// CPCSC · ITSP.10.171 · 98 REQUIREMENTS

The 98 requirements

Last verified: 2026-10-05

ITSP.10.171 is the Canadian Centre for Cyber Security's adaptation of NIST SP 800-171 Revision 3; the second release, dated October 28, 2025, is current. It holds 98 requirements in 17 families: the 97 from Revision 3 plus 03.14.09, dedicated administration workstation, which Canada added from its own control catalogue. Gaps in the numbering are the identifiers NIST withdrew in Revision 3, which Canada keeps as "not allocated" so the numbers line up across the border. The 13 Level 1 requirements are marked.

Many requirements contain organization-defined parameters: how long before an inactive account is disabled, how many failed logins before lockout, how long logs are kept. Unless a contract names a value, you choose it, record it in your system security plan, and defend it at assessment. The bracketed values in the templates are exactly those choices.

// 17 FAMILIES

03.01 16 requirements

Access control

The right people reach the right data and nothing more.

Level 1: 4
03.02 2 requirements

Awareness and training

People who touch the data know what it is, how to handle it, and what an attack on them looks like this year.

03.03 8 requirements

Audit and accountability

When something happens, you can reconstruct it.

03.04 10 requirements

Configuration management

Systems run in a known state and change on purpose.

03.05 8 requirements

Identification and authentication

Know who is on the system before it does anything.

Level 1: 3
03.06 5 requirements

Incident response

When it goes wrong, you act instead of improvising.

03.07 3 requirements

Maintenance

Control who services the systems, with what tools, from where.

03.08 7 requirements

Media protection

Protected data on removable and portable media is controlled from creation to destruction.

Level 1: 1
03.09 2 requirements

Personnel security

Screen people before they get access to protected data, and pull access cleanly when they leave or move roles.

03.10 5 requirements

Physical protection

The hardware holding protected data sits behind physical access control with a short key list.

Level 1: 2
03.11 3 requirements

Risk assessment

Assess risk to the protected data periodically, scan for vulnerabilities on a cycle, and fix what the scans find inside a defined window.

03.12 4 requirements

Security assessment and monitoring

Check that the controls work, plan and track the fixes, and keep watching.

03.13 10 requirements

System and communications protection

The network architecture itself defends the data.

Level 1: 1
03.14 6 requirements

System and information integrity

Patch on a cadence with proof, run current malware protection everywhere in scope, act on the alerts your own tools raise, and do administrative work only from a dedicated, isolated workstation.

Level 1: 2
03.15 3 requirements

Planning

The system security plan exists, describes the real environment and boundary, and gets updated when the environment changes; rules of behaviour for users are written down.

03.16 3 requirements

System and services acquisition

Security is considered when systems and services are bought or built, including what external providers are responsible for.

03.17 3 requirements

Supply chain risk management

Know who is in your supply chain for the in-scope systems, assess the risk they bring, and flow requirements down where protected data flows down.

// ALL 98 REQUIREMENTS · 13 AT LEVEL 1

IdentifierRequirementFamilyLevel 1
03.01.01 Account management Access control Level 1
03.01.02 Access enforcement Access control Level 1
03.01.03 Information flow enforcement Access control
03.01.04 Separation of duties Access control
03.01.05 Least privilege Access control
03.01.06 Least privilege (privileged accounts) Access control
03.01.07 Least privilege (privileged functions) Access control
03.01.08 Unsuccessful logon attempts Access control
03.01.09 System use notification Access control
03.01.10 Device lock Access control
03.01.11 Session termination Access control
03.01.12 Remote access Access control
03.01.16 Wireless access Access control
03.01.18 Access control for mobile devices Access control
03.01.20 Use of external systems Access control Level 1
03.01.22 Publicly accessible content Access control Level 1
03.02.01 Literacy training and awareness Awareness and training
03.02.02 Role-based training Awareness and training
03.03.01 Event logging Audit and accountability
03.03.02 Audit record content Audit and accountability
03.03.03 Audit record generation Audit and accountability
03.03.04 Response to audit logging process failures Audit and accountability
03.03.05 Audit record review, analysis, and reporting Audit and accountability
03.03.06 Audit record reduction and report generation Audit and accountability
03.03.07 Time stamps Audit and accountability
03.03.08 Protection of audit information Audit and accountability
03.04.01 Baseline configuration Configuration management
03.04.02 Configuration settings Configuration management
03.04.03 Configuration change control Configuration management
03.04.04 Impact analyses Configuration management
03.04.05 Access restrictions for change Configuration management
03.04.06 Least functionality Configuration management
03.04.08 Authorized software (allow by exception) Configuration management
03.04.10 System component inventory Configuration management
03.04.11 Information location Configuration management
03.04.12 System and component configuration for high-risk areas Configuration management
03.05.01 User identification, authentication, and re-authentication Identification and authentication Level 1
03.05.02 Device identification and authentication Identification and authentication Level 1
03.05.03 Multi-factor authentication Identification and authentication Level 1
03.05.04 Replay-resistant authentication Identification and authentication
03.05.05 Identifier management Identification and authentication
03.05.07 Password management Identification and authentication
03.05.11 Authentication feedback Identification and authentication
03.05.12 Authenticator management Identification and authentication
03.06.01 Incident handling Incident response
03.06.02 Incident monitoring, reporting, and response assistance Incident response
03.06.03 Incident response testing Incident response
03.06.04 Incident response training Incident response
03.06.05 Incident response plan Incident response
03.07.04 Maintenance tools Maintenance
03.07.05 Non-local maintenance Maintenance
03.07.06 Maintenance personnel Maintenance
03.08.01 Media storage Media protection
03.08.02 Media access Media protection
03.08.03 Media sanitization Media protection Level 1
03.08.04 Media marking Media protection
03.08.05 Media transport Media protection
03.08.07 Media use Media protection
03.08.09 System backup (cryptographic protection) Media protection
03.09.01 Personnel screening Personnel security
03.09.02 Personnel termination and transfer Personnel security
03.10.01 Physical access authorizations Physical protection Level 1
03.10.02 Monitoring physical access Physical protection
03.10.06 Alternate work site Physical protection
03.10.07 Physical access control Physical protection Level 1
03.10.08 Access control for transmission Physical protection
03.11.01 Risk assessment Risk assessment
03.11.02 Vulnerability monitoring and scanning Risk assessment
03.11.04 Risk response Risk assessment
03.12.01 Security assessment Security assessment and monitoring
03.12.02 Plan of action and milestones Security assessment and monitoring
03.12.03 Continuous monitoring Security assessment and monitoring
03.12.05 Information exchange Security assessment and monitoring
03.13.01 Boundary protection System and communications protection Level 1
03.13.04 Information in shared system resources System and communications protection
03.13.06 Network communications, deny by default, allow by exception System and communications protection
03.13.08 Transmission and storage confidentiality System and communications protection
03.13.09 Network disconnect System and communications protection
03.13.10 Cryptographic key establishment and management System and communications protection
03.13.11 Cryptographic protection System and communications protection
03.13.12 Collaborative computing devices and applications System and communications protection
03.13.13 Mobile code System and communications protection
03.13.15 Session authenticity System and communications protection
03.14.01 Flaw remediation System and information integrity Level 1
03.14.02 Malicious code protection System and information integrity Level 1
03.14.03 Security alerts, advisories, and directives System and information integrity
03.14.06 System monitoring System and information integrity
03.14.08 Information management and retention System and information integrity
03.14.09 Dedicated administration workstation System and information integrity
03.15.01 Policy and procedures Planning
03.15.02 System security plan Planning
03.15.03 Rules of behaviour Planning
03.16.01 Security engineering principles System and services acquisition
03.16.02 Unsupported system components System and services acquisition
03.16.03 External system services System and services acquisition
03.17.01 Supply chain risk management plan Supply chain risk management
03.17.02 Acquisition strategies, tools, and methods Supply chain risk management
03.17.03 Supply chain requirements and processes Supply chain risk management

References

  1. Protecting specified information in non-Government of Canada systems and organizations (ITSP.10.171)April 2025, updated October 2025
    Canadian Centre for Cyber Securitycyber.gc.ca
  2. NIST SP 800-171 Revision 3, Protecting Controlled Unclassified Information in Nonfederal Systems and OrganizationsRevision 3
    NISTcsrc.nist.gov
  3. How to meet Level 1 requirementsModified 2026-09-29
    Public Services and Procurement Canadacanada.ca

Outbound links open in a new tab. Source-pinned. If a vendor moves a doc, this block gets updated.