Who this applies to
Federal departments, their suppliers, and organizations that align to Government of Canada security practice.
What to know
- It sets out a lifecycle for managing IT security risk, from planning and design through operation and disposal.
- It uses a catalog of security controls and profiles, so requirements can be tailored to the sensitivity of a system.
- Public sector security assessments and many supplier requirements still point back to it.
What to do
- Confirm which control profile your contract or department requires.
- Keep assessment evidence organized by control, because reviewers ask for it that way.
This guide is a plain-language summary for general information. It is not legal advice and it does not replace the official source. Requirements change, so check the linked source before you act.