// ITSP.10.171 · FAMILY 16 · 3 REQUIREMENTS

System and services acquisition

Last verified: 2026-10-05

// REQUIREMENTS

IdentifierRequirementLevel 1
03.16.01 Security engineering principles
03.16.02 Unsupported system components
03.16.03 External system services

// INTENT

Security is considered when systems and services are bought or built, including what external providers are responsible for.

// WHAT A FIRST ASSESSMENT FINDS

Gear bought from whoever was cheapest that week, with no record of where it came from.

// THE WORK

A documented buying path for anything entering the enclave, provider responsibilities captured in the matrix, and a software bill of materials for anything you develop.

// HOW WE CAN INTERPRET IT

// TEMPLATES FOR THIS FAMILY

References

  1. Protecting specified information in non-Government of Canada systems and organizations (ITSP.10.171)April 2025, updated October 2025
    Canadian Centre for Cyber Securitycyber.gc.ca
  2. NIST SP 800-171 Revision 3, Protecting Controlled Unclassified Information in Nonfederal Systems and OrganizationsRevision 3
    NISTcsrc.nist.gov

Outbound links open in a new tab. Source-pinned. If a vendor moves a doc, this block gets updated.