// CPCSC TEMPLATES · 02 OF 14

ITSP.10.171 requirement index

Last verified: 2026-10-05

All 98 requirements by family and identifier, Level 1 items marked. Use it as the row list of a gap register or the folder structure of an evidence library. Identifiers NIST withdrew in Revision 3 are omitted.

Download as Markdown

Free to use, edit, and share, including by an MSP for a client, under CC BY 4.0. Keep the credit "Hans Study, hans.study" and the licence with it. None of it is legal advice or a substitute for the contract clauses in front of you.

TPL-02 Static template

Access control

Awareness and training

Audit and accountability

Configuration management

Identification and authentication

  • 03.05.01 User identification, authentication, and re-authentication (Level 1)
  • 03.05.02 Device identification and authentication (Level 1)
  • 03.05.03 Multi-factor authentication (Level 1)
  • 03.05.04 Replay-resistant authentication
  • 03.05.05 Identifier management
  • 03.05.07 Password management
  • 03.05.11 Authentication feedback
  • 03.05.12 Authenticator management

Incident response

Maintenance

Media protection

Personnel security

Physical protection

Risk assessment

Security assessment and monitoring

System and communications protection

  • 03.13.01 Boundary protection (Level 1)
  • 03.13.04 Information in shared system resources
  • 03.13.06 Network communications, deny by default, allow by exception
  • 03.13.08 Transmission and storage confidentiality
  • 03.13.09 Network disconnect
  • 03.13.10 Cryptographic key establishment and management
  • 03.13.11 Cryptographic protection
  • 03.13.12 Collaborative computing devices and applications
  • 03.13.13 Mobile code
  • 03.13.15 Session authenticity

System and information integrity

  • 03.14.01 Flaw remediation (Level 1)
  • 03.14.02 Malicious code protection (Level 1)
  • 03.14.03 Security alerts, advisories, and directives
  • 03.14.06 System monitoring
  • 03.14.08 Information management and retention
  • 03.14.09 Dedicated administration workstation

Planning

System and services acquisition

Supply chain risk management

  • 03.17.01 Supply chain risk management plan
  • 03.17.02 Acquisition strategies, tools, and methods
  • 03.17.03 Supply chain requirements and processes

References

  1. Protecting specified information in non-Government of Canada systems and organizations (ITSP.10.171)April 2025, updated October 2025
    Canadian Centre for Cyber Securitycyber.gc.ca
  2. NIST SP 800-171 Revision 3, Protecting Controlled Unclassified Information in Nonfederal Systems and OrganizationsRevision 3
    NISTcsrc.nist.gov

Outbound links open in a new tab. Source-pinned. If a vendor moves a doc, this block gets updated.