// ITSP.10.171 · FAMILY 09 · 2 REQUIREMENTS

Personnel security

Last verified: 2026-10-05

// REQUIREMENTS

IdentifierRequirementLevel 1
03.09.01 Personnel screening
03.09.02 Personnel termination and transfer

// INTENT

Screen people before they get access to protected data, and pull access cleanly when they leave or move roles.

// WHAT A FIRST ASSESSMENT FINDS

Hiring paperwork in a filing cabinet HR can't find, and the last engineer to leave still has a live account.

// THE WORK

Screening to the contract's requirements before enclave access, a named Company Security Officer where the contract requires one, and an offboarding process with a checklist that HR and IT both sign.

// HOW WE CAN INTERPRET IT

// TEMPLATES FOR THIS FAMILY

References

  1. Protecting specified information in non-Government of Canada systems and organizations (ITSP.10.171)April 2025, updated October 2025
    Canadian Centre for Cyber Securitycyber.gc.ca
  2. NIST SP 800-171 Revision 3, Protecting Controlled Unclassified Information in Nonfederal Systems and OrganizationsRevision 3
    NISTcsrc.nist.gov

Outbound links open in a new tab. Source-pinned. If a vendor moves a doc, this block gets updated.