// ITSP.10.171 · FAMILY 02 · 2 REQUIREMENTS
Awareness and training
Last verified: 2026-10-05
// REQUIREMENTS
// INTENT
People who touch the data know what it is, how to handle it, and what an attack on them looks like this year.
// WHAT A FIRST ASSESSMENT FINDS
One onboarding video from 3 years ago, no record of who watched it, and a sales team posting shop-floor photos.
// THE WORK
Annual training with a sign-off sheet as the floor, role-specific content for admins and privileged users, and 5 minutes at a toolbox talk each quarter, which does more than the video anyone can click through.
// HOW WE CAN INTERPRET IT
// TEMPLATES FOR THIS FAMILY
References
- Protecting specified information in non-Government of Canada systems and organizations (ITSP.10.171)Canadian Centre for Cyber Securitycyber.gc.ca
- NIST SP 800-171 Revision 3, Protecting Controlled Unclassified Information in Nonfederal Systems and OrganizationsNISTcsrc.nist.gov
Outbound links open in a new tab. Source-pinned. If a vendor moves a doc, this block gets updated.