home / frameworks / cccs-top-10

// Canadian government guidance

Top 10 IT security actions to protect Internet connected networks and information (ITSM.10.089)

The Cyber Centre's list of 10 priority IT security actions, from defending Internet gateways and patching to admin privilege control and application allow lists. ITSM.10.089 was published in September 2021.

CanadaVoluntaryITSM.10.089 (September 2021)

Overview

Top 10 IT security actions to protect Internet connected networks and information, ITSM.10.089, is the Canadian Centre for Cyber Security's short list of the measures that most reduce the risk of compromise. It was published in September 2021 and replaces earlier versions, ITSM.10.189 and ITSB-89 version 3. Federal departments were the first audience. The actions apply just as well to any organization that runs its own network or uses cloud services.

The list starts at the network edge with consolidating, monitoring, and defending Internet gateways, then moves to patching, controlling administrative privileges, and hardening operating systems and applications. It continues with segmenting information, giving staff tailored training, protecting information at the enterprise level, adding host-level protection, isolating web-facing applications, and using application allow lists. Most actions have a companion guide. One example is ITSM.10.094 on managing administrative privileges, published in July 2022.

It isn't a certification. There's no assessment scheme or certificate, and organizations use it as a quick gap check or a roadmap, often alongside the Cyber Centre's baseline controls for small and medium organizations. Smaller organizations that find the list too broad can start with ITSAP.10.035, which recommends 4 starting controls. Its themes also appear in CPCSC Level 1 and in the GC Cloud Guardrails. The list dates from 2021, so pair it with the Cyber Centre's more recent advisories and guidance.

Who it applies to in Canada

Any organization with Internet-connected networks, written first for federal departments and widely used by businesses, public bodies, and non-profits.

It's the Cyber Centre's own priority list, and federal and provincial bodies often cite it as a minimum. Each action links to a detailed Cyber Centre publication.

Controls at a glance

ITSM.10.089 lists 10 numbered actions, grouped here by where they apply.

Network edge and segmentation (actions 1, 5, 9)

  • Consolidate, monitor, and defend Internet gateways
  • Segment and separate information by sensitivity
  • Isolate web-facing applications

Systems and software (actions 2, 4, 8, 10)

  • Patch operating systems and applications
  • Harden operating systems and applications
  • Apply protection at the host level
  • Implement application allow lists

People and privileges (actions 3, 6)

  • Enforce management of administrative privileges
  • Use multi-factor authentication for admin accounts
  • Provide training tailored to staff roles

Information (action 7)

  • Protect information at the enterprise level
  • Assess and classify information by sensitivity
  • Manage retention and secure disposal
  • Check external and cloud services before sharing data
  • Keep separate backup copies of critical data

Certification and assessment

Organizations compare their environment against the 10 actions and the related Cyber Centre guidance, then plan fixes. There's no certificate or attestation.

Dates to know

2021-09
ITSM.10.089 published, superseding ITSM.10.189 and ITSB-89 version 3

Resources

Official texts and free tools for CCCS Top 10. Links open the publisher’s site.

Need help? Browse the directory or read the guides.

References

  1. Top 10 IT security actions to protect Internet connected networks and information (ITSM.10.089), Canadian Centre for Cyber Security
  2. Top 10 IT security actions No. 3, Managing and controlling administrative privileges (ITSM.10.094), Canadian Centre for Cyber Security