// ITSP.10.171 · FAMILY 05 · 8 REQUIREMENTS

Identification and authentication

Last verified: 2026-10-05

// REQUIREMENTS

IdentifierRequirementLevel 1
03.05.01 User identification, authentication, and re-authentication Level 1
03.05.02 Device identification and authentication Level 1
03.05.03 Multi-factor authentication Level 1
03.05.04 Replay-resistant authentication
03.05.05 Identifier management
03.05.07 Password management
03.05.11 Authentication feedback
03.05.12 Authenticator management

// INTENT

Know who is on the system before it does anything.

// WHAT A FIRST ASSESSMENT FINDS

MFA on the VPN maybe, absent on email, absent on the domain, absent on the cloud tenant's admin plane.

// THE WORK

MFA on every path to Specified Information and on every privileged account, unique IDs, a written password policy that matches the one applied, and replay-resistant mechanisms. At Level 2 none of this is negotiable, and it shouldn't be at your company regardless of the program.

// HOW WE CAN INTERPRET IT

// TEMPLATES FOR THIS FAMILY

References

  1. Protecting specified information in non-Government of Canada systems and organizations (ITSP.10.171)April 2025, updated October 2025
    Canadian Centre for Cyber Securitycyber.gc.ca
  2. NIST SP 800-171 Revision 3, Protecting Controlled Unclassified Information in Nonfederal Systems and OrganizationsRevision 3
    NISTcsrc.nist.gov

Outbound links open in a new tab. Source-pinned. If a vendor moves a doc, this block gets updated.