home / guides / baseline-cyber-security-controls

Frameworks and controls · Canadian Centre for Cyber Security

Baseline cyber security controls for small and medium organizations

A practical starting list of controls written for organizations under 500 employees.

Who this applies to

Small and medium organizations that need a defensible starting point and do not have a security program yet.

What to know

  • It is written by the Canadian Centre for Cyber Security for organizations that meet the federal definition of small or medium, under 500 employees.
  • The controls are grouped into 13 categories, among them incident response planning, patching, anti-malware and firewalls, secure configuration, multi-factor authentication, awareness training, backups, mobile devices, network perimeter, cloud providers, website security, access control, and portable media.
  • It also asks the organization to document its systems, assess potential harm, name its main cyber threat, and commit leadership and budget.
  • The list is deliberately short. It is a floor, not a full security program.

What to do

  • Score your organization against each category and write down the gaps.
  • Fix multi-factor authentication, patching, and backups first, because they stop the most common attacks.
  • Test a restore from your backups before you need one.