Organisme canadien de certification accrédité par le CCN (Conseil canadien des normes)
Développement communautaire

Webinaire enregistré le 6 mars 2024

Certification CyberSécuritaire Canada pour les CFDC de l’Ontario

Une présentation pour les dirigeants, les conseils d’administration et les équipes des organismes de développement des collectivités de l’Ontario (CFDC, Community Futures Development Corporations). Bronwyn, de Complade, explique la certification à partir de situations familières en audit et en gestion.

Enregistrement historique. Les prix et certaines modalités de 2024 ne constituent pas une offre actuelle. Voir les précisions actuelles.

Présentation en anglais, avec sous-titres anglais issus de la transcription fournie. Durée : 32 min 29 s.

Dans cette présentation

La séance aborde les questions d’une petite équipe qui se prépare à la certification : qui met en place les pratiques, qui réalise l’audit indépendant et quelles preuves permettent de montrer que les procédures sont suivies. L’introduction évoque aussi une précédente séance tenue en novembre.

  • Les rôles de la direction, des intervenants en mise en œuvre et de l’organisme de certification.
  • La différence entre une politique, une procédure et les preuves de son application.
  • La revue documentaire, les entretiens et le traitement des constats d’audit.
  • Le maintien des pratiques lors des changements de personnel, de logiciels et de services.

Le fichier fourni se termine au début de la période de questions; il ne contient pas de séance complète de questions-réponses.

Précisions pour les lecteurs actuels

Ces précisions sont distinctes de la présentation enregistrée. Mise à jour du 8 octobre 2026.

  • L’accréditation repose sur une évaluation de la compétence et de la conformité. Elle ne s’obtient pas simplement par l’achat d’une qualification. Vérifier l’accréditation de Complade.
  • La durée d’audit, les délais de correction, le suivi et le renouvellement dépendent du programme applicable et de l’entente. Les exemples et nombres cités en 2024 ne constituent pas des règles universelles. Consulter le processus actuel.
  • Les auditeurs constatent les écarts et évaluent les mesures prises. Ils ne mettent pas en œuvre les solutions pour le client. La délivrance d’un certificat dépend d’une décision de certification indépendante.
  • L’embauche d’un consultant et l’achat d’un outil nommé dans la vidéo ne sont pas obligatoires pour obtenir une certification auprès de Complade.
  • Le tarif et la remise présentés dans cette séance sont historiques. Consulter les prix et hypothèses actuels.

Ressources pour votre organisation

Transcription anglaise

Transcription fournie avec l’enregistrement. Les erreurs évidentes dans les noms Complade et CFDC ont été corrigées; les propos restent ceux de la séance de 2024 et d’autres erreurs de transcription peuvent subsister. Les précisions ci-dessus s’appliquent notamment aux prix, aux exigences et à l’impartialité.

Télécharger la transcription en texte

0:00 Welcome and Ontario CFDC context

see the title d uh title of the session is demystifying the cybersecurity canada certification and we've been working with Complade on um helping the southern CFDCs get through those final stages of the certification and they have some valuable uh information and resources that they'd like to talk to you about so i'll let them take over the meeting and i know that i have to leave a little bit early so i won't be here at the end but denise will be here and keeping an eye on the chat and after any comments or

questions so uh doing the presentation today will be bronwyn from Complade and take it away

0:39 Why this session was held

thanks anna and hello everybody uh welcome to our webinar um we had another webinar in november i'm not sure if anyone was present for that but um previously we talked about um sort of the financial risks of cyber security and the implications of that and sort of what you can do and what kind of costs they'd be running you on average and sort of setting up the situation to deal with now i understand we're at a stage where we now need to do that and deal with it and sort of we've

taken in the costs and you know certain uh groups have received funding and um sort of it's it's it's a great time and an opportunity to move forward with that but it can be a little bit daunting um it can look like a long process a lot of things to sort of muddle through a lot of technical language so today our objective is really to strip away some of that technical jargon and just let you know what you're looking at what the process will be like and break down the concepts a little bit so that you can hopefully have a greater

understanding and not have to rely so heavily on people totally outside of your sphere and what you do on the daily basis so just to begin this is me um bronwyn i am the analyst for Complade and i'm usually giving these presentations and i am sort of the go-between client relations whatever i wear i wear many hats but if at any point you want to reach out to me for any questions or to get in contact with anybody from our company

um or you need help um directing where to go you can always email me my contact information will be at the end so let's get started just to let you know about Complade we are a cyber security standards conformity auditor uh we deliver an informed sense of assurance that your risks and controls are in balance and so we partner with boards of directors and senior management teams to solve cyber security assurance and governance challenges we provide impartial audits tailored to your organizational objectives based on de jour standards that's just our

little disclaimer at the beginning and here's our certificate um showing we are an accredited management system certification body that means we can give you the certification and complete your audits given to us by the standards council of canada who's the one who decides um basically who does and does get these things if you're qualified we bought the qualification from them and there's our certificate um and just to let you know as another disclaimer we are one of four groups in canada who offer this um what they call certification bodies

those have been accredited by standards council of canada or scc um we offer you the ability to connect with any of these i understand bulletproof for example has a long-standing relationship with CFDCs do the tech part uh we're just kind of coming into the game here to offer um educational services and let you know what's up so that hopefully you can learn from us the agenda today we will just talk a little bit about what all of this means from financial audits and something you might

be a little more familiar with to a cyber security audit which likely you are not unless you have done most of the process or better yet completed it um to understand the cybersecure canada ecosystem um all the parts of the hole that make up the standard that it is now the pasta certification what you actually need to do to achieve the certificate and the next steps that you should take um after today hopefully starting this afternoon and then we'll open up at the end to a q a so from financial audits to a cyber

4:32 Financial audits and cybersecurity audits

security audit we will start with something that i hope everyone here is very familiar with the gap principles in accounting um basically if um what we think is a great way to understand a new concept is to take old concepts and apply the parallels there you know this is a new system that everyone in the world is getting used to cyber security is obviously relatively new reflective of technology and all the advancements over the last you know couple decades and especially five years or so

whereas accounting and financial audits are all very familiar to us because they have been the standard for a long time and for most of our working lives and something that we just know that we have to do we have to do taxes every year we have to do our business audits we have to keep our books we've all worked with cpas we've all worked with bookkeepers um you know it's just something that we're used to and something that we don't say like okay like should we get this done it just it just is and we we sort of hope that as we coast along with this industry that cyber

security audits will be something that just are as well uh they're incredibly crucial and it's not yet clear to a lot of people why they're as crucial as your financial audits but um they follow sort of a similar framework so we will get into that so this is a graph that i think everyone will recognize as well just to um give some background that um basically for the past 25 years the annual financial audit has served as a pivotal framework for corporate integrity and transparency driven by historical necessities and much much

precedent such as this the enron scandal and the resulting sarbanes-oxley act the sox act um basically uh this shows a progression from a financial chaos to a structured accountability where here you see stock prices fell so drastically in the year 2000 that basically there had to be a scramble to come up with a standard to level it and bring it to a place where everyone was you know annually updating their information to make sure that it didn't

go all over the place you don't lose track of it because obviously then we headed further towards a financial recession and i can only imagine that if in 2008 if these standards weren't in place how unaccountable businesses would have been um how much people would have how much more we imagine people would have lost how much more chaos it would have been and you know the thing to take away here is that there is always going to be chaos so the better controls we have in balance to mitigate those risks and the

resulting chaos hopefully not too much is to have a system and like i said we have a new system here cybersecure canada is just an example of it it's the one that you will all get but there are versions of cybersecure canada all over the world for all different kinds of businesses suiting all different kinds of needs and they all adhere to these similar principles and structure as something like gap that we use in accounting um basically um you know it was and it was an optional

thing and like i said we'd like it to move a little bit further from the trajectory of an optional precaution to a critical and more standardized necessity um so that it mirrors the financial systems and because just as financial standards like gaap have been instrumental in restoring trust and stability in financial reporting as is the principle of a standard itself cyber security standards such as iso 27001 you may have heard um very similar to cyber circuit canada which we now have they have been developed to safeguard digital assets

and data just like financial ones safeguard your money and how do we implement this accounting system in an organization it's in four simple steps first of all you have a cpa who implements the accounting system for your business then the cpa will recommend an accounting tool such as quickbooks sage tools that again you will be familiar with and that everybody uses this just shows how these things can be complicated but once you use them you look at it as just commonplace and yeah we we do that every day and you know a student can be

trained to do it fresh out of undergrad and someone who's been in their career 35 years can probably learn how to do it they're adoptable and that is great um the next step crucially on that is that you get everyone trained in it so the cpa will then branch out to train assistance on bookkeeping and then eventually reach others in the organization lastly another cpa a different impartial auditor outside of this structure will audit the books and deliver your annual audit report

9:36 Understanding the standard

so how does this work for cybersecure canada well there is a standard that we follow um some of you may have seen it we are more than happy to send it out or to go through it with you at a later date um this is the standard that lets you know we'll take a quick look at the index here exactly what your organization needs to do to meet the requirements to get that certificate um i think there are 18 different controls and points that you need to meet um we won't go through it too

detailed but basically there are the organizational controls so that's the main points within your organization your actual employees in your office which is the leadership the accountability cyber security training and cyber security risk assessment which looks at your exact organization who's working there what do you need to do who's in charge who's going to be accountable for getting all of this done then the actual nitty-gritty which is the baseline controls you need to create an incident response plan

patch your operating system make sure your software is up to date make sure you have a system for your devices whether you bring your own phones whether the phones need to have work done whether the company issues phones etc etc um these are all the little things that you will encounter on your way that you need to keep track of and um there's quite a lot but it does all fit on this one page so it is definitely manageable um

11:02 Implementation, software tools and independent auditors

to understand that you need to understand the ecosystem of a cyber security um organize a certification basically what are the parts to this hole that we're talking about so achieving the cybersecure canada certification does require a structured ecosystem quite similar to that of the financial auditing as we said and it's comprised of several parts one implementers that's just like your cpa they are certified professionals such as cyber security lead implementers trained in setting up cyber security environments following iso 27003 and

other relevant guidelines like this one then you have your grc tools grc stands for the cyber security governance risk management and compliance they range from spreadsheets um you know using excel basically logging things writing them down keeping lists to more specialized software like vanta drata and maple grc these are tools that the implementers use which support the implementation and ongoing activities of your cyber security management finally you have your independent auditors just like that second cpa who comes in there is an auditor who has to

who hasn't been a part of your process initially um and they haven't looked at anything until you are prepared to do your audit they are accredited certification bodies by the standard council of canada like us so just to map out what they look like the implementer starts out just like the cpa implementing your system then they recommend a tool to use just like your quickbooks or sage which um is you know used by a specialist and then given to everyone else so that people can train and learn it as a commonplace

tool just as we use excel the implementer will then train assistants and further the rest of the company and hopefully it spreads and the cybersecurity auditor finally audits your cyber security and delivers your annual audit report very similar system following different standards and dealing with slightly different information but basically an audit is an audit we have all done them and they can be time consuming and taxing but um once you understand the system and you have professionals in place to help you it can be

quite painless and not take too long so the path to certification uh what does it look like basically you take that initial implementation phase and ideally you arrive at a place where you are just maintaining and all the work is done and after your initial audit is done we hope that you're in a place where again you know what to do you're familiar with the system you have people in place to deal with everything and you just maintain you just tweak little things you know if you hire someone new you let them know if you totally change

your software and your systems you adjust that to show that that's what you're going to be using in three main parts we begin with the initial implementation establishing the security framework within the organization guided by the standards and facilitated by certain implementers step one the initial implementation looks a

14:12 Policies, procedures and audit evidence

little bit like this this is basically what do you do when you begin the process how do we actually do the audit how does it work we start with a security manual that is your policy and the document that you are going to generate that says we are going to adhere to cybersecure canada because we are going to do this this and this now that's all well and good to have a claim a policy that says you're going to do something but you know who's going to implement that who's going to check up on it what's in it where do you begin

how do you organize that how do you structure it the next step is the standard and guideline procedures describes who what when and where so that's who's in charge who's doing it who's being trained on this you know who works here who uses what computer etc then you have your working checklists forms and controls that describes how the specific tasks and activities are done so we take an example of we were just talking about a restaurant when you have your your health checkups when the health inspector comes and they have to make sure

you know okay you say that this is a a clean and sanitary restaurant but who is in charge of that that takes number one is your claim your policy number two is the management and the employees who uh implement this and enforce this number three your working checklist forms controls that's your chart on the bathroom for daily cleaning that's who signed off on who mopped in the kitchen just a list that keeps everybody accountable and organized of what exactly needs to be done and how that will work and then finally number four that is your

material evidence your records what is going into everything so when someone says okay yes we made a form but also here's the inventory for the cleaning products that we bought and this is where they're kept and here's the book of all the previous logs from the past six weeks of all the cleanings and basically everything that you collect and use is evidence so that when the auditor comes and says okay well i see that you have a form in place to show that you're doing this but where is the evidence to show that you've been doing this for the last 11 months since

i've been here because one day of cleaning is obviously not sufficient to prove that you adhered to their to your policy so that's your bulk of records and that's the paperwork that you can have a little help with collecting because it can be pretty overwhelming i would say that of all the parts looking at all of your stuff and thinking what do we do with all of this is probably the most daunting so um that's why the system is here to just begin at step one and break it down piece by piece then the certification process itself

undergoing a rigorous audit by an independent certified auditor to verify adherence to cybersecure canada standards culminating in the issuance of the certification much like your annual financial report that is a certificate that you will get from cybersecure canada um it looks a little bit okay next step so basically we look at

17:16 Stage 1, Stage 2 and findings

our process like i laid it out number one that you have to do in this process is submit your documents that's after you've done everything from the initial implementation here once you've looked at your steps when you've got gathered everything once you've worked with an implementer to figure out you know how are we going to organize this and then how are we going to make it into basically a package of documents that we give in to the auditor that is the first thing that you do once you are ready to give it into the auditor once you have done your

implementation once once you have slogged through all of your work all of your documents made sure that everything is checked off in the cyber secure canada standards list you've reached all 18 points you've generated a policy that says you are going to reach all 18 points then you take all of that and you give it to your auditor what they will do is begin stage one which is once they have access to your documents they will um look it over um make sure that there's nothing missing um you know get you to a place

where you and they will collectively decide that you're ready for stage two where then you sit together with the auditor online in person whatever works for you you basically have one day set aside to be with your auditor where they look at your documents and they say okay we took a look you prepared we let you know what we you needed to fix let's make sure and the auditor will ask you questions like okay have all your employees done the training for uh let's say phishing one that we all know

does everybody know how to recognize you know scam links and emails okay yes they do right well then who are your employees let's see that all the employees have taken the training you will need some evidence of that you know screenshots people giving certificates from completing trainings online whatever you have collected to show that your employees have indeed completed the trainings and can demonstrate knowledge that they gain from it once that is finished the auditor will um take a look at everything they will

let you know absolutely if um i'll just go next to let you know here they will go across all the requirements one by one and they will see policy procedure and proof of it happening like i said evidence or a screenshot important to note they will share with you what is missing so it's not like an exam at school where if you're missing something you don't pass and then you begin all over again the point of sitting all day with the auditor is because rather than them taking a couple hours to independently review your information they want to share with you what you can do and give you the

opportunity to fix it you will have then six months to fix what is missing and share that with them if there are major things missing like nobody completed training highly highly unlikely and no implementer would recommend you go into your audit without that but for example if there's something missing they will let you know and it will be you know pretty obvious and they'll say look you need to complete this and this is what you need to do and here's who you can work with and whatever and there are always opportunities to fix things once you're on the system basically you are set up to succeed it is not set up

to make you fail and once it's fixed you will get certified um after let's go back to our process here uh just to

20:30 Maintaining certification

sort of summarize the last two points here the annual surveillance and the re-certification the important thing to know is that it is an ongoing process they're sort of once you get your certificate it does certify you for two years but it's a little confusing because your policy will say you know we declare that we are going to do this this and this within the next year and they need to check up on you at the end of that year to make sure that you did in fact do everything that you claimed you were going to do in your audit there's sort of a surveillance

audit just to make sure that everything is going well and um get you that certificate you know lasting your second year at the end of that second year you will then need to recertify because several things in an organization can change in a year just like we do our taxes every year just like we do any audits they're cyclical and they have to reflect the evolving rotating nature of not only cyber security threats the new things that can come up new things that you may have to train employees on but your organization what turnover you may have

what new revenue you may take in what new organizational systems you might implement so basically um it's pretty manageable like i said once you have done the whole bulk of the thing all subsequent ones are just an issue of maintenance and you just need to like update it as it goes along it will get easier and easier once an organization we hope in the future has done 40 50 of these it will just be a quick thing that you need to set aside a little time to do every year so

this is basically just an example of the audit report um it will let you know you know you can you can take a look at what the auditor is going to do sort of the limitations um the classification of what means a major non-conformity what is a minor non-conformity like what's a big thing that you're missing and what's not a big deal what is absolutely necessary to have in there what needs to be fixed sooner rather than later what it will look like

um you will know basically for all steps in this process exactly what it will look like beforehand and you will be i hope 100 prepared and this is the certificate you'll get this is what it will look like you can display the seal here it will be personalized to your organization you can display it on your website it's really great for clients and all your future stakeholders board members just to let them know that it's something that you put time into and that you care about safeguarding their data their financial information

it's a great sense of assurance and not only does it establish trust with your clients but your boards the people that are giving you money the people that you work with it's a whole system and we talked about the concept of an ecosystem it's really important to maintain trust accountability transparency make sure that everything is above board and that's basically why we have standards and um this is just sort of a fun thing that you get you can print it out frame it just like any other certificate um and this is the seal that cybersecure canada will give you

and then this is a custom seal that we will give you so the ongoing maintenance what do you do once you get your certification and basically how does that work it's the continuous monitoring um of um an updating of your cybersecurity practices to ensure your compliance with like i said the evolving landscape of cyber threats and standards but also of your organization what does that require quarterly training you know updating on new things you need to train employees on or new

employees that need to be trained from the get monthly checking access to your systems for example prior employees that don't have access making sure that someone has left the company that they don't still have access their passwords are changed they're removed from the system the due diligence is done appointing updating your software when you get those little reminders that say you know please update your computer tonight whatever just try to click yes and all that kind of thing once you go into this process it will be very clear with you what is worth it to maintain and what you need

to be doing on a regular basis so

24:43 Next steps at different stages

let's take a little breather here because this was a lot of information it's sort of you know it's all well and good to say okay this is how the certification works but you may not be at that stage you may have no idea what iso is or what security logs are or patches or softwares or all this kind of thing so the question is what do you do now regardless of what stage you're at whether you are just beginning whether you are looking down the barrel at the day that you have to get this done or you are one step away and you're ready to do your audit next week if

that's the case call us but basically we need to let you know what are the next steps regardless of what stage you're at so you find an implementer first of all to help you out that can help you hugely to muddle through the system and implement the cybersecure canada standard it's not something that you individually as an organization every single member needs to intricately understand the standard but you do have to have an idea of the gist of it and an implementor is a professional who works with something like this

to help you there to help you understand it next once you've done your implementation once you've worked through and reached met all the requirements of the standard you will reach out to a certification body to get certified then all you have to do like i said is maintain your system and of course every year you will renew it you will complete the yearly audits that will be a breeze as long as you're maintaining so where to find an implementer you want to make sure that your implementer has

iso lead implementer certification that's the classification that says that they can take you from your information that you have now and get it to the standard of cyber secure canada or whatever standard you're meeting whatever certification it is you want to achieve um many implementers work with many different kinds of certification they're all kind of similar when it comes down to it it's just the nitty-gritty of what certification you're trying to achieve here we're trying to do cybersecure canada so we

are more than prepared because um everybody is working towards the same goal which is great and your implementer will certainly uh be able to get you there they will have the ability to lead you there here are examples of some implementers you can use drada maple six clicks they're all over the place if you sort of muddle through and um you wanna use somebody who like we said has that lead implementer certification um basically who is able to work with you um help you use this tool the grc tools um like using

quickbooks and help your organization get on board with that and get all your information built into a software that hopefully is you know highly specialized and um can take what you have and sort of organize it automatically and make it not look like a huge bulk of documents but rather a well-oiled machine with easy to read charts that kind of thing so once you are implemented once all of that is done you need to reach out to a cybersecure canada accredited certification body now here again are some examples here are the four that can issue you the

cybersecure canada certification um if you look online at different certification bodies they do offer you know iso and the various other certifications you may seek to achieve after cyber secure canada but we will start here and so here is your scope then basically all you need to do is keep running your security management system to keep a sense of assurance of course that your cyber risks and controls are in balance now that is a statement that basically encapsulates what it is we are doing here we just

want to create a sense of assurance we want to make everybody feel okay about their systems we want to make it so that people aren't hearing news articles about hacks that are happening every day and thinking that we are plummeting towards the equivalent of a financial crisis in the cyber security world and say well we're going to get ahead of this and do what needs to be done give yourself a sense of assurance instead of seeing the news articles and saying oh my god like do i need to change my password what do i do to prevent us

being hacked and all of our client data being leaked well this is exactly what you need to do just gives you peace of mind assurance is just you thinking okay i've done what needs to be done i've done cybersecure canada as a standard for a reason they tell you what they think needs to be done in your organization to get you to a point where all of those risks are in balance and you know exactly how to mitigate them if and when

29:13 The CFDC offer discussed in 2024

the time comes so for the CFDCs here we have um for our audit should you work with us and should you be at a stage where you're ready to do audit you're completed your implementation the stage one and stage two so the part where the auditor actually works with you with your data takes your documents and then reviews it together with you is just over a thousand here we have a little bit of a discount for the CFDCs um because we've been working with you guys for a little

while and because you're a collective organization with whom we like to build trust and that sense of assurance as well um we basically uh can't because we are auditors we have to remain impartial we can't offer you that implementation but when you are ready we will be here when you're at the stage where hopefully all of that hard work is done and you're ready to just give over your documents to us get that audit and get that beautiful certificate we will be here

30:15 Closing remarks

when you need and so in conclusion here we'll just sort of give a statement of um what it is we need to remember about the audits here and especially cater to businesses like the cfdc small financial services organizations we know that navigating the complexities of the cybersecurity world and all of this language and this whole process can be very daunting however by understanding i hope the parallel between financial audits and cyber security certification we hope that leaders board members

executive directors everybody involved in your organization can eventually get on board and understand this language by appreciating the importance of cybersecure canada and a certification like this in establishing a robust cyber security posture the certification not only enhances an organization's security measures but also reinforces its credibility and trustworthiness in the eyes of stakeholders as digital threats continue to evolve embracing standards such as a cybersecure canada will be pivotal in safeguarding the future of financial

services organizations and all of the sensitive data that you manage so we will open it up now to a quick q a if anybody has questions um we have a couple of us here from uh Complade um if you have questions about anything in the presentation if you have questions about what should you do next and particular to your organization anything that you like we are here to answer so i will open up the floor to start um also yeah yeah just posted in the chat here if anybody needs full details for the certification process

um you can go to our website we'll have that displayed here and i will show it helpful here at the end if you need to ask specific questions you need a little more time of it you can email me you can set up a meeting give us a call come by your office whatever you like um yes hand raised and