// ITSP.10.171 · FAMILY 15 · 3 REQUIREMENTS

Planning

Last verified: 2026-10-05

// REQUIREMENTS

IdentifierRequirementLevel 1
03.15.01 Policy and procedures
03.15.02 System security plan
03.15.03 Rules of behaviour

// INTENT

The system security plan exists, describes the real environment and boundary, and gets updated when the environment changes; rules of behaviour for users are written down.

// WHAT A FIRST ASSESSMENT FINDS

No SSP, or a template one describing a company that doesn't exist.

// THE WORK

Write the SSP skeleton first (Chapter 9), have users sign rules of behaviour on hire and annually, and wire the review trigger into change control.

// HOW WE CAN INTERPRET IT

// TEMPLATES FOR THIS FAMILY

References

  1. Protecting specified information in non-Government of Canada systems and organizations (ITSP.10.171)April 2025, updated October 2025
    Canadian Centre for Cyber Securitycyber.gc.ca
  2. NIST SP 800-171 Revision 3, Protecting Controlled Unclassified Information in Nonfederal Systems and OrganizationsRevision 3
    NISTcsrc.nist.gov

Outbound links open in a new tab. Source-pinned. If a vendor moves a doc, this block gets updated.