// CPCSC TEMPLATES · 04 OF 14

Access control policy

Last verified: 2026-10-05

Role-based access with least privilege, granted to groups and reviewed on a schedule. Satisfies the core of 03.01.01, 03.01.02, 03.01.04, and 03.01.05.

Free to use, edit, and share, including by an MSP for a client, under CC BY 4.0. Keep the credit "Hans Study, hans.study" and the licence with it. None of it is legal advice or a substitute for the contract clauses in front of you.

TPL-04 Static template

Policy

[Company] grants access to systems and data holding Specified Information on the basis of role and need. Access is assigned to groups, never to individual accounts. A group with one member is still a group. The owner of the company holds no enclave access unless the owner's role requires it.

Account types allowed: individual user, individual privileged (separate account), service. Account types prohibited on enclave systems: shared, guest, anonymous, temporary without an end date.

Privileged accounts are separate from daily-use accounts and are used only from a dedicated administration workstation with no email or web browsing. Privileged actions are logged.

Accounts are disabled the same day a person leaves or changes roles, after [30] days of inactivity, or when HR reports a significant risk. Account managers are notified within [1 business day] of any of those events. Users log out after [8 hours] of expected inactivity or when leaving the site.

Group hierarchy

ENCLAVE-USERS            membership = screening complete, training signed
  PROJ-[A]-ENGINEERING   drawings, BOMs (read/write)
  PROJ-[A]-FIRMWARE      source, build artifacts (read/write)
  PROJ-[A]-QUALITY       test records (read/write); drawings (read only)
  PROJ-[A]-MASTER        everything in the project; [2] named people
ENCLAVE-ADMINS           separate admin accounts only
BUSINESS-USERS           office network; no enclave rights

Review

Group membership is exported and compared to the HR active list every [quarter] by [owner, role]. The export and the review record are retained as evidence.

Owner: [name, role]. Reviewed: [date]. Next review: [date].

References

  1. Protecting specified information in non-Government of Canada systems and organizations (ITSP.10.171)April 2025, updated October 2025
    Canadian Centre for Cyber Securitycyber.gc.ca
  2. NIST SP 800-171 Revision 3, Protecting Controlled Unclassified Information in Nonfederal Systems and OrganizationsRevision 3
    NISTcsrc.nist.gov

Outbound links open in a new tab. Source-pinned. If a vendor moves a doc, this block gets updated.