// ITSP.10.171 · FAMILY 01 · 16 REQUIREMENTS

Access control

Last verified: 2026-10-05

// REQUIREMENTS

IdentifierRequirementLevel 1
03.01.01 Account management Level 1
03.01.02 Access enforcement Level 1
03.01.03 Information flow enforcement
03.01.04 Separation of duties
03.01.05 Least privilege
03.01.06 Least privilege (privileged accounts)
03.01.07 Least privilege (privileged functions)
03.01.08 Unsuccessful logon attempts
03.01.09 System use notification
03.01.10 Device lock
03.01.11 Session termination
03.01.12 Remote access
03.01.16 Wireless access
03.01.18 Access control for mobile devices
03.01.20 Use of external systems Level 1
03.01.22 Publicly accessible content Level 1

// INTENT

The right people reach the right data and nothing more.

// WHAT A FIRST ASSESSMENT FINDS

Everyone in the "Engineering" group can reach everything Engineering ever made, 3 departed employees still have live accounts, and the shared "shop floor" login has been running since 2019.

// THE WORK

Least privilege applied to the enclave. Role-based groups scoped to need, a joiner-mover-leaver process that fires the day someone changes roles, no shared accounts touching Specified Information, and remote access that terminates on the enclave's edge under MFA. Quarterly access reviews with a dated record turn this family from a hope into evidence.

// HOW WE CAN INTERPRET IT

// TEMPLATES FOR THIS FAMILY

References

  1. Protecting specified information in non-Government of Canada systems and organizations (ITSP.10.171)April 2025, updated October 2025
    Canadian Centre for Cyber Securitycyber.gc.ca
  2. NIST SP 800-171 Revision 3, Protecting Controlled Unclassified Information in Nonfederal Systems and OrganizationsRevision 3
    NISTcsrc.nist.gov

Outbound links open in a new tab. Source-pinned. If a vendor moves a doc, this block gets updated.