// ITSP.10.171 · FAMILY 17 · 3 REQUIREMENTS
Supply chain risk management
Last verified: 2026-10-05
// REQUIREMENTS
// INTENT
Know who is in your supply chain for the in-scope systems, assess the risk they bring, and flow requirements down where protected data flows down.
// WHAT A FIRST ASSESSMENT FINDS
Subcontractors receiving drawings with no clause attached and no questions asked.
// THE WORK
An inventory of who touches in-scope systems and data, flow-down language in subcontracts, and evidence that the process repeats.
// HOW WE CAN INTERPRET IT
// TEMPLATES FOR THIS FAMILY
References
- Protecting specified information in non-Government of Canada systems and organizations (ITSP.10.171)Canadian Centre for Cyber Securitycyber.gc.ca
- NIST SP 800-171 Revision 3, Protecting Controlled Unclassified Information in Nonfederal Systems and OrganizationsNISTcsrc.nist.gov
Outbound links open in a new tab. Source-pinned. If a vendor moves a doc, this block gets updated.