// ITSP.10.171 · FAMILY 06 · 5 REQUIREMENTS

Incident response

Last verified: 2026-10-05

// REQUIREMENTS

IdentifierRequirementLevel 1
03.06.01 Incident handling
03.06.02 Incident monitoring, reporting, and response assistance
03.06.03 Incident response testing
03.06.04 Incident response training
03.06.05 Incident response plan

// INTENT

When it goes wrong, you act instead of improvising.

// WHAT A FIRST ASSESSMENT FINDS

A plan nobody has walked through, or no plan, and contract reporting timelines nobody has read.

// THE WORK

Names, phone numbers, a definition of an incident involving Specified Information, containment steps for your actual environment, and the contract's reporting obligations with their timelines. Reporting obligations and their clocks live in your contract clauses and differ between contracts, so read yours rather than a summary. Then exercise it once a year on a tabletop, because a plan nobody has walked through is a document, and the difference shows within 10 minutes of a real event.

// HOW WE CAN INTERPRET IT

// TEMPLATES FOR THIS FAMILY

References

  1. Protecting specified information in non-Government of Canada systems and organizations (ITSP.10.171)April 2025, updated October 2025
    Canadian Centre for Cyber Securitycyber.gc.ca
  2. NIST SP 800-171 Revision 3, Protecting Controlled Unclassified Information in Nonfederal Systems and OrganizationsRevision 3
    NISTcsrc.nist.gov

Outbound links open in a new tab. Source-pinned. If a vendor moves a doc, this block gets updated.