// ITSP.10.171 · FAMILY 11 · 3 REQUIREMENTS

Risk assessment

Last verified: 2026-10-05

// REQUIREMENTS

IdentifierRequirementLevel 1
03.11.01 Risk assessment
03.11.02 Vulnerability monitoring and scanning
03.11.04 Risk response

// INTENT

Assess risk to the protected data periodically, scan for vulnerabilities on a cycle, and fix what the scans find inside a defined window.

// WHAT A FIRST ASSESSMENT FINDS

A penetration test bought before a single vulnerability scan was run, and a report nobody actioned.

// THE WORK

Scan the enclave on a cycle with proper tools, rank the findings, fix inside a defined window, and record the next scan date. Progress is what the assessor wants to see.

// HOW WE CAN INTERPRET IT

// TEMPLATES FOR THIS FAMILY

References

  1. Protecting specified information in non-Government of Canada systems and organizations (ITSP.10.171)April 2025, updated October 2025
    Canadian Centre for Cyber Securitycyber.gc.ca
  2. NIST SP 800-171 Revision 3, Protecting Controlled Unclassified Information in Nonfederal Systems and OrganizationsRevision 3
    NISTcsrc.nist.gov

Outbound links open in a new tab. Source-pinned. If a vendor moves a doc, this block gets updated.