vast undertaking requiring time and resources from multiple organizations concurrently.

Cyber Campaign Receives Mixed Reviews

The release of Brilliant at Basics just after the suspension of CMMC phase 2 creates many questions.  Chief among them is what is the long term goal for small and medium contractors and subcontractors working with the Department of War.  While most items mentioned in the publication are covered under various controls of NIST SP 800-171, some such as phishing resistant MFA and secure adoption of AI go beyond the bounds of the standard.  

Perhaps the greatest issue for small and medium organizations striving to meet CMMC requirements is resources.  Costs far exceed an auditors fee.  Implementation also often requires hardware upgrades and contracting with third party service providers.  Additionally, staffing requirements must be met for technical positions for which there is a shortage of qualified applicants.

CVG Strategy Cybersecurity Consultants

CVG Strategy can provide guidance and help your organization understand and implement contractually required NIST standards and CMMC.  We are dedicated to helping small businesses navigate federal regulations and contract requirements for Quality Management, CybersecurityExport Compliance, and Test and Evaluation. We can help you meet your information security management system goals.  CVG Strategy QMS experts can provide guidance for engaging in a ISMS and make it meet desired objectives.

Identify CUI Areas with CVG Strategy Signs

CVG Strategy provides signs to identify areas containing CUI and export controlled items. These signs should be posted at all facility entrances where access controlled or export controlled articles and technology are present.

 

Kevin Gholston

Share this post

Secret Link