- Password and authentication (03.05) · length, MFA, lockout, breach screening
- Account management (03.01) · joiner, mover, leaver; privileged accounts
- Access review (03.01.05) · cadence, owner, record retained
- Acceptable use and rules of behaviour (03.15.03) · personal devices, personal browsing on enclave systems
- Incident response (03.06) · definition, contacts, containment, contract reporting
- Media handling (03.08) · encryption, transport, sanitization, destruction receipts
- Physical security (03.10) · enclave hardware, key control, visitor handling
- Configuration and change management (03.04) · baselines, approval, record
- Vulnerability and patch management (03.11, 03.14) · scan cadence, fix windows, exceptions
- Logging and monitoring (03.03) · events captured, retention, review cadence
- Security awareness and training (03.02) · annual, sign-off, role-specific
- Personnel security (03.09) · screening to contract requirements, offboarding
- Vendor and MSP responsibility (03.16, 03.17) · matrix, deliverables, remote access
- Backup and recovery · scope, frequency, restore testing
// CPCSC TEMPLATES · 03 OF 14
Policy inventory checklist
Last verified: 2026-10-05
The 14 policies a small supplier needs written down and followed. Each line names the family it serves.
Free to use, edit, and share, including by an MSP for a client, under CC BY 4.0. Keep the credit "Hans Study, hans.study" and the licence with it. None of it is legal advice or a substitute for the contract clauses in front of you.
References
- Protecting specified information in non-Government of Canada systems and organizations (ITSP.10.171)Canadian Centre for Cyber Securitycyber.gc.ca
- NIST SP 800-171 Revision 3, Protecting Controlled Unclassified Information in Nonfederal Systems and OrganizationsNISTcsrc.nist.gov
Outbound links open in a new tab. Source-pinned. If a vendor moves a doc, this block gets updated.