The DoD says it's reducing cybersecurity burden on the Defense Industrial Base. At the same time, the first recommendation in the new "Brilliant at the Basics" campaign calls for phishing-resistant multi-factor authentication, a capability that goes well beyond today's NIST SP 800-171 requirements.

In this episode we break down replay resistance vs. phishing resistance, explain why they are different security properties, and explore where phishing-resistant authentication fits into the NIST standards lifecycle. We also ask a simple question:

If this is now considered "basic," why isn't it in the NIST control catalog yet?

800-63: https://csrc.nist.gov/pubs/sp/800/63/b/4/final

Brilliant at the Basics: https://dowcio.war.gov/BrilliantBasics/