Overview
Top 10 IT security actions to protect Internet connected networks and information, ITSM.10.089, is the Canadian Centre for Cyber Security's short list of the measures that most reduce the risk of compromise. It was published in September 2021 and replaces earlier versions, ITSM.10.189 and ITSB-89 version 3. Federal departments were the first audience. The actions apply just as well to any organization that runs its own network or uses cloud services.
The list starts at the network edge with consolidating, monitoring, and defending Internet gateways, then moves to patching, controlling administrative privileges, and hardening operating systems and applications. It continues with segmenting information, giving staff tailored training, protecting information at the enterprise level, adding host-level protection, isolating web-facing applications, and using application allow lists. Most actions have a companion guide. One example is ITSM.10.094 on managing administrative privileges, published in July 2022.
It isn't a certification. There's no assessment scheme or certificate, and organizations use it as a quick gap check or a roadmap, often alongside the Cyber Centre's baseline controls for small and medium organizations. Smaller organizations that find the list too broad can start with ITSAP.10.035, which recommends 4 starting controls. Its themes also appear in CPCSC Level 1 and in the GC Cloud Guardrails. The list dates from 2021, so pair it with the Cyber Centre's more recent advisories and guidance.
Who it applies to in Canada
Any organization with Internet-connected networks, written first for federal departments and widely used by businesses, public bodies, and non-profits.
It's the Cyber Centre's own priority list, and federal and provincial bodies often cite it as a minimum. Each action links to a detailed Cyber Centre publication.
Controls at a glance
ITSM.10.089 lists 10 numbered actions, grouped here by where they apply.
Network edge and segmentation (actions 1, 5, 9)
- Consolidate, monitor, and defend Internet gateways
- Segment and separate information by sensitivity
- Isolate web-facing applications
Systems and software (actions 2, 4, 8, 10)
- Patch operating systems and applications
- Harden operating systems and applications
- Apply protection at the host level
- Implement application allow lists
People and privileges (actions 3, 6)
- Enforce management of administrative privileges
- Use multi-factor authentication for admin accounts
- Provide training tailored to staff roles
Information (action 7)
- Protect information at the enterprise level
- Assess and classify information by sensitivity
- Manage retention and secure disposal
- Check external and cloud services before sharing data
- Keep separate backup copies of critical data
Certification and assessment
Organizations compare their environment against the 10 actions and the related Cyber Centre guidance, then plan fixes. There's no certificate or attestation.
Dates to know
- 2021-09
- ITSM.10.089 published, superseding ITSM.10.189 and ITSB-89 version 3
Resources
Official texts and free tools for CCCS Top 10. Links open the publisher’s site.
- Top 10 IT security actions to protect Internet connected networks and information (ITSM.10.089), Canadian Centre for Cyber Security
- Top 10 IT security actions No. 3, Managing and controlling administrative privileges (ITSM.10.094), Canadian Centre for Cyber Securityguidance
- Baseline cyber security controls for small and medium organizations, Canadian Centre for Cyber Securityguidance
Need help? Browse the directory or read the guides.
References
- Top 10 IT security actions to protect Internet connected networks and information (ITSM.10.089), Canadian Centre for Cyber Security
- Top 10 IT security actions No. 3, Managing and controlling administrative privileges (ITSM.10.094), Canadian Centre for Cyber Security
General information, reviewed 2026-10-11. Not legal advice. Confirm requirements with the publisher, your regulator, or a qualified advisor.