// ITSP.10.171 · FAMILY 01 · 16 REQUIREMENTS
Access control
Last verified: 2026-10-05
// REQUIREMENTS
| Identifier | Requirement | Level 1 |
|---|---|---|
| 03.01.01 | Account management | Level 1 |
| 03.01.02 | Access enforcement | Level 1 |
| 03.01.03 | Information flow enforcement | |
| 03.01.04 | Separation of duties | |
| 03.01.05 | Least privilege | |
| 03.01.06 | Least privilege (privileged accounts) | |
| 03.01.07 | Least privilege (privileged functions) | |
| 03.01.08 | Unsuccessful logon attempts | |
| 03.01.09 | System use notification | |
| 03.01.10 | Device lock | |
| 03.01.11 | Session termination | |
| 03.01.12 | Remote access | |
| 03.01.16 | Wireless access | |
| 03.01.18 | Access control for mobile devices | |
| 03.01.20 | Use of external systems | Level 1 |
| 03.01.22 | Publicly accessible content | Level 1 |
// INTENT
The right people reach the right data and nothing more.
// WHAT A FIRST ASSESSMENT FINDS
Everyone in the "Engineering" group can reach everything Engineering ever made, 3 departed employees still have live accounts, and the shared "shop floor" login has been running since 2019.
// THE WORK
Least privilege applied to the enclave. Role-based groups scoped to need, a joiner-mover-leaver process that fires the day someone changes roles, no shared accounts touching Specified Information, and remote access that terminates on the enclave's edge under MFA. Quarterly access reviews with a dated record turn this family from a hope into evidence.
// HOW WE CAN INTERPRET IT
// TEMPLATES FOR THIS FAMILY
References
- Protecting specified information in non-Government of Canada systems and organizations (ITSP.10.171)Canadian Centre for Cyber Securitycyber.gc.ca
- NIST SP 800-171 Revision 3, Protecting Controlled Unclassified Information in Nonfederal Systems and OrganizationsNISTcsrc.nist.gov
Outbound links open in a new tab. Source-pinned. If a vendor moves a doc, this block gets updated.