// ITSP.10.171 · FAMILY 14 · 6 REQUIREMENTS

System and information integrity

Last verified: 2026-10-05

// REQUIREMENTS

IdentifierRequirementLevel 1
03.14.01 Flaw remediation Level 1
03.14.02 Malicious code protection Level 1
03.14.03 Security alerts, advisories, and directives
03.14.06 System monitoring
03.14.08 Information management and retention
03.14.09 Dedicated administration workstation

// INTENT

Patch on a cadence with proof, run current malware protection everywhere in scope, act on the alerts your own tools raise, and do administrative work only from a dedicated, isolated workstation.

// WHAT A FIRST ASSESSMENT FINDS

"we patch when we can," Windows patched and nothing else, alerts landing in a mailbox nobody owns.

// THE WORK

"critical patches inside 14 days, the rest monthly, exceptions recorded," with the patch report joining the evidence folder and every alert routed to a ticket that gets closed.

// HOW WE CAN INTERPRET IT

// CANADA'S ADDITION · 03.14.09

Canada's addition, 03.14.09: dedicated administration workstation. This is the one requirement in ITSP.10.171 that isn't in NIST SP 800-171, and it comes from the Canadian control catalogue (source control SI-400, the ITSG-33 lineage) rather than from NIST. It asks for 3 things. Administrative and superuser actions get done from a physical workstation dedicated to that work and isolated from all other functions and networks, especially the internet. Remote connection from that workstation to the network it administers runs over a carrier private network, such as VPLS or MPLS, with VPN encryption on top. And the workstation is a hardened, single-purpose machine or thin client that isn't shared between security realms. The discussion in the standard goes further than most shops expect: the workstation isn't domain-joined, doesn't download patches from the internet, carries no office tools, and isn't used to update documentation in networked applications.

For a 20-person shop that means one admin machine, kept off the internet, patched from media you bring to it, and used for nothing but administering the enclave; admin accounts work from that machine and from nowhere else.

The remote clause is the hard part. An MSP administering your enclave from its own office over an internet VPN doesn't meet the requirement as written, and a carrier private network to every client is not how most MSPs are built. This is a Level 2 requirement, it's new, and the assessment method hasn't been published... so read the text yourself, keep administrative work inside the enclave wherever you can, and get your assessor's reading in writing before you buy circuits.

// TEMPLATES FOR THIS FAMILY

References

  1. Protecting specified information in non-Government of Canada systems and organizations (ITSP.10.171)April 2025, updated October 2025
    Canadian Centre for Cyber Securitycyber.gc.ca
  2. NIST SP 800-171 Revision 3, Protecting Controlled Unclassified Information in Nonfederal Systems and OrganizationsRevision 3
    NISTcsrc.nist.gov

Outbound links open in a new tab. Source-pinned. If a vendor moves a doc, this block gets updated.