// ITSP.10.171 · FAMILY 06 · 5 REQUIREMENTS
Incident response
Last verified: 2026-10-05
// REQUIREMENTS
// INTENT
When it goes wrong, you act instead of improvising.
// WHAT A FIRST ASSESSMENT FINDS
A plan nobody has walked through, or no plan, and contract reporting timelines nobody has read.
// THE WORK
Names, phone numbers, a definition of an incident involving Specified Information, containment steps for your actual environment, and the contract's reporting obligations with their timelines. Reporting obligations and their clocks live in your contract clauses and differ between contracts, so read yours rather than a summary. Then exercise it once a year on a tabletop, because a plan nobody has walked through is a document, and the difference shows within 10 minutes of a real event.
// HOW WE CAN INTERPRET IT
// TEMPLATES FOR THIS FAMILY
References
- Protecting specified information in non-Government of Canada systems and organizations (ITSP.10.171)Canadian Centre for Cyber Securitycyber.gc.ca
- NIST SP 800-171 Revision 3, Protecting Controlled Unclassified Information in Nonfederal Systems and OrganizationsNISTcsrc.nist.gov
Outbound links open in a new tab. Source-pinned. If a vendor moves a doc, this block gets updated.