// ITSP.10.171 · FAMILY 04 · 10 REQUIREMENTS
Configuration management
Last verified: 2026-10-05
// REQUIREMENTS
| Identifier | Requirement | Level 1 |
|---|---|---|
| 03.04.01 | Baseline configuration | |
| 03.04.02 | Configuration settings | |
| 03.04.03 | Configuration change control | |
| 03.04.04 | Impact analyses | |
| 03.04.05 | Access restrictions for change | |
| 03.04.06 | Least functionality | |
| 03.04.08 | Authorized software (allow by exception) | |
| 03.04.10 | System component inventory | |
| 03.04.11 | Information location | |
| 03.04.12 | System and component configuration for high-risk areas |
// INTENT
Systems run in a known state and change on purpose.
// WHAT A FIRST ASSESSMENT FINDS
Golden images from 3 IT generations ago, local admin everywhere, and change control that lives in someone's memory.
// THE WORK
Baselines for the enclave's workstation and server classes, hardened against a recognized benchmark, local admin stripped from daily-driver accounts, an inventory of what runs, and every change recorded with a date and a name. Tedious, and it powers half the other families, because drift is where controls stop working without anyone noticing.
// HOW WE CAN INTERPRET IT
// TEMPLATES FOR THIS FAMILY
References
- Protecting specified information in non-Government of Canada systems and organizations (ITSP.10.171)Canadian Centre for Cyber Securitycyber.gc.ca
- NIST SP 800-171 Revision 3, Protecting Controlled Unclassified Information in Nonfederal Systems and OrganizationsNISTcsrc.nist.gov
Outbound links open in a new tab. Source-pinned. If a vendor moves a doc, this block gets updated.