home / frameworks / cccs-baseline

// Canadian government guidance

Baseline cyber security controls for small and medium organizations

The Cyber Centre's free list of 13 baseline controls for organizations with fewer than 500 employees, chosen to deliver most of the protection for a modest effort. Version 1.2 dates from 2020 and underpins the CAN/DGSI 104 standard.

CanadaVoluntaryVersion 1.2 (February 18, 2020)

Overview

The Canadian Centre for Cyber Security published Baseline cyber security controls for small and medium organizations to give smaller Canadian organizations a short, realistic security program. It applies the 80/20 rule. The idea is to get about 80% of the benefit from 20% of the effort by focusing on the controls that stop the most common attacks, such as phishing, ransomware, and account takeover. The current version is 1.2, dated February 18, 2020. It's aimed at organizations that fit the federal definition of small or medium, meaning fewer than 500 employees.

The document opens with organizational controls. An organization confirms it fits the size range, decides which IT systems are in scope, assesses the harm a compromise could cause, identifies its main threats, and names someone responsible for security. Then come 13 baseline controls, numbered BC.1 to BC.13. They cover incident response, patching, anti-malware, secure configuration, strong authentication, awareness training, backups, mobile devices, perimeter defences, cloud and outsourced IT, websites, access control, and portable media. Each control comes with practical guidance and links to more detailed Cyber Centre publications.

The baseline is guidance, not a certification. Its content was turned into a National Standard of Canada, first CAN/CIOSC 104:2021 and now CAN/DGSI 104:2021 / Rev 1:2024, which SCC-accredited bodies can certify under CyberSecure Canada. The Cyber Centre also publishes shorter companions, including Top measures to enhance cyber security for small and medium organizations (ITSAP.10.035, February 2024) and Foundational cyber security actions for small organizations (ITSAP.10.300, May 2023).

Who it applies to in Canada

Small and medium organizations in Canada, defined as those with fewer than 500 employees, that want a practical starting set of cyber security controls.

It's free federal guidance written for Canadian businesses and non-profits. The national standard behind CyberSecure Canada certification was built from it, and its controls overlap heavily with CPCSC Level 1.

Controls at a glance

The document sets 5 organizational controls (OC.1 to OC.5) and then 13 baseline controls (BC.1 to BC.13).

Organizational controls (OC.1 to OC.5)

  • Confirm the organization has fewer than 500 employees
  • Define in-scope IT systems and document exclusions
  • Assess harm to confidentiality, integrity, and availability
  • Identify the main cyber threats
  • Assign security leadership and commit to improvement

Respond and recover (BC.1, BC.7)

  • Have an incident response plan
  • Include recovery procedures in the plan
  • Back up critical data
  • Encrypt backups and store copies offsite

Keep systems clean (BC.2, BC.3, BC.4)

  • Turn on automatic patching or manage vulnerabilities
  • Run auto-updating anti-malware
  • Use software firewalls on hosts
  • Change default passwords
  • Disable unneeded features and services

People and accounts (BC.5, BC.6, BC.12)

  • Use two-factor authentication for important accounts
  • Set sensible password policies
  • Train staff in cyber security awareness
  • Give users only the access they need

Devices and network (BC.8, BC.9, BC.13)

  • Secure mobile devices and separate work data
  • Use perimeter firewalls and DNS filtering
  • Use VPNs for remote access
  • Secure Wi-Fi networks
  • Allow only encrypted, organization-owned portable media

Cloud and web (BC.10, BC.11)

  • Ask cloud providers for SOC 3 or similar reports
  • Choose providers that meet your security needs
  • Build and run websites to OWASP guidance

Certification and assessment

Organizations measure themselves against the 13 controls and close gaps over time. Those wanting third-party proof can seek CyberSecure Canada certification to the related national standard.

Dates to know

2020-02-18
Version 1.2 of the baseline controls published

Resources

Official texts and free tools for CCCS baseline controls. Links open the publisher’s site.

Need help? Browse the directory or read the guides.

References

  1. Baseline cyber security controls for small and medium organizations, Canadian Centre for Cyber Security
  2. Top measures to enhance cyber security for small and medium organizations (ITSAP.10.035), Canadian Centre for Cyber Security
  3. Foundational cyber security actions for small organizations (ITSAP.10.300), Canadian Centre for Cyber Security