// ITSP.10.171 · FAMILY 16 · 3 REQUIREMENTS
System and services acquisition
Last verified: 2026-10-05
// REQUIREMENTS
// INTENT
Security is considered when systems and services are bought or built, including what external providers are responsible for.
// WHAT A FIRST ASSESSMENT FINDS
Gear bought from whoever was cheapest that week, with no record of where it came from.
// THE WORK
A documented buying path for anything entering the enclave, provider responsibilities captured in the matrix, and a software bill of materials for anything you develop.
// HOW WE CAN INTERPRET IT
// TEMPLATES FOR THIS FAMILY
References
- Protecting specified information in non-Government of Canada systems and organizations (ITSP.10.171)Canadian Centre for Cyber Securitycyber.gc.ca
- NIST SP 800-171 Revision 3, Protecting Controlled Unclassified Information in Nonfederal Systems and OrganizationsNISTcsrc.nist.gov
Outbound links open in a new tab. Source-pinned. If a vendor moves a doc, this block gets updated.