// guides
Cybersecurity guides for Canada
12 guides, each written from the official source and linked to it.
Frameworks and controls
The control sets and risk frameworks Canadian organizations build programs on.
Baseline cyber security controls for small and medium organizations
A practical starting list of controls written for organizations under 500 employees.
Read the guide →NIST Cybersecurity Framework 2.0
A widely used outcome-based framework for organizing a security program and explaining it to executives.
Read the guide →CIS Critical Security Controls
A prioritized set of 18 controls, with implementation groups that scale to organization size.
Read the guide →ISO/IEC 27001 information security management
The international standard for running an information security management system, with third-party certification.
Read the guide →ITSG-33 IT security risk management
The Government of Canada lifecycle approach to managing IT security risk, widely referenced in public sector work.
Read the guide →Privacy and breach duties
What the law expects when personal information is lost or exposed.
PIPEDA breach reporting
Private-sector organizations must report certain breaches, notify people, and keep a record of every breach.
Read the guide →Quebec Law 25 confidentiality incidents
Quebec requires organizations to manage, record, and in serious cases report incidents involving personal information.
Read the guide →Sector and contracting
Rules and assurance schemes that come with a regulator, a contract, or a customer.
OSFI Guideline B-13 technology and cyber risk
Expectations for how federally regulated financial institutions govern and manage technology and cyber risk.
Read the guide →CPCSC for defence suppliers
The Canadian Program for Cyber Security Certification sets cyber requirements for suppliers on defence contracts.
Read the guide →SOC 2 reports
An independent auditor report on a service organization’s controls, often requested by customers.
Read the guide →PCI DSS for card payments
The industry security standard for any organization that stores, processes, or transmits payment card data.
Read the guide →Incident response
What to do before and after something goes wrong.