// CPCSC TEMPLATES · 14 OF 14

System security plan outline

Last verified: 2026-10-05

The document the assessment orbits. Satisfies 03.15.02 when the contents are true. Aim for accurate over long.

Download as Markdown

Free to use, edit, and share, including by an MSP for a client, under CC BY 4.0. Keep the credit "Hans Study, hans.study" and the licence with it. None of it is legal advice or a substitute for the contract clauses in front of you.

TPL-14 Static template
  1. System name, owner, and purpose
  2. Scope and boundary: what is in, what is out, and why
  3. Network diagram, matching the running network, dated
  4. Asset inventory: in-scope systems, security protection assets
  5. Data flows for Specified Information: arrive, rest, work, leave, echo
  6. Roles and responsibilities, including MSP and cloud, with the shared responsibility matrix attached
  7. Control implementation, requirement by requirement from the index: how, where, evidence location
  8. Open items: reference to the remediation register (plan of action and milestones)
  9. Change log and review triggers

References

  1. Protecting specified information in non-Government of Canada systems and organizations (ITSP.10.171)April 2025, updated October 2025
    Canadian Centre for Cyber Securitycyber.gc.ca
  2. NIST SP 800-171 Revision 3, Protecting Controlled Unclassified Information in Nonfederal Systems and OrganizationsRevision 3
    NISTcsrc.nist.gov

Outbound links open in a new tab. Source-pinned. If a vendor moves a doc, this block gets updated.