// ITSP.10.171 · FAMILY 13 · 10 REQUIREMENTS

System and communications protection

Last verified: 2026-10-05

// REQUIREMENTS

IdentifierRequirementLevel 1
03.13.01 Boundary protection Level 1
03.13.04 Information in shared system resources
03.13.06 Network communications, deny by default, allow by exception
03.13.08 Transmission and storage confidentiality
03.13.09 Network disconnect
03.13.10 Cryptographic key establishment and management
03.13.11 Cryptographic protection
03.13.12 Collaborative computing devices and applications
03.13.13 Mobile code
03.13.15 Session authenticity

// INTENT

The network architecture itself defends the data.

// WHAT A FIRST ASSESSMENT FINDS

One flat subnet behind a consumer router, and a guest wifi that is a different SSID and nothing else.

// THE WORK

A real boundary with deny-by-default rules at the edge, encryption for Specified Information in transit and wherever it's stored, which 03.13.08 requires on servers, laptops, backups, and portable media alike, separation between the enclave and everything else that isn't just a different SSID, and DNS and remote access paths you can draw. If your firewall rule set can't be explained to an assessor in one sitting, it can't be defended in one either.

// HOW WE CAN INTERPRET IT

// TEMPLATES FOR THIS FAMILY

References

  1. Protecting specified information in non-Government of Canada systems and organizations (ITSP.10.171)April 2025, updated October 2025
    Canadian Centre for Cyber Securitycyber.gc.ca
  2. NIST SP 800-171 Revision 3, Protecting Controlled Unclassified Information in Nonfederal Systems and OrganizationsRevision 3
    NISTcsrc.nist.gov

Outbound links open in a new tab. Source-pinned. If a vendor moves a doc, this block gets updated.