Introduction to Standards
Overview of frameworks such as ISO, National Institute of Standards and Technology Cybersecurity Framework (NIST CSF), and System and Organization Controls 2 (SOC 2)
Portal loginComplade is accredited by the Standards Council of Canada to provide ISO/IEC 27001 and CyberSecure Canada certification services.
Complade is accredited by the Standards Council of Canada to provide ISO/IEC 27001 and CyberSecure Canada certification services. To protect impartiality, Complade does not provide consulting, implementation, or internal audit services.
These free educational resources introduce CyberSecure Canada terminology and requirements. They are general information only and are not implementation guidance tailored to a specific organization.
For questions, contact your Complade account manager or email info@complade.com.
The control library below is aligned to the supplied CAN/DGSI 104:2021 / Rev 1:2024 audit workbook. Always use the current standard, available from the Digital Governance Council, as the authoritative source. The older videos are retained as general background only.
This pathway is designed to guide individuals from no prior experience to becoming knowledgeable of CyberSecure Canada standard
Basic understanding of information security.
Understand the foundational concepts of CyberSecure Canada and related standards.
Standard https://dgc-cgn.org/product/can-dgsi-1042021-rev-12024/
The library below covers all 18 control families and 83 auditable requirements identified in the supplied CAN/DGSI 104:2021 / Rev 1:2024 audit workbook. Requirement wording is separated from practical implementation guidance and examples of evidence an auditor may examine. This educational guidance does not replace the standard or advice tailored to your organization.
5 auditable requirements
Top management shall demonstrate their commitment to the cyber security program by:
ensuring the cyber security policy and objectives are established and are aligned with the strategic direction of the organization;
Develop a comprehensive cyber security policy that aligns with the strategic goals of the organization. This policy should include specific objectives that are measurable and achievable.
Provide the cyber security policy document, along with minutes from meetings or communications where top management discussed and approved the policy and its alignment with the organization's strategic direction.
Top management shall demonstrate their commitment to the cyber security program by:
ensuring that the resources needed for the cyber security program are available and are aligned with the cyber security policy and objectives;
Allocate necessary resources including budget, personnel, and technology to support the cyber security program. This may involve hiring skilled personnel, investing in security technologies, or allocating funds for training and development.
Prepare financial reports, hiring records, and investment documents showing resource allocation towards cyber security. Additionally, training records and procurement documents for security tools and technologies can be presented.
Top management shall demonstrate their commitment to the cyber security program by:
communicating the importance of effective cyber security and of conforming to the cyber security program requirements;
Top management should actively communicate the importance of cyber security to all levels of the organization. This can be through company-wide emails, meetings, training sessions, and regular updates on cyber security matters.
Provide copies of communications sent to employees, agendas or minutes from meetings where cyber security was discussed, and records of any cyber security awareness programs conducted.
Top management shall demonstrate their commitment to the cyber security program by:
establishing cybersecurity program metrics and tracking progress; and
Define clear metrics to evaluate the effectiveness of the cyber security program. These could include the number of incidents handled, response times, training completion rates, or system audit results. Regularly review these metrics to track progress.
Compile reports that show the metrics being tracked over time. Include documentation on how these metrics were established and how they are regularly reviewed by management.
Top management shall demonstrate their commitment to the cyber security program by:
supporting other relevant management roles to demonstrate their leadership as it applies to their areas of responsibility.
ensure that other management roles are empowered and have the necessary resources to uphold their cyber security responsibilities. This involves clear communication of roles, responsibilities, and expectations to all managerial staff.
Provide organizational charts, job descriptions, and policy documents that outline the cyber security responsibilities of various management roles. Also, include records of meetings or communications where support from top management for these roles is evident.
5 auditable requirements
Top management shall appoint a member of the senior-level leadership team to oversee and be accountable for the organization’s cyber security. Accountabilities of the member of the senior- level leadership team shall include the following:
developing and implementing a company-wide information cyber security program to meet baseline cyber security controls;
The appointed senior-level leader should develop and implement a comprehensive cyber security program that addresses all baseline cyber security controls. This program must cover various aspects such as risk management, incident response, and asset protection.
Provide the cyber security program document, project plans for implementation, and records of the program being discussed and approved in management meetings.
Top management shall appoint a member of the senior-level leadership team to oversee and be accountable for the organization’s cyber security. Accountabilities of the member of the senior- level leadership team shall include the following:
documenting and disseminating information security policies and procedures;
Create detailed information security policies and procedures, and ensure they are accessible to all employees. Regular updates should be communicated effectively.
Present the documented policies and procedures, evidence of dissemination (e.g., emails, intranet postings), and records of policy acknowledgments by employees.
Top management shall appoint a member of the senior-level leadership team to oversee and be accountable for the organization’s cyber security. Accountabilities of the member of the senior- level leadership team shall include the following:
coordinating the development and implementation of a company-wide information security training and awareness program;
Coordinate the development and implementation of an organization-wide information security training and awareness program. Ensure it is comprehensive and covers all employees.
Show training materials, schedules, attendance records, and feedback from participants. Include metrics demonstrating the program's reach and effectiveness.
Top management shall appoint a member of the senior-level leadership team to oversee and be accountable for the organization’s cyber security. Accountabilities of the member of the senior- level leadership team shall include the following:
coordinating a response to actual or suspected breaches in the confidentiality, integrity, or availability of the organization’s data; and
Establish a procedure for responding to security breaches. This includes identification, containment, eradication, and recovery processes, along with communication plans.
Document the incident response plan and provide records of any drills or actual incidents, including how they were managed and resolved
Top management shall appoint a member of the senior-level leadership team to oversee and be accountable for the organization’s cyber security. Accountabilities of the member of the senior- level leadership team shall include the following:
identifying organizational risks and prioritizing risk treatment relative to likelihood and potential impact of cyber threats.
Regularly identify and assess organizational risks related to cyber security. Develop a process for prioritizing these risks based on their likelihood and potential impact.
Produce risk assessment reports, risk treatment plans, and documentation showing how risks are prioritized and addressed.
5 auditable requirements
The organization shall train employees on basic security practices, including but not limited to the following practices:
Compliance with password policies (see Subsection 5.5);
Develop and provide training sessions on effective password policies, such as creating strong passwords, changing them regularly, and not sharing them.
Provide training materials, records of training sessions conducted (dates, attendees), and assessments or quizzes to demonstrate employee understanding.
The organization shall train employees on basic security practices, including but not limited to the following practices:
Identification of malicious communications and phishing;
Train employees on how to identify and handle malicious emails and links. This could include recognizing phishing attempts and understanding the risks of clicking unknown links.
Show training content specific to this topic, along with records of training completion and any assessments or practical tests conducted.
The organization shall train employees on basic security practices, including but not limited to the following practices:
Keeping employee devices and software updated.
Train employees to keep organization-managed devices, operating systems, browsers and approved applications updated. Explain how to recognize update prompts and where to report failed updates.
Training material covering updates and patching; completion records; device-management or patch-compliance reports; and sampled employee interviews.
The organization shall train employees on basic security practices, including but not limited to the following practices:
Principle of least privilege and basic access controls.
Explain least privilege in plain language: employees receive only the access needed for their work, do not share accounts, and request additional access through the approved process.
Training material covering least privilege and access control; attendance or completion records; knowledge checks; and sampled employee interviews.
The organization shall provide documentation that they provide regular and ongoing cyber security awareness and training for their employees.
Develop an Ongoing Training Program: Establish a continuous training program that covers various aspects of cyber security. This program should be updated regularly to include new threats, trends, and best practices. Schedule Regular Training Sessions: Organize training sessions at regular intervals (e.g., quarterly or bi-annually) to ensure continuous learning and awareness among employees. Incorporate Diverse Training Methods: Use a mix of training methods such as e-learning, workshops, webinars, and interactive sessions to cater to different learning styles. Customize Training Content: Tailor the training content to different roles within the organization, focusing on the specific risks and responsibilities associated with each role. Measure Training Effectiveness: Implement methods to assess the effectiveness of training, such as quizzes, practical exercises, or feedback surveys.
Training Program Documentation: Provide a comprehensive outline of the training program, including objectives, topics covered, and updates made over time. Training Schedules and Attendance Records: Present schedules of all training sessions conducted, along with attendance records to show employee participation. Training Materials and Methods Used: Share examples of training materials and describe the methods used for training delivery. Assessment Results: Provide results of quizzes, tests, or surveys conducted to assess the understanding and effectiveness of the training. Feedback and Improvement Records: Show records of feedback received from employees on training sessions and any subsequent improvements made to the training program.
11 auditable requirements
The organization shall conduct a cyber security risk assessment. NOTE: Refer to Cyber Security Risk Assessment Questionnaire in Annex B
The senior-level leader should regularly conduct comprehensive cyber security risk assessments. This involves identifying potential risks, assessing their impact and likelihood, and prioritizing them.
Provide documentation of the risk assessment process, including risk registers, assessment reports, and minutes from meetings where these assessments were reviewed.
The member of the senior-level leadership team appointed to oversee the organization’s cyber security shall conduct cyber security risk assessments and coordinate the implementation of cyber security controls to address potential cyber security risks. NOTE 1: The member of the senior-level leadership team appointed to oversee the organization’s cyber security should consult experts to review and provide input into the cyber security risk assessment and in the selection of controls to safeguard against cyber security risks identified and assessed. NOTE 2: The organization may consider the implementation of physical controls as part of its framework to mitigate cyber security risks.
Engage with cyber security experts to review and provide input into risk assessments and the selection of appropriate controls.
Maintain records of consultations with experts, including meeting notes, emails, and reports provided by these experts.
The organization shall develop and maintain an asset register of its information systems and IT assets, including records showing management’s understanding of the assets’ purpose. For any information systems and assets not included in their implementation of the baseline cyber security controls, the organization shall document all instances where they make the business decision not to do so.
Create and regularly update an inventory of all information systems and assets. Document any exceptions where baseline controls are not implemented.
Present the inventory list and any accompanying documentation justifying why certain systems or assets do not have baseline controls.
Inherent and residual cyber security risks accepted by the organization shall be documented and authorized by a senior official of the organization.
Document any cyber security risks that the organization decides to accept rather than mitigate. These decisions must be authorized by a senior official.
Provide the risk acceptance documents signed by the authorizing senior official.
The organization shall identify their financial spending levels for cyber security investment (as raw numbers and as a percent of total expenditures).
record and monitor the spending on IT and IT security, both as raw numbers and as a percentage of total expenditures.
Financial reports detailing IT and IT security spending.
The organization shall identify their internal staffing levels for cyber security (as raw numbers and as a percent of total staff).
Keep records of staffing levels in the IT and IT security departments, including raw numbers and percentages.
Human resources records and organizational charts showing staffing levels.
The organization shall commit to progressive improvements to cyber security.
Implement a plan for continuous improvement in cyber security, including regular updates to policies and technologies.
Documentation of improvement plans, records of updates made to cyber security practices, and reports showing progress.
The organization shall determine triggers and thresholds to conduct a new or update an existing cyber security risk assessment.
establish criteria for when to conduct a new or update an existing cyber security risk assessment, such as new threats, major system changes, or after an incident.
Documentation of the criteria and instances when risk assessments were triggered.
Regardless of the outcomes from the cyber security risk assessment, the organization shall implement the foundational or baseline cyber security controls specified in Section 5, and as appropriate, Section 6 based on its business environment.
Implement every foundational control in Section 5 regardless of the risk-assessment score. Evaluate each Section 6 control against the organization’s business environment and document applicability decisions.
Control applicability matrix; implemented-control records; risk assessment; documented Section 6 applicability decisions; and management approval.
The organization shall periodically review and/or test cyber security controls to ensure effectiveness. Testing and/or review shall take place at a minimum annually, or if a major change occurs in their system.
Create an annual control-testing schedule and repeat testing after major system changes. Define the owner, method, sample and expected result for each review.
Annual testing plan; completed test scripts or review checklists; findings; corrective-action records; and evidence of testing after major changes.
The organization shall provide documentation attesting to the total number of employees employed by the organization as well as part-time employees and contractors that may have access to the organization’s data.
Maintain a current workforce count that separately identifies full-time employees, part-time employees and contractors with access to organizational data.
Current HR roster or signed management attestation; contractor register; access lists; and a reconciliation showing who can access organizational data.
5 auditable requirements
The organization shall have an incident response plan for how to respond to different types of incidents of varying severity. If an organization is unable to manage some types of incidents on its own, the organization shall have a plan for what it will do.
Develop a comprehensive Incident Response Plan (IRP) that outlines procedures for responding to incidents of varying severity. Ensure it covers all aspects of incident management from identification to recovery.
Provide the IRP document, along with records of its development, updates, and approval by relevant authorities within the organization.
The incident response plan shall detail who is responsible for handling incidents including any relevant contact information for communicating to external parties, stakeholders and regulators (such as breach counsel), as well as what mechanisms to use for communicating during an incident response. The organization shall have an up-to-date hard copy version of this plan available for situations where soft copies are not available.
Clearly define roles and responsibilities within the IRP. Include contact information for individuals responsible for incident management and for communicating with external parties, stakeholders, and regulators.
The IRP should contain a section detailing these roles and contacts. Additionally, maintain an up-to-date hard copy of the IRP for situations where electronic versions are not accessible.
The organization shall test the incident response plan to ensure that the plan meets the intended outcomes. Where appropriate, this shall include any third-party cyber security service providers.
Exercise the incident response plan at planned intervals using realistic scenarios. Include relevant third-party providers when their services are part of the response and record lessons learned.
Exercise plan and scenario; participant list; test results; third-party participation records; lessons learned; and tracked improvement actions.
The organization should consider purchasing a cyber security insurance policy that includes coverage for incident response and recovery activities or provide rationale for not purchasing one.
Evaluate the need for a cyber security insurance policy that covers incident response and recovery activities. If deciding against it, document the rationale behind this decision.
Provide the insurance policy if purchased, or documentation outlining the rationale for not purchasing it, including risk assessments and decision-making processes.
The organization may use the incident response plan template (see Annex A) as a measure of satisfying requirements contained in Subsection 5.1.2.
If the Annex A incident response template is used, tailor it to the organization’s systems, people, escalation paths, contacts and incident severities.
Completed and approved incident response plan based on the template, with organization-specific roles, contacts, scenarios and revision history.
3 auditable requirements
The organization shall have up-to-date security patches for all software and hardware installed to protect assets from known vulnerabilities.
Implement a patch management process to ensure all software and hardware are regularly updated with the latest security patches. This process should cover all devices and systems within the organization.
Provide patch management policies and procedures, logs or reports showing recent patches applied, and schedules of regular patching activities.
The organization shall enable automatic patching for all software and hardware or document all instances where they make the business decision not to do so.
Enable automatic updates for all eligible software and hardware. For instances where automatic patching is not feasible or is opted against, document the reasons and alternative measures taken.
Show system settings or configurations that enable automatic updates, along with documentation of instances where automatic patching is not used and the justification for these decisions.
The organization shall perform a risk assessment to determine whether to replace systems incapable of automatic patching.
Conduct risk assessments to decide whether to replace systems that cannot be automatically patched. This involves evaluating the risks associated with keeping such systems versus the costs and implications of replacing them.
Present risk assessment reports detailing the evaluation of systems incapable of automatic patching, decisions made, and any actions taken as a result.
1 auditable requirements
The organization shall enable anti-malware solutions that update automatically and prevent malware from executing.
Deploy Anti-Malware Solutions: Install and activate anti-malware software on all connected devices across the organization. This includes servers, desktops, laptops, and mobile devices. Enable Automatic Updates: Configure the anti-malware software to update automatically. This ensures that the software is equipped with the latest definitions to detect and prevent new strains of malware. Autonomous Malware Prevention: Set the anti-malware solutions to operate in a mode that automatically blocks or removes malware without requiring user intervention. This is critical to prevent delays in response which could lead to a security breach. Regular Testing and Configuration Reviews: Periodically test the effectiveness of the anti-malware solutions and review their configurations to ensure optimal performance and coverage.
Software Deployment Records: Provide documentation or system reports showing the installation of anti-malware software on all relevant devices. Configuration Settings: Show the configuration settings of the anti-malware solutions that enable automatic updates and autonomous operation. Update Logs: Maintain logs or reports that show a history of the anti-malware software updates, indicating that they are being kept current. Test Results and Reviews: Provide records of any tests conducted to verify the effectiveness of the anti-malware solutions, along with any subsequent configuration changes made as a result of these tests.
3 auditable requirements
The organization shall implement secure configurations for all their devices by:
changing all default passwords.
Conduct an audit of all devices to identify those with default passwords. Change default passwords to strong, unique passwords following best practices in password security. Ensure that this policy is applied to new devices as they are brought into the network.
Provide a policy document that mandates the changing of default passwords. Show records of password changes or system configurations indicating that default passwords have been altered.
The organization shall implement secure configurations for all their devices by:
by turning off unnecessary features i.e., block unused ports, disable unused services, remove unused or obsolete software; and
Disable or remove unnecessary ports, services, accounts, features and obsolete software. Maintain a secure configuration baseline and review it when devices or services change.
Secure configuration standard; configuration exports or screenshots; software inventory; disabled-service or port records; and periodic configuration review results.
The organization shall implement secure configurations for all their devices by:
by enabling all relevant security features.
Enable relevant built-in security features such as host firewalls, encryption, secure boot, screen locking and device-management controls based on the device type and risk.
Configuration reports or management-console exports showing enabled security features; baseline compliance reports; and exception records.
4 auditable requirements
The organization shall implement multi-factor authentication or document all instances where they cannot or make the business decision not to do so.
Deploy MFA across the organization, requiring users to authenticate using at least two different factors (something they know, have, or are). In cases where MFA cannot be implemented, document the reasons and any compensating controls in place.
Provide policies and technical documents showing the implementation of MFA. In cases of exceptions, present the documentation explaining why MFA was not feasible and the alternative measures taken.
The organization shall enforce password changes on suspicion or evidence of compromise.
Establish protocols to enforce immediate password changes if there is suspicion or evidence of a security compromise. Implement monitoring tools to detect potential compromises and trigger password change procedures.
Show the policy outlining the procedure for forced password changes in case of compromise. Provide incident reports or logs where this policy was enacted.
The organization shall have clear policies on password length and reuse, the use of password managers and if, when, and how users can physically write down and securely store a password. NOTE: The organization may use password selection guidance from the Canadian Centre for Cyber Security, such as the ITSP.30.031 User Authentication Guidance for Information Technology Systems.
Develop clear policies regarding password length, complexity, reuse, and storage. Include guidelines on the use of password managers and instructions for securely writing down and storing passwords, if permitted.
Present the documented password policies. If applicable, show guidelines provided to employees regarding password management and storage.
The organization shall implement a password manager or document the business decision not to do so. NOTE: Refer to ITSAP.30.032 for Best Practices for Passphrases and Passwords.
Implement a password manager to help users securely store and manage their passwords. If a password manager is not used, document the business reasons and any alternative measures in place.
Provide documentation of the password manager solution implemented. In cases where a password manager is not used, present the business justification and any alternative password management strategies employed.
8 auditable requirements
The organization shall determine on a case-by-case basis what business information and software (including but not limited to sensitive information) is essential to the functioning of the organization, and how frequently this information changes.
Assess and document what business information and software are critical to the organization's operations and how frequently this information changes. This assessment should include all types of data, especially sensitive information, and should be updated regularly.
Provide documentation detailing the critical business information identified, the rationale behind these choices, and the frequency of data changes.
The organization shall determine on a case-by-case basis what systems to back up and at what frequency since every system will have different backup and recovery requirements.
Based on the data assessment, determine which systems need to be backed up and the appropriate backup frequency for each. This could vary between systems, with some requiring more frequent backups than others.
Show backup schedules and policies that outline the systems included and their respective backup frequencies.
The organization shall backup systems that contain essential business information and ensure that recovery mechanisms effectively and efficiently restore these systems from backups.
Implement backup solutions that cover all identified essential systems and data. Ensure that recovery mechanisms are tested and can efficiently restore data from these backups.
Provide test results of recovery drills and documentation of the backup processes in place.
The organization shall store backups at a fully offsite location at regular intervals to provide diversity in the event of a disaster (fire, flood, earthquake or localized cyber security incident).
Store backup copies in secure offsite locations, which could include physical locations or cloud services with network separation. Regularly update these offsite backups to reflect the most current data.
Provide contracts or agreements with offsite storage providers or cloud service documentation, along with records of backup transfers.
The organization should consider the use of encrypted backups with securely stored and recoverable key material. Decryption keys and/or unencrypted backups should be stored securely and should be accessible only to authorized employees or officers.
Encrypt backup data, ensuring that the encryption keys are securely stored and recoverable. Establish procedures for handling and accessing these keys and backups.
Show encryption policies, procedures for key management, and logs or records demonstrating the use of encrypted backups.
Backup files shall not be modifiable to maintain data integrity.
Protect backup files from alteration or deletion by ordinary and privileged accounts. Use immutable, write-once or access-isolated backup storage where appropriate.
Backup storage configuration; immutability or retention-lock settings; access-control lists; deletion-protection settings; and change or access logs.
The organization shall regularly test critical backups for security and integrity.
Test critical backups on a defined schedule for readability, malware exposure, integrity and successful restoration. Track and correct failed tests.
Backup test schedule; integrity-check results; restoration records; failed-test tickets; corrective actions; and management review records.
The organization shall use a sampling of backup data to test and verify recovery procedures at regular intervals to ensure the integrity of the end-to-end backup and restoration process.
Regularly test a sampling of backup data to verify the effectiveness of recovery procedures. Ensure the integrity of the end-to-end backup and restoration process.
Provide records of these tests, including dates, the scope of the testing, and any findings or actions taken as a result.
9 auditable requirements
The organization shall have a firewall placed between two perimeters that controls the amount and kinds of traffic that may pass between the two.
Install firewalls at strategic points within the network to control traffic between different network segments. Configure firewall rules to manage and monitor the types of traffic that can pass between these segments.
Provide network diagrams showing the location of firewalls. Show firewall configuration settings and policies.
The organization shall implement a DNS firewall for outbound DNS requests to the Internet.
Implement a DNS firewall or protective DNS service for outbound Internet name-resolution requests and ensure organizational devices use the approved resolver.
DNS security configuration; endpoint or network resolver settings; filtering policies; blocked-domain reports; and coverage records.
The organization shall activate any software firewalls included on devices within their networks or document the alternative measures in place instead of these firewalls.
Activate software firewalls on all devices within the network. If alternative measures are used, document these and the reasons for not using the inbuilt software firewalls.
Show records of activated software firewalls or documentation of alternative security measures.
The organization shall require encrypted connectivity to all corporate IT resources and require VPN connectivity with multi-factor authentication for all remote access into corporate networks.
Require encrypted connections for accessing all corporate IT resources. Implement VPNs with multi-factor authentication for remote access.
Provide policies mandating encrypted connectivity and VPN use. Show VPN configuration settings, especially those related to multi-factor authentication.
The organization shall use secure Wi-Fi, at a minimum WPA2-AES, and preferably WPA2-Enterprise or WPA3-Enterprise, and configure related passwords in accordance with section 5.5.
Use secure Wi-Fi protocols, such as WPA2-AES, WPA2-Enterprise, or WPA3-Enterprise. Ensure Wi-Fi passwords comply with the organization's password policy.
Document Wi-Fi security settings and protocols in use. Provide excerpts from the password policy relevant to Wi-Fi security.
The organization shall segment their networks to ensure networks provided to the public/customers are separated (and/or isolated) from the corporate networks.
Segment networks to separate public/customer access from corporate networks. Ensure appropriate controls are in place for each segment.
Show network segmentation diagrams and the security measures implemented for each segment.
The organization shall ensure the implementation of DMARC, DKIM and SPF on all organization email services.
Configure SPF and DKIM for each organizational sending domain and publish a DMARC policy. Monitor DMARC reports and address unauthorized senders or configuration failures.
DNS records for SPF, DKIM and DMARC; DMARC aggregate reports; mail-provider configuration; and remediation records.
The organization shall ensure email filtering is implemented.
Implement email filtering solutions to block spam, phishing attempts, and other malicious content. Regularly update and configure the filtering criteria based on emerging threats.
Show documentation of the email filtering solution, including configuration settings and filtering rules.
The organization should ensure that their users join a separate network that is independent of the home network (e.g. guest network) in conducting their employment activities.
Require remote workers to use a separate trusted work network, such as a dedicated home guest network, when feasible. Document guidance and any accepted exceptions.
Remote-work or home-network guidance; employee acknowledgements; awareness material; sampled interviews; and documented exceptions.
4 auditable requirements
The organization shall provision accounts with the minimum functionality necessary for tasks and shall restrict administrator privileges to an as-required basis.
Implement user account management practices that adhere to the principle of least privilege, ensuring users are granted only the access necessary to perform their tasks. Regularly review user accounts and adjust privileges to ensure they align with current job responsibilities.
Documented policies and procedures for user account management. Records of user accounts, their privileges, and logs of changes made to account privileges.
The organization shall remove accounts and/or functionality when users no longer require these for their tasks.
Establish a process for regular review and removal of user accounts and privileges that are no longer required. Implement automated or manual procedures to promptly remove or adjust access when a user's role changes or when they leave the organization.
Documentation of the account review and removal process. Logs or records showing instances of account or privilege removals.
The organization shall only permit administrator accounts to perform administrative activities (and not user-level activities such as accessing email or browsing the web).
Ensure that administrator accounts are used exclusively for administrative tasks and are not used for regular user activities like email access or web browsing. Implement technical controls to enforce this separation of duties.
Policies outlining the acceptable use of administrator accounts. System logs or reports demonstrating compliance with these policies.
The organization should implement a centralized authentication system such as a directory or identity service.
Consider implementing a centralized system for managing user authorizations across various systems and applications. Such a system can streamline the process of granting, adjusting, and revoking access, ensuring consistency and auditability.
If a centralized authorization system is implemented, provide documentation of the system and its configuration. If not implemented, document the rationale and describe any alternative measures in place for managing user access.
6 auditable requirements
The organization using mobile devices (i.e., cellphones) shall decide on an ownership model for mobile devices and document the rationale and associated risks.
Choose between a COPE or BYOD model based on organizational needs. Assess the risks associated with each model, such as data security and device management.
Document outlining the chosen model, the rationale behind this choice, and a risk assessment related to mobile device usage in the organization.
The organization using mobile devices (i.e., cellphones) shall:
require separation between work and personal data on mobile devices with access to corporate IT resources and document the details of this separation;
Use mobile device management (MDM) solutions to create a clear separation between work and personal data, such as secure containers or profiles.
Policy documents detailing the separation measures and records of MDM settings on devices.
The organization using mobile devices (i.e., cellphones) shall:
ensure that employees only download mobile device applications (i.e., apps) from the organization’s list of trusted sources;
Establish a policy that restricts app downloads to organization-approved sources and regularly update the list of approved sources.
Policy documentation and a list of approved app sources.
The organization using mobile devices (i.e., cellphones) shall:
require that all mobile devices store all sensitive information in a secure, encrypted state;
Enforce encryption of sensitive data stored on mobile devices, using built-in encryption features or third-party tools.
Technical documentation or configuration settings showing encryption enforcement on devices.
The organization using mobile devices (i.e., cellphones) shall:
implement an enterprise mobility management solution for all mobile devices or document the risks assumed to the audit, management, and security functionality of mobile devices by not implementing such a solution;
If feasible, implement an EMM solution for enhanced device management. If not implemented, document the risks and alternative strategies.
Documentation of the EMM solution or a written rationale for not implementing it.
The organization using mobile devices (i.e., cellphones) shall:
enforce users to: - disable automatic connections to open networks; - avoid connecting to untrusted Wi-Fi networks; - limit the use of Bluetooth and NFC for the exchange of sensitive information; - use corporate Wi-Fi or cellular data network connectivity rather than public Wi-Fi; and - use secure connectivity (VPN, Virtual Desktop etc.) when connecting to public Wi-Fi networks or provide the rationale for not doing so.
Conduct regular training sessions for employees on safe mobile device usage, focusing on secure connections and avoiding unsecured networks. Encourage the use of VPNs or other secure methods when connecting to public Wi-Fi. Document the reasons if these technologies are not implemented.
Training records, policy documents, and employee acknowledgments. "Policy documents on secure connectivity, VPN configuration settings, or a statement explaining the absence of such technologies. "
6 auditable requirements
Organization using cloud applications and/or outsourcing IT services shall evaluate their risk tolerance level with how their outsourced IT providers handle and access their sensitive information.
Assess the risk associated with how outsourced IT providers handle and access sensitive information. Consider factors like data security, privacy policies, and compliance with relevant regulations.
Risk assessment reports, including evaluations of IT service providers and the criteria used for these assessments.
The organization using cloud applications and/or outsourcing IT services shall:
complete a risk assessment of externally provided services. NOTE: Refer to Vendor Risk Analysis Questionnaire template in Annex C.
Assess each externally provided service before use and at planned intervals. Evaluate the service, data involved, access, availability dependencies, subcontractors and exit requirements.
Completed vendor risk assessments; service inventory; review approvals; reassessment schedule; identified risks; and treatment actions.
The organization using cloud applications and/or outsourcing IT services shall:
require that all their external providers share a report that states that they achieved compliance with SOC 2, ISO/IEC 27001, PCI-DSS, ISO/IEC 20000, CAN/DGSI 104:2021 or equivalent, or provide a documented business case as why they chose not to; NOTE: The organization determines equivalence to the standard depending on the type of IT service that is outsourced.
Obtain and review relevant independent assurance reports or certifications from external providers. If suitable assurance is unavailable, document the business case, risk and compensating controls.
Current SOC 2, ISO/IEC 27001, PCI DSS, ISO/IEC 20000, CAN/DGSI 104 or equivalent reports; review notes; validity checks; or approved exception business cases.
The organization using cloud applications and/or outsourcing IT services shall:
complete a risk assessment of their data transmittal and data storage process (e.g., risks associated with legal jurisdictions);
Assess how data is transmitted and stored, including encryption, geographic location, legal jurisdiction, retention, backup and deletion obligations.
Data-flow diagrams; data-location records; legal or privacy assessment; contract clauses; encryption configuration; and approved risk decisions.
The organization using cloud applications and/or outsourcing IT services shall:
ensure that their IT infrastructure and users communicate securely with all cloud services and applications; and
Require secure protocols and approved configurations for all user and infrastructure connections to cloud services and applications. Disable insecure or obsolete connection methods.
Architecture diagrams; TLS, VPN or secure-access configuration; identity-provider settings; security policies; and connection or monitoring logs.
The organization using cloud applications and/or outsourcing IT services shall:
ensure that all administrative accounts for cloud services use multi-factor authentication and differ from internal administrator accounts.
Protect every cloud administrative account with multi-factor authentication and use cloud administrator identities that are separate from internal administrator accounts.
Cloud identity inventory; MFA enforcement settings; separate administrator account records; privileged-access reviews; and authentication logs.
2 auditable requirements
The organization shall remediate the high and medium OWASP Top 10 risks (for primary marketing websites) to an acceptable risk tolerance level. NOTE: For a comprehensive list of vulnerability scanning tools, refer to the Community Page for “Vulnerability Scanning Tools” on the OWASP website.
Conduct regular security assessments of websites to identify and address the OWASP top 10 vulnerabilities. Implement necessary security measures to mitigate these vulnerabilities, such as input validation, authentication controls, and secure configuration practices.
Security assessment reports showing the evaluation of websites against the OWASP top 10 vulnerabilities. Documentation of security measures implemented to address identified vulnerabilities.
The organization shall define the OWASP ASVS level they need to meet for each of their websites.
Determine the appropriate OWASP Application Security Verification Standard (ASVS) level for each website based on its functionality and the sensitivity of the data it handles. Implement security controls and practices to meet the identified ASVS level. This may involve code reviews, penetration testing, and regular security audits.
Documentation outlining the ASVS levels determined for each website and the rationale behind these determinations. Evidence of security measures and practices in place to meet the ASVS levels, such as audit reports, test results, and security control documentation.
4 auditable requirements
Organizations using portable media shall mandate the sole use of organization-owned secure portable media.
Implement a policy that restricts the use of portable media to only those devices provided and secured by the organization. Ensure these devices are commercially encrypted and track their distribution among employees.
Policy document mandating the use of organization-owned portable media. Records of issued devices and their encryption status.
The organization using portable media shall:
have strong asset controls for these devices;
Develop a system for tracking and monitoring the issuance, return, and usage of portable media devices. Conduct regular audits to account for all issued devices.
Asset tracking logs or a database showing the issuance and current status of each device. Audit reports demonstrating regular checks of portable media assets.
The organization using portable media shall:
require the use of encryption on all of these devices; and
Enforce the use of encryption on all portable media devices. This can include hardware encryption or software-based encryption solutions. Regularly verify that the encryption is active and up-to-date.
Documentation of the encryption standards used and procedures for ensuring encryption on all devices. Records showing regular checks or audits of device encryption status.
The organization using portable media shall:
have processes for the sanitization or destruction of portable media prior to disposal.
Establish processes for the secure sanitization or destruction of portable media devices prior to their disposal. This can include physical destruction, degaussing, or software-based data wiping methods.
Procedures for device sanitization or destruction. Records of devices that have been sanitized or destroyed, including the methods used.
1 auditable requirements
The organization using point of sale terminals and financial systems shall follow the Payment Card Industry Data Security Standard (PCI DSS).
Conduct a comprehensive review of all POS terminals and financial systems to ensure they align with the requirements of the PCI DSS. Implement necessary controls as outlined in the PCI DSS, such as network segmentation, firewall implementation, encryption of transmission data, regular updates and patches, and strict access controls. Train staff on PCI DSS requirements and secure handling of payment card data. Regularly update and review the security measures to ensure ongoing compliance with the PCI DSS.
Documentation showing the organization’s PCI DSS compliance status, including self-assessment questionnaires or reports from external PCI DSS assessments. Records of security controls in place for POS and financial systems, such as network diagrams, firewall configurations, access control lists, and encryption protocols. Training records demonstrating staff education on PCI DSS and secure handling of payment card data. Logs or reports showing regular monitoring, testing, and updates of security measures related to POS and financial systems.
1 auditable requirements
The organization shall have a policy on log management (including log backup), and a procedure to implement the policy. NOTE:The retention period for logs depends on various factors, including legal requirements, business needs, and best practices.
Assess the organization's current logging capabilities, identifying what security logs are being captured, such as user login events, file accesses, system configurations, firewall logs, and intrusion detection system logs. Develop a log management policy that outlines how logs are collected, stored, analyzed, and protected. The policy should address the retention period, access controls, and procedures for reviewing and analyzing logs. Implement tools and systems for effective log management, ensuring they can handle the volume and variety of logs generated. Train IT staff on the importance of log management and the procedures outlined in the policy. Regularly review and update the log management policy and tools to ensure they remain effective and align with the organization's evolving needs.
The log management policy document, detailing procedures for log collection, storage, analysis, and protection. Records of the log management system configuration and capabilities. Training records showing staff education on log management practices. Examples of logs being collected and reports generated from log analysis. Documentation of regular reviews and updates to the log management policy and systems.
Below videos are intended to be used alongside the standard. Please purchase the standard first.
The videos are presented in sequence and should be watched in order.
If you have questions or comments, please email us at info@complade.com.
Overview of frameworks such as ISO, National Institute of Standards and Technology Cybersecurity Framework (NIST CSF), and System and Organization Controls 2 (SOC 2)
Standard here ( this is an older version but close to the current version). Use it as a reference only. You will be certified in the new standard here
Audit Sheet (make a copy and track your implementation) : https://docs.google.com/spreadsheets/d/14JbN6yBnOYZjRiXft1-26KE3cwgc_c6Id8KAwW4z3sg
Please note this is an older version, email us for access to newer version.
Complade recruits experienced external auditors and offers an Auditor in Training program with supervised external audit days.
Complade provides these resources as a free service to enhance understanding of ISO 27001 and CyberSecure Canada. These resources are not a substitute for tailored implementation guidance. For customized support, we recommend working with qualified ISO consultants.