// ITSP.10.171 · FAMILY 15 · 3 REQUIREMENTS
Planning
Last verified: 2026-10-05
// REQUIREMENTS
// INTENT
The system security plan exists, describes the real environment and boundary, and gets updated when the environment changes; rules of behaviour for users are written down.
// WHAT A FIRST ASSESSMENT FINDS
No SSP, or a template one describing a company that doesn't exist.
// THE WORK
Write the SSP skeleton first (Chapter 9), have users sign rules of behaviour on hire and annually, and wire the review trigger into change control.
// HOW WE CAN INTERPRET IT
// TEMPLATES FOR THIS FAMILY
References
- Protecting specified information in non-Government of Canada systems and organizations (ITSP.10.171)Canadian Centre for Cyber Securitycyber.gc.ca
- NIST SP 800-171 Revision 3, Protecting Controlled Unclassified Information in Nonfederal Systems and OrganizationsNISTcsrc.nist.gov
Outbound links open in a new tab. Source-pinned. If a vendor moves a doc, this block gets updated.