// ITSP.10.171 · FAMILY 11 · 3 REQUIREMENTS
Risk assessment
Last verified: 2026-10-05
// REQUIREMENTS
// INTENT
Assess risk to the protected data periodically, scan for vulnerabilities on a cycle, and fix what the scans find inside a defined window.
// WHAT A FIRST ASSESSMENT FINDS
A penetration test bought before a single vulnerability scan was run, and a report nobody actioned.
// THE WORK
Scan the enclave on a cycle with proper tools, rank the findings, fix inside a defined window, and record the next scan date. Progress is what the assessor wants to see.
// HOW WE CAN INTERPRET IT
// TEMPLATES FOR THIS FAMILY
References
- Protecting specified information in non-Government of Canada systems and organizations (ITSP.10.171)Canadian Centre for Cyber Securitycyber.gc.ca
- NIST SP 800-171 Revision 3, Protecting Controlled Unclassified Information in Nonfederal Systems and OrganizationsNISTcsrc.nist.gov
Outbound links open in a new tab. Source-pinned. If a vendor moves a doc, this block gets updated.