// ITSP.10.171 · FAMILY 04 · 10 REQUIREMENTS

Configuration management

Last verified: 2026-10-05

// REQUIREMENTS

IdentifierRequirementLevel 1
03.04.01 Baseline configuration
03.04.02 Configuration settings
03.04.03 Configuration change control
03.04.04 Impact analyses
03.04.05 Access restrictions for change
03.04.06 Least functionality
03.04.08 Authorized software (allow by exception)
03.04.10 System component inventory
03.04.11 Information location
03.04.12 System and component configuration for high-risk areas

// INTENT

Systems run in a known state and change on purpose.

// WHAT A FIRST ASSESSMENT FINDS

Golden images from 3 IT generations ago, local admin everywhere, and change control that lives in someone's memory.

// THE WORK

Baselines for the enclave's workstation and server classes, hardened against a recognized benchmark, local admin stripped from daily-driver accounts, an inventory of what runs, and every change recorded with a date and a name. Tedious, and it powers half the other families, because drift is where controls stop working without anyone noticing.

// HOW WE CAN INTERPRET IT

// TEMPLATES FOR THIS FAMILY

References

  1. Protecting specified information in non-Government of Canada systems and organizations (ITSP.10.171)April 2025, updated October 2025
    Canadian Centre for Cyber Securitycyber.gc.ca
  2. NIST SP 800-171 Revision 3, Protecting Controlled Unclassified Information in Nonfederal Systems and OrganizationsRevision 3
    NISTcsrc.nist.gov

Outbound links open in a new tab. Source-pinned. If a vendor moves a doc, this block gets updated.