// ITSP.10.171 · FAMILY 12 · 4 REQUIREMENTS
Security assessment and monitoring
Last verified: 2026-10-05
// REQUIREMENTS
// INTENT
Check that the controls work, plan and track the fixes, and keep watching.
// WHAT A FIRST ASSESSMENT FINDS
The gap register archived the day it was finished.
// THE WORK
Keep the Chapter 7 register alive, review it on a schedule, update it when the environment changes, and track the remediation tail to completion. This is where the system security plan and the register live.
// HOW WE CAN INTERPRET IT
// TEMPLATES FOR THIS FAMILY
References
- Protecting specified information in non-Government of Canada systems and organizations (ITSP.10.171)Canadian Centre for Cyber Securitycyber.gc.ca
- NIST SP 800-171 Revision 3, Protecting Controlled Unclassified Information in Nonfederal Systems and OrganizationsNISTcsrc.nist.gov
Outbound links open in a new tab. Source-pinned. If a vendor moves a doc, this block gets updated.