// ITSP.10.171 · FAMILY 17 · 3 REQUIREMENTS

Supply chain risk management

Last verified: 2026-10-05

// REQUIREMENTS

IdentifierRequirementLevel 1
03.17.01 Supply chain risk management plan
03.17.02 Acquisition strategies, tools, and methods
03.17.03 Supply chain requirements and processes

// INTENT

Know who is in your supply chain for the in-scope systems, assess the risk they bring, and flow requirements down where protected data flows down.

// WHAT A FIRST ASSESSMENT FINDS

Subcontractors receiving drawings with no clause attached and no questions asked.

// THE WORK

An inventory of who touches in-scope systems and data, flow-down language in subcontracts, and evidence that the process repeats.

// HOW WE CAN INTERPRET IT

// TEMPLATES FOR THIS FAMILY

References

  1. Protecting specified information in non-Government of Canada systems and organizations (ITSP.10.171)April 2025, updated October 2025
    Canadian Centre for Cyber Securitycyber.gc.ca
  2. NIST SP 800-171 Revision 3, Protecting Controlled Unclassified Information in Nonfederal Systems and OrganizationsRevision 3
    NISTcsrc.nist.gov

Outbound links open in a new tab. Source-pinned. If a vendor moves a doc, this block gets updated.