// ITSP.10.171 · FAMILY 12 · 4 REQUIREMENTS

Security assessment and monitoring

Last verified: 2026-10-05

// REQUIREMENTS

IdentifierRequirementLevel 1
03.12.01 Security assessment
03.12.02 Plan of action and milestones
03.12.03 Continuous monitoring
03.12.05 Information exchange

// INTENT

Check that the controls work, plan and track the fixes, and keep watching.

// WHAT A FIRST ASSESSMENT FINDS

The gap register archived the day it was finished.

// THE WORK

Keep the Chapter 7 register alive, review it on a schedule, update it when the environment changes, and track the remediation tail to completion. This is where the system security plan and the register live.

// HOW WE CAN INTERPRET IT

// TEMPLATES FOR THIS FAMILY

References

  1. Protecting specified information in non-Government of Canada systems and organizations (ITSP.10.171)April 2025, updated October 2025
    Canadian Centre for Cyber Securitycyber.gc.ca
  2. NIST SP 800-171 Revision 3, Protecting Controlled Unclassified Information in Nonfederal Systems and OrganizationsRevision 3
    NISTcsrc.nist.gov

Outbound links open in a new tab. Source-pinned. If a vendor moves a doc, this block gets updated.