// ITSP.10.171 · FAMILY 13 · 10 REQUIREMENTS
System and communications protection
Last verified: 2026-10-05
// REQUIREMENTS
| Identifier | Requirement | Level 1 |
|---|---|---|
| 03.13.01 | Boundary protection | Level 1 |
| 03.13.04 | Information in shared system resources | |
| 03.13.06 | Network communications, deny by default, allow by exception | |
| 03.13.08 | Transmission and storage confidentiality | |
| 03.13.09 | Network disconnect | |
| 03.13.10 | Cryptographic key establishment and management | |
| 03.13.11 | Cryptographic protection | |
| 03.13.12 | Collaborative computing devices and applications | |
| 03.13.13 | Mobile code | |
| 03.13.15 | Session authenticity |
// INTENT
The network architecture itself defends the data.
// WHAT A FIRST ASSESSMENT FINDS
One flat subnet behind a consumer router, and a guest wifi that is a different SSID and nothing else.
// THE WORK
A real boundary with deny-by-default rules at the edge, encryption for Specified Information in transit and wherever it's stored, which 03.13.08 requires on servers, laptops, backups, and portable media alike, separation between the enclave and everything else that isn't just a different SSID, and DNS and remote access paths you can draw. If your firewall rule set can't be explained to an assessor in one sitting, it can't be defended in one either.
// HOW WE CAN INTERPRET IT
// TEMPLATES FOR THIS FAMILY
References
- Protecting specified information in non-Government of Canada systems and organizations (ITSP.10.171)Canadian Centre for Cyber Securitycyber.gc.ca
- NIST SP 800-171 Revision 3, Protecting Controlled Unclassified Information in Nonfederal Systems and OrganizationsNISTcsrc.nist.gov
Outbound links open in a new tab. Source-pinned. If a vendor moves a doc, this block gets updated.