Canadian certification body accredited by the Standards Council of Canada
Training & Resources

Complade CyberSecure Canada Training Resources

Complade is accredited by the Standards Council of Canada to provide ISO/IEC 27001 and CyberSecure Canada certification services.

How to use these CyberSecure Canada resources

Complade is accredited by the Standards Council of Canada to provide ISO/IEC 27001 and CyberSecure Canada certification services. To protect impartiality, Complade does not provide consulting, implementation, or internal audit services.

These free educational resources introduce CyberSecure Canada terminology and requirements. They are general information only and are not implementation guidance tailored to a specific organization.

For questions, contact your Complade account manager or email info@complade.com.

The control library below is aligned to the supplied CAN/DGSI 104:2021 / Rev 1:2024 audit workbook. Always use the current standard, available from the Digital Governance Council, as the authoritative source. The older videos are retained as general background only.

Learning pathway

Resources to Get Started with CyberSecure Canada

This pathway is designed to guide individuals from no prior experience to becoming knowledgeable of CyberSecure Canada standard

Prerequisite:

Basic understanding of information security.

CyberSecure Canada Standard

Objective:

Understand the foundational concepts of CyberSecure Canada and related standards.

Course Materials:

Standard https://dgc-cgn.org/product/can-dgsi-1042021-rev-12024/

Requirement-by-requirement guide

Controls, implementation and audit evidence

The library below covers all 18 control families and 83 auditable requirements identified in the supplied CAN/DGSI 104:2021 / Rev 1:2024 audit workbook. Requirement wording is separated from practical implementation guidance and examples of evidence an auditor may examine. This educational guidance does not replace the standard or advice tailored to your organization.

4.1.2.1(a)ensuring the cyber security policy and objectives are established and are aligned with the strategic direction of the organization;

Requirement context

Top management shall demonstrate their commitment to the cyber security program by:

Requirement

ensuring the cyber security policy and objectives are established and are aligned with the strategic direction of the organization;

General implementation guidance

Develop a comprehensive cyber security policy that aligns with the strategic goals of the organization. This policy should include specific objectives that are measurable and achievable.

Evidence an auditor may examine

Provide the cyber security policy document, along with minutes from meetings or communications where top management discussed and approved the policy and its alignment with the organization's strategic direction.

4.1.2.1(b)ensuring that the resources needed for the cyber security program are available and are aligned with the cyber security policy and objectives;

Requirement context

Top management shall demonstrate their commitment to the cyber security program by:

Requirement

ensuring that the resources needed for the cyber security program are available and are aligned with the cyber security policy and objectives;

General implementation guidance

Allocate necessary resources including budget, personnel, and technology to support the cyber security program. This may involve hiring skilled personnel, investing in security technologies, or allocating funds for training and development.

Evidence an auditor may examine

Prepare financial reports, hiring records, and investment documents showing resource allocation towards cyber security. Additionally, training records and procurement documents for security tools and technologies can be presented.

4.1.2.1(c)communicating the importance of effective cyber security and of conforming to the cyber security program requirements;

Requirement context

Top management shall demonstrate their commitment to the cyber security program by:

Requirement

communicating the importance of effective cyber security and of conforming to the cyber security program requirements;

General implementation guidance

Top management should actively communicate the importance of cyber security to all levels of the organization. This can be through company-wide emails, meetings, training sessions, and regular updates on cyber security matters.

Evidence an auditor may examine

Provide copies of communications sent to employees, agendas or minutes from meetings where cyber security was discussed, and records of any cyber security awareness programs conducted.

4.1.2.1(d)establishing cybersecurity program metrics and tracking progress; and

Requirement context

Top management shall demonstrate their commitment to the cyber security program by:

Requirement

establishing cybersecurity program metrics and tracking progress; and

General implementation guidance

Define clear metrics to evaluate the effectiveness of the cyber security program. These could include the number of incidents handled, response times, training completion rates, or system audit results. Regularly review these metrics to track progress.

Evidence an auditor may examine

Compile reports that show the metrics being tracked over time. Include documentation on how these metrics were established and how they are regularly reviewed by management.

4.1.2.1(e)supporting other relevant management roles to demonstrate their leadership as it applies to their areas of responsibility.

Requirement context

Top management shall demonstrate their commitment to the cyber security program by:

Requirement

supporting other relevant management roles to demonstrate their leadership as it applies to their areas of responsibility.

General implementation guidance

ensure that other management roles are empowered and have the necessary resources to uphold their cyber security responsibilities. This involves clear communication of roles, responsibilities, and expectations to all managerial staff.

Evidence an auditor may examine

Provide organizational charts, job descriptions, and policy documents that outline the cyber security responsibilities of various management roles. Also, include records of meetings or communications where support from top management for these roles is evident.

4.2.2.1(a)developing and implementing a company-wide information cyber security program to meet baseline cyber security controls;

Requirement context

Top management shall appoint a member of the senior-level leadership team to oversee and be accountable for the organization’s cyber security. Accountabilities of the member of the senior- level leadership team shall include the following:

Requirement

developing and implementing a company-wide information cyber security program to meet baseline cyber security controls;

General implementation guidance

The appointed senior-level leader should develop and implement a comprehensive cyber security program that addresses all baseline cyber security controls. This program must cover various aspects such as risk management, incident response, and asset protection.

Evidence an auditor may examine

Provide the cyber security program document, project plans for implementation, and records of the program being discussed and approved in management meetings.

4.2.2.1(b)documenting and disseminating information security policies and procedures;

Requirement context

Top management shall appoint a member of the senior-level leadership team to oversee and be accountable for the organization’s cyber security. Accountabilities of the member of the senior- level leadership team shall include the following:

Requirement

documenting and disseminating information security policies and procedures;

General implementation guidance

Create detailed information security policies and procedures, and ensure they are accessible to all employees. Regular updates should be communicated effectively.

Evidence an auditor may examine

Present the documented policies and procedures, evidence of dissemination (e.g., emails, intranet postings), and records of policy acknowledgments by employees.

4.2.2.1(c)coordinating the development and implementation of a company-wide information security training and awareness program;

Requirement context

Top management shall appoint a member of the senior-level leadership team to oversee and be accountable for the organization’s cyber security. Accountabilities of the member of the senior- level leadership team shall include the following:

Requirement

coordinating the development and implementation of a company-wide information security training and awareness program;

General implementation guidance

Coordinate the development and implementation of an organization-wide information security training and awareness program. Ensure it is comprehensive and covers all employees.

Evidence an auditor may examine

Show training materials, schedules, attendance records, and feedback from participants. Include metrics demonstrating the program's reach and effectiveness.

4.2.2.1(d)coordinating a response to actual or suspected breaches in the confidentiality, integrity, or availability of the organization’s data; and

Requirement context

Top management shall appoint a member of the senior-level leadership team to oversee and be accountable for the organization’s cyber security. Accountabilities of the member of the senior- level leadership team shall include the following:

Requirement

coordinating a response to actual or suspected breaches in the confidentiality, integrity, or availability of the organization’s data; and

General implementation guidance

Establish a procedure for responding to security breaches. This includes identification, containment, eradication, and recovery processes, along with communication plans.

Evidence an auditor may examine

Document the incident response plan and provide records of any drills or actual incidents, including how they were managed and resolved

4.2.2.1(e)identifying organizational risks and prioritizing risk treatment relative to likelihood and potential impact of cyber threats.

Requirement context

Top management shall appoint a member of the senior-level leadership team to oversee and be accountable for the organization’s cyber security. Accountabilities of the member of the senior- level leadership team shall include the following:

Requirement

identifying organizational risks and prioritizing risk treatment relative to likelihood and potential impact of cyber threats.

General implementation guidance

Regularly identify and assess organizational risks related to cyber security. Develop a process for prioritizing these risks based on their likelihood and potential impact.

Evidence an auditor may examine

Produce risk assessment reports, risk treatment plans, and documentation showing how risks are prioritized and addressed.

4.3.2.1(a)Compliance with password policies (see Subsection 5.5);

Requirement context

The organization shall train employees on basic security practices, including but not limited to the following practices:

Requirement

Compliance with password policies (see Subsection 5.5);

General implementation guidance

Develop and provide training sessions on effective password policies, such as creating strong passwords, changing them regularly, and not sharing them.

Evidence an auditor may examine

Provide training materials, records of training sessions conducted (dates, attendees), and assessments or quizzes to demonstrate employee understanding.

4.3.2.1(b)Identification of malicious communications and phishing;

Requirement context

The organization shall train employees on basic security practices, including but not limited to the following practices:

Requirement

Identification of malicious communications and phishing;

General implementation guidance

Train employees on how to identify and handle malicious emails and links. This could include recognizing phishing attempts and understanding the risks of clicking unknown links.

Evidence an auditor may examine

Show training content specific to this topic, along with records of training completion and any assessments or practical tests conducted.

4.3.2.1(c)Keeping employee devices and software updated.

Requirement context

The organization shall train employees on basic security practices, including but not limited to the following practices:

Requirement

Keeping employee devices and software updated.

General implementation guidance

Train employees to keep organization-managed devices, operating systems, browsers and approved applications updated. Explain how to recognize update prompts and where to report failed updates.

Evidence an auditor may examine

Training material covering updates and patching; completion records; device-management or patch-compliance reports; and sampled employee interviews.

4.3.2.1(d)Principle of least privilege and basic access controls.

Requirement context

The organization shall train employees on basic security practices, including but not limited to the following practices:

Requirement

Principle of least privilege and basic access controls.

General implementation guidance

Explain least privilege in plain language: employees receive only the access needed for their work, do not share accounts, and request additional access through the approved process.

Evidence an auditor may examine

Training material covering least privilege and access control; attendance or completion records; knowledge checks; and sampled employee interviews.

4.3.3.1The organization shall provide documentation that they provide regular and ongoing cyber security awareness and training for their employees.

Requirement

The organization shall provide documentation that they provide regular and ongoing cyber security awareness and training for their employees.

General implementation guidance

Develop an Ongoing Training Program: Establish a continuous training program that covers various aspects of cyber security. This program should be updated regularly to include new threats, trends, and best practices. Schedule Regular Training Sessions: Organize training sessions at regular intervals (e.g., quarterly or bi-annually) to ensure continuous learning and awareness among employees. Incorporate Diverse Training Methods: Use a mix of training methods such as e-learning, workshops, webinars, and interactive sessions to cater to different learning styles. Customize Training Content: Tailor the training content to different roles within the organization, focusing on the specific risks and responsibilities associated with each role. Measure Training Effectiveness: Implement methods to assess the effectiveness of training, such as quizzes, practical exercises, or feedback surveys.

Evidence an auditor may examine

Training Program Documentation: Provide a comprehensive outline of the training program, including objectives, topics covered, and updates made over time. Training Schedules and Attendance Records: Present schedules of all training sessions conducted, along with attendance records to show employee participation. Training Materials and Methods Used: Share examples of training materials and describe the methods used for training delivery. Assessment Results: Provide results of quizzes, tests, or surveys conducted to assess the understanding and effectiveness of the training. Feedback and Improvement Records: Show records of feedback received from employees on training sessions and any subsequent improvements made to the training program.

4.4.2.1The organization shall conduct a cyber security risk assessment. NOTE: Refer to Cyber Security Risk Assessment Questionnaire in Annex B

Requirement

The organization shall conduct a cyber security risk assessment. NOTE: Refer to Cyber Security Risk Assessment Questionnaire in Annex B

General implementation guidance

The senior-level leader should regularly conduct comprehensive cyber security risk assessments. This involves identifying potential risks, assessing their impact and likelihood, and prioritizing them.

Evidence an auditor may examine

Provide documentation of the risk assessment process, including risk registers, assessment reports, and minutes from meetings where these assessments were reviewed.

4.4.3.1The member of the senior-level leadership team appointed to oversee the organization’s cyber security shall conduct cyber security risk assessments and coordinate the implementation of cyber security controls to address potential cyber security risks. NOTE 1: The member of the senior-level leadership team appointed to oversee the organization’s cyber security should consult experts to review and provide input into the cyber security risk assessment and in the selection of controls to safeguard against cyber security risks identified and assessed. NOTE 2: The organization may consider the implementation of physical controls as part of its framework to mitigate cyber security risks.

Requirement

The member of the senior-level leadership team appointed to oversee the organization’s cyber security shall conduct cyber security risk assessments and coordinate the implementation of cyber security controls to address potential cyber security risks. NOTE 1: The member of the senior-level leadership team appointed to oversee the organization’s cyber security should consult experts to review and provide input into the cyber security risk assessment and in the selection of controls to safeguard against cyber security risks identified and assessed. NOTE 2: The organization may consider the implementation of physical controls as part of its framework to mitigate cyber security risks.

General implementation guidance

Engage with cyber security experts to review and provide input into risk assessments and the selection of appropriate controls.

Evidence an auditor may examine

Maintain records of consultations with experts, including meeting notes, emails, and reports provided by these experts.

4.4.3.2The organization shall develop and maintain an asset register of its information systems and IT assets, including records showing management’s understanding of the assets’ purpose. For any information systems and assets not included in their implementation of the baseline cyber security controls, the organization shall document all instances where they make the business decision not to do so.

Requirement

The organization shall develop and maintain an asset register of its information systems and IT assets, including records showing management’s understanding of the assets’ purpose. For any information systems and assets not included in their implementation of the baseline cyber security controls, the organization shall document all instances where they make the business decision not to do so.

General implementation guidance

Create and regularly update an inventory of all information systems and assets. Document any exceptions where baseline controls are not implemented.

Evidence an auditor may examine

Present the inventory list and any accompanying documentation justifying why certain systems or assets do not have baseline controls.

4.4.3.3Inherent and residual cyber security risks accepted by the organization shall be documented and authorized by a senior official of the organization.

Requirement

Inherent and residual cyber security risks accepted by the organization shall be documented and authorized by a senior official of the organization.

General implementation guidance

Document any cyber security risks that the organization decides to accept rather than mitigate. These decisions must be authorized by a senior official.

Evidence an auditor may examine

Provide the risk acceptance documents signed by the authorizing senior official.

4.4.3.4The organization shall identify their financial spending levels for cyber security investment (as raw numbers and as a percent of total expenditures).

Requirement

The organization shall identify their financial spending levels for cyber security investment (as raw numbers and as a percent of total expenditures).

General implementation guidance

record and monitor the spending on IT and IT security, both as raw numbers and as a percentage of total expenditures.

Evidence an auditor may examine

Financial reports detailing IT and IT security spending.

4.4.3.5The organization shall identify their internal staffing levels for cyber security (as raw numbers and as a percent of total staff).

Requirement

The organization shall identify their internal staffing levels for cyber security (as raw numbers and as a percent of total staff).

General implementation guidance

Keep records of staffing levels in the IT and IT security departments, including raw numbers and percentages.

Evidence an auditor may examine

Human resources records and organizational charts showing staffing levels.

4.4.3.6The organization shall commit to progressive improvements to cyber security.

Requirement

The organization shall commit to progressive improvements to cyber security.

General implementation guidance

Implement a plan for continuous improvement in cyber security, including regular updates to policies and technologies.

Evidence an auditor may examine

Documentation of improvement plans, records of updates made to cyber security practices, and reports showing progress.

4.4.3.7The organization shall determine triggers and thresholds to conduct a new or update an existing cyber security risk assessment.

Requirement

The organization shall determine triggers and thresholds to conduct a new or update an existing cyber security risk assessment.

General implementation guidance

establish criteria for when to conduct a new or update an existing cyber security risk assessment, such as new threats, major system changes, or after an incident.

Evidence an auditor may examine

Documentation of the criteria and instances when risk assessments were triggered.

4.4.3.8Regardless of the outcomes from the cyber security risk assessment, the organization shall implement the foundational or baseline cyber security controls specified in Section 5, and as appropriate, Section 6 based on its business environment.

Requirement

Regardless of the outcomes from the cyber security risk assessment, the organization shall implement the foundational or baseline cyber security controls specified in Section 5, and as appropriate, Section 6 based on its business environment.

General implementation guidance

Implement every foundational control in Section 5 regardless of the risk-assessment score. Evaluate each Section 6 control against the organization’s business environment and document applicability decisions.

Evidence an auditor may examine

Control applicability matrix; implemented-control records; risk assessment; documented Section 6 applicability decisions; and management approval.

4.4.3.9The organization shall periodically review and/or test cyber security controls to ensure effectiveness. Testing and/or review shall take place at a minimum annually, or if a major change occurs in their system.

Requirement

The organization shall periodically review and/or test cyber security controls to ensure effectiveness. Testing and/or review shall take place at a minimum annually, or if a major change occurs in their system.

General implementation guidance

Create an annual control-testing schedule and repeat testing after major system changes. Define the owner, method, sample and expected result for each review.

Evidence an auditor may examine

Annual testing plan; completed test scripts or review checklists; findings; corrective-action records; and evidence of testing after major changes.

4.4.3.10The organization shall provide documentation attesting to the total number of employees employed by the organization as well as part-time employees and contractors that may have access to the organization’s data.

Requirement

The organization shall provide documentation attesting to the total number of employees employed by the organization as well as part-time employees and contractors that may have access to the organization’s data.

General implementation guidance

Maintain a current workforce count that separately identifies full-time employees, part-time employees and contractors with access to organizational data.

Evidence an auditor may examine

Current HR roster or signed management attestation; contractor register; access lists; and a reconciliation showing who can access organizational data.

5.1.2.1The organization shall have an incident response plan for how to respond to different types of incidents of varying severity. If an organization is unable to manage some types of incidents on its own, the organization shall have a plan for what it will do.

Requirement

The organization shall have an incident response plan for how to respond to different types of incidents of varying severity. If an organization is unable to manage some types of incidents on its own, the organization shall have a plan for what it will do.

General implementation guidance

Develop a comprehensive Incident Response Plan (IRP) that outlines procedures for responding to incidents of varying severity. Ensure it covers all aspects of incident management from identification to recovery.

Evidence an auditor may examine

Provide the IRP document, along with records of its development, updates, and approval by relevant authorities within the organization.

5.1.2.2The incident response plan shall detail who is responsible for handling incidents including any relevant contact information for communicating to external parties, stakeholders and regulators (such as breach counsel), as well as what mechanisms to use for communicating during an incident response. The organization shall have an up-to-date hard copy version of this plan available for situations where soft copies are not available.

Requirement

The incident response plan shall detail who is responsible for handling incidents including any relevant contact information for communicating to external parties, stakeholders and regulators (such as breach counsel), as well as what mechanisms to use for communicating during an incident response. The organization shall have an up-to-date hard copy version of this plan available for situations where soft copies are not available.

General implementation guidance

Clearly define roles and responsibilities within the IRP. Include contact information for individuals responsible for incident management and for communicating with external parties, stakeholders, and regulators.

Evidence an auditor may examine

The IRP should contain a section detailing these roles and contacts. Additionally, maintain an up-to-date hard copy of the IRP for situations where electronic versions are not accessible.

5.1.2.3The organization shall test the incident response plan to ensure that the plan meets the intended outcomes. Where appropriate, this shall include any third-party cyber security service providers.

Requirement

The organization shall test the incident response plan to ensure that the plan meets the intended outcomes. Where appropriate, this shall include any third-party cyber security service providers.

General implementation guidance

Exercise the incident response plan at planned intervals using realistic scenarios. Include relevant third-party providers when their services are part of the response and record lessons learned.

Evidence an auditor may examine

Exercise plan and scenario; participant list; test results; third-party participation records; lessons learned; and tracked improvement actions.

5.1.2.4The organization should consider purchasing a cyber security insurance policy that includes coverage for incident response and recovery activities or provide rationale for not purchasing one.

Requirement

The organization should consider purchasing a cyber security insurance policy that includes coverage for incident response and recovery activities or provide rationale for not purchasing one.

General implementation guidance

Evaluate the need for a cyber security insurance policy that covers incident response and recovery activities. If deciding against it, document the rationale behind this decision.

Evidence an auditor may examine

Provide the insurance policy if purchased, or documentation outlining the rationale for not purchasing it, including risk assessments and decision-making processes.

5.1.2.5The organization may use the incident response plan template (see Annex A) as a measure of satisfying requirements contained in Subsection 5.1.2.

Requirement

The organization may use the incident response plan template (see Annex A) as a measure of satisfying requirements contained in Subsection 5.1.2.

General implementation guidance

If the Annex A incident response template is used, tailor it to the organization’s systems, people, escalation paths, contacts and incident severities.

Evidence an auditor may examine

Completed and approved incident response plan based on the template, with organization-specific roles, contacts, scenarios and revision history.

5.2.2.1The organization shall have up-to-date security patches for all software and hardware installed to protect assets from known vulnerabilities.

Requirement

The organization shall have up-to-date security patches for all software and hardware installed to protect assets from known vulnerabilities.

General implementation guidance

Implement a patch management process to ensure all software and hardware are regularly updated with the latest security patches. This process should cover all devices and systems within the organization.

Evidence an auditor may examine

Provide patch management policies and procedures, logs or reports showing recent patches applied, and schedules of regular patching activities.

5.2.2.2The organization shall enable automatic patching for all software and hardware or document all instances where they make the business decision not to do so.

Requirement

The organization shall enable automatic patching for all software and hardware or document all instances where they make the business decision not to do so.

General implementation guidance

Enable automatic updates for all eligible software and hardware. For instances where automatic patching is not feasible or is opted against, document the reasons and alternative measures taken.

Evidence an auditor may examine

Show system settings or configurations that enable automatic updates, along with documentation of instances where automatic patching is not used and the justification for these decisions.

5.2.2.3The organization shall perform a risk assessment to determine whether to replace systems incapable of automatic patching.

Requirement

The organization shall perform a risk assessment to determine whether to replace systems incapable of automatic patching.

General implementation guidance

Conduct risk assessments to decide whether to replace systems that cannot be automatically patched. This involves evaluating the risks associated with keeping such systems versus the costs and implications of replacing them.

Evidence an auditor may examine

Present risk assessment reports detailing the evaluation of systems incapable of automatic patching, decisions made, and any actions taken as a result.

5.3.2.1The organization shall enable anti-malware solutions that update automatically and prevent malware from executing.

Requirement

The organization shall enable anti-malware solutions that update automatically and prevent malware from executing.

General implementation guidance

Deploy Anti-Malware Solutions: Install and activate anti-malware software on all connected devices across the organization. This includes servers, desktops, laptops, and mobile devices. Enable Automatic Updates: Configure the anti-malware software to update automatically. This ensures that the software is equipped with the latest definitions to detect and prevent new strains of malware. Autonomous Malware Prevention: Set the anti-malware solutions to operate in a mode that automatically blocks or removes malware without requiring user intervention. This is critical to prevent delays in response which could lead to a security breach. Regular Testing and Configuration Reviews: Periodically test the effectiveness of the anti-malware solutions and review their configurations to ensure optimal performance and coverage.

Evidence an auditor may examine

Software Deployment Records: Provide documentation or system reports showing the installation of anti-malware software on all relevant devices. Configuration Settings: Show the configuration settings of the anti-malware solutions that enable automatic updates and autonomous operation. Update Logs: Maintain logs or reports that show a history of the anti-malware software updates, indicating that they are being kept current. Test Results and Reviews: Provide records of any tests conducted to verify the effectiveness of the anti-malware solutions, along with any subsequent configuration changes made as a result of these tests.

5.4.2.1(a)changing all default passwords.

Requirement context

The organization shall implement secure configurations for all their devices by:

Requirement

changing all default passwords.

General implementation guidance

Conduct an audit of all devices to identify those with default passwords. Change default passwords to strong, unique passwords following best practices in password security. Ensure that this policy is applied to new devices as they are brought into the network.

Evidence an auditor may examine

Provide a policy document that mandates the changing of default passwords. Show records of password changes or system configurations indicating that default passwords have been altered.

5.4.2.1(b)by turning off unnecessary features i.e., block unused ports, disable unused services, remove unused or obsolete software; and

Requirement context

The organization shall implement secure configurations for all their devices by:

Requirement

by turning off unnecessary features i.e., block unused ports, disable unused services, remove unused or obsolete software; and

General implementation guidance

Disable or remove unnecessary ports, services, accounts, features and obsolete software. Maintain a secure configuration baseline and review it when devices or services change.

Evidence an auditor may examine

Secure configuration standard; configuration exports or screenshots; software inventory; disabled-service or port records; and periodic configuration review results.

5.4.2.1(c)by enabling all relevant security features.

Requirement context

The organization shall implement secure configurations for all their devices by:

Requirement

by enabling all relevant security features.

General implementation guidance

Enable relevant built-in security features such as host firewalls, encryption, secure boot, screen locking and device-management controls based on the device type and risk.

Evidence an auditor may examine

Configuration reports or management-console exports showing enabled security features; baseline compliance reports; and exception records.

5.5.2.1The organization shall implement multi-factor authentication or document all instances where they cannot or make the business decision not to do so.

Requirement

The organization shall implement multi-factor authentication or document all instances where they cannot or make the business decision not to do so.

General implementation guidance

Deploy MFA across the organization, requiring users to authenticate using at least two different factors (something they know, have, or are). In cases where MFA cannot be implemented, document the reasons and any compensating controls in place.

Evidence an auditor may examine

Provide policies and technical documents showing the implementation of MFA. In cases of exceptions, present the documentation explaining why MFA was not feasible and the alternative measures taken.

5.5.2.2The organization shall enforce password changes on suspicion or evidence of compromise.

Requirement

The organization shall enforce password changes on suspicion or evidence of compromise.

General implementation guidance

Establish protocols to enforce immediate password changes if there is suspicion or evidence of a security compromise. Implement monitoring tools to detect potential compromises and trigger password change procedures.

Evidence an auditor may examine

Show the policy outlining the procedure for forced password changes in case of compromise. Provide incident reports or logs where this policy was enacted.

5.5.2.3The organization shall have clear policies on password length and reuse, the use of password managers and if, when, and how users can physically write down and securely store a password. NOTE: The organization may use password selection guidance from the Canadian Centre for Cyber Security, such as the ITSP.30.031 User Authentication Guidance for Information Technology Systems.

Requirement

The organization shall have clear policies on password length and reuse, the use of password managers and if, when, and how users can physically write down and securely store a password. NOTE: The organization may use password selection guidance from the Canadian Centre for Cyber Security, such as the ITSP.30.031 User Authentication Guidance for Information Technology Systems.

General implementation guidance

Develop clear policies regarding password length, complexity, reuse, and storage. Include guidelines on the use of password managers and instructions for securely writing down and storing passwords, if permitted.

Evidence an auditor may examine

Present the documented password policies. If applicable, show guidelines provided to employees regarding password management and storage.

5.5.3.1The organization shall implement a password manager or document the business decision not to do so. NOTE: Refer to ITSAP.30.032 for Best Practices for Passphrases and Passwords.

Requirement

The organization shall implement a password manager or document the business decision not to do so. NOTE: Refer to ITSAP.30.032 for Best Practices for Passphrases and Passwords.

General implementation guidance

Implement a password manager to help users securely store and manage their passwords. If a password manager is not used, document the business reasons and any alternative measures in place.

Evidence an auditor may examine

Provide documentation of the password manager solution implemented. In cases where a password manager is not used, present the business justification and any alternative password management strategies employed.

5.6.2.1The organization shall determine on a case-by-case basis what business information and software (including but not limited to sensitive information) is essential to the functioning of the organization, and how frequently this information changes.

Requirement

The organization shall determine on a case-by-case basis what business information and software (including but not limited to sensitive information) is essential to the functioning of the organization, and how frequently this information changes.

General implementation guidance

Assess and document what business information and software are critical to the organization's operations and how frequently this information changes. This assessment should include all types of data, especially sensitive information, and should be updated regularly.

Evidence an auditor may examine

Provide documentation detailing the critical business information identified, the rationale behind these choices, and the frequency of data changes.

5.6.2.2The organization shall determine on a case-by-case basis what systems to back up and at what frequency since every system will have different backup and recovery requirements.

Requirement

The organization shall determine on a case-by-case basis what systems to back up and at what frequency since every system will have different backup and recovery requirements.

General implementation guidance

Based on the data assessment, determine which systems need to be backed up and the appropriate backup frequency for each. This could vary between systems, with some requiring more frequent backups than others.

Evidence an auditor may examine

Show backup schedules and policies that outline the systems included and their respective backup frequencies.

5.6.2.3The organization shall backup systems that contain essential business information and ensure that recovery mechanisms effectively and efficiently restore these systems from backups.

Requirement

The organization shall backup systems that contain essential business information and ensure that recovery mechanisms effectively and efficiently restore these systems from backups.

General implementation guidance

Implement backup solutions that cover all identified essential systems and data. Ensure that recovery mechanisms are tested and can efficiently restore data from these backups.

Evidence an auditor may examine

Provide test results of recovery drills and documentation of the backup processes in place.

5.6.2.4The organization shall store backups at a fully offsite location at regular intervals to provide diversity in the event of a disaster (fire, flood, earthquake or localized cyber security incident).

Requirement

The organization shall store backups at a fully offsite location at regular intervals to provide diversity in the event of a disaster (fire, flood, earthquake or localized cyber security incident).

General implementation guidance

Store backup copies in secure offsite locations, which could include physical locations or cloud services with network separation. Regularly update these offsite backups to reflect the most current data.

Evidence an auditor may examine

Provide contracts or agreements with offsite storage providers or cloud service documentation, along with records of backup transfers.

5.6.2.5The organization should consider the use of encrypted backups with securely stored and recoverable key material. Decryption keys and/or unencrypted backups should be stored securely and should be accessible only to authorized employees or officers.

Requirement

The organization should consider the use of encrypted backups with securely stored and recoverable key material. Decryption keys and/or unencrypted backups should be stored securely and should be accessible only to authorized employees or officers.

General implementation guidance

Encrypt backup data, ensuring that the encryption keys are securely stored and recoverable. Establish procedures for handling and accessing these keys and backups.

Evidence an auditor may examine

Show encryption policies, procedures for key management, and logs or records demonstrating the use of encrypted backups.

5.6.2.6Backup files shall not be modifiable to maintain data integrity.

Requirement

Backup files shall not be modifiable to maintain data integrity.

General implementation guidance

Protect backup files from alteration or deletion by ordinary and privileged accounts. Use immutable, write-once or access-isolated backup storage where appropriate.

Evidence an auditor may examine

Backup storage configuration; immutability or retention-lock settings; access-control lists; deletion-protection settings; and change or access logs.

5.6.2.7The organization shall regularly test critical backups for security and integrity.

Requirement

The organization shall regularly test critical backups for security and integrity.

General implementation guidance

Test critical backups on a defined schedule for readability, malware exposure, integrity and successful restoration. Track and correct failed tests.

Evidence an auditor may examine

Backup test schedule; integrity-check results; restoration records; failed-test tickets; corrective actions; and management review records.

5.6.2.8The organization shall use a sampling of backup data to test and verify recovery procedures at regular intervals to ensure the integrity of the end-to-end backup and restoration process.

Requirement

The organization shall use a sampling of backup data to test and verify recovery procedures at regular intervals to ensure the integrity of the end-to-end backup and restoration process.

General implementation guidance

Regularly test a sampling of backup data to verify the effectiveness of recovery procedures. Ensure the integrity of the end-to-end backup and restoration process.

Evidence an auditor may examine

Provide records of these tests, including dates, the scope of the testing, and any findings or actions taken as a result.

5.7.3.1The organization shall have a firewall placed between two perimeters that controls the amount and kinds of traffic that may pass between the two.

Requirement

The organization shall have a firewall placed between two perimeters that controls the amount and kinds of traffic that may pass between the two.

General implementation guidance

Install firewalls at strategic points within the network to control traffic between different network segments. Configure firewall rules to manage and monitor the types of traffic that can pass between these segments.

Evidence an auditor may examine

Provide network diagrams showing the location of firewalls. Show firewall configuration settings and policies.

5.7.3.2The organization shall implement a DNS firewall for outbound DNS requests to the Internet.

Requirement

The organization shall implement a DNS firewall for outbound DNS requests to the Internet.

General implementation guidance

Implement a DNS firewall or protective DNS service for outbound Internet name-resolution requests and ensure organizational devices use the approved resolver.

Evidence an auditor may examine

DNS security configuration; endpoint or network resolver settings; filtering policies; blocked-domain reports; and coverage records.

5.7.3.3The organization shall activate any software firewalls included on devices within their networks or document the alternative measures in place instead of these firewalls.

Requirement

The organization shall activate any software firewalls included on devices within their networks or document the alternative measures in place instead of these firewalls.

General implementation guidance

Activate software firewalls on all devices within the network. If alternative measures are used, document these and the reasons for not using the inbuilt software firewalls.

Evidence an auditor may examine

Show records of activated software firewalls or documentation of alternative security measures.

5.7.3.4The organization shall require encrypted connectivity to all corporate IT resources and require VPN connectivity with multi-factor authentication for all remote access into corporate networks.

Requirement

The organization shall require encrypted connectivity to all corporate IT resources and require VPN connectivity with multi-factor authentication for all remote access into corporate networks.

General implementation guidance

Require encrypted connections for accessing all corporate IT resources. Implement VPNs with multi-factor authentication for remote access.

Evidence an auditor may examine

Provide policies mandating encrypted connectivity and VPN use. Show VPN configuration settings, especially those related to multi-factor authentication.

5.7.3.5The organization shall use secure Wi-Fi, at a minimum WPA2-AES, and preferably WPA2-Enterprise or WPA3-Enterprise, and configure related passwords in accordance with section 5.5.

Requirement

The organization shall use secure Wi-Fi, at a minimum WPA2-AES, and preferably WPA2-Enterprise or WPA3-Enterprise, and configure related passwords in accordance with section 5.5.

General implementation guidance

Use secure Wi-Fi protocols, such as WPA2-AES, WPA2-Enterprise, or WPA3-Enterprise. Ensure Wi-Fi passwords comply with the organization's password policy.

Evidence an auditor may examine

Document Wi-Fi security settings and protocols in use. Provide excerpts from the password policy relevant to Wi-Fi security.

5.7.3.6The organization shall segment their networks to ensure networks provided to the public/customers are separated (and/or isolated) from the corporate networks.

Requirement

The organization shall segment their networks to ensure networks provided to the public/customers are separated (and/or isolated) from the corporate networks.

General implementation guidance

Segment networks to separate public/customer access from corporate networks. Ensure appropriate controls are in place for each segment.

Evidence an auditor may examine

Show network segmentation diagrams and the security measures implemented for each segment.

5.7.3.7The organization shall ensure the implementation of DMARC, DKIM and SPF on all organization email services.

Requirement

The organization shall ensure the implementation of DMARC, DKIM and SPF on all organization email services.

General implementation guidance

Configure SPF and DKIM for each organizational sending domain and publish a DMARC policy. Monitor DMARC reports and address unauthorized senders or configuration failures.

Evidence an auditor may examine

DNS records for SPF, DKIM and DMARC; DMARC aggregate reports; mail-provider configuration; and remediation records.

5.7.3.8The organization shall ensure email filtering is implemented.

Requirement

The organization shall ensure email filtering is implemented.

General implementation guidance

Implement email filtering solutions to block spam, phishing attempts, and other malicious content. Regularly update and configure the filtering criteria based on emerging threats.

Evidence an auditor may examine

Show documentation of the email filtering solution, including configuration settings and filtering rules.

5.7.3.9The organization should ensure that their users join a separate network that is independent of the home network (e.g. guest network) in conducting their employment activities.

Requirement

The organization should ensure that their users join a separate network that is independent of the home network (e.g. guest network) in conducting their employment activities.

General implementation guidance

Require remote workers to use a separate trusted work network, such as a dedicated home guest network, when feasible. Document guidance and any accepted exceptions.

Evidence an auditor may examine

Remote-work or home-network guidance; employee acknowledgements; awareness material; sampled interviews; and documented exceptions.

5.8.2.1The organization shall provision accounts with the minimum functionality necessary for tasks and shall restrict administrator privileges to an as-required basis.

Requirement

The organization shall provision accounts with the minimum functionality necessary for tasks and shall restrict administrator privileges to an as-required basis.

General implementation guidance

Implement user account management practices that adhere to the principle of least privilege, ensuring users are granted only the access necessary to perform their tasks. Regularly review user accounts and adjust privileges to ensure they align with current job responsibilities.

Evidence an auditor may examine

Documented policies and procedures for user account management. Records of user accounts, their privileges, and logs of changes made to account privileges.

5.8.2.2The organization shall remove accounts and/or functionality when users no longer require these for their tasks.

Requirement

The organization shall remove accounts and/or functionality when users no longer require these for their tasks.

General implementation guidance

Establish a process for regular review and removal of user accounts and privileges that are no longer required. Implement automated or manual procedures to promptly remove or adjust access when a user's role changes or when they leave the organization.

Evidence an auditor may examine

Documentation of the account review and removal process. Logs or records showing instances of account or privilege removals.

5.8.2.3The organization shall only permit administrator accounts to perform administrative activities (and not user-level activities such as accessing email or browsing the web).

Requirement

The organization shall only permit administrator accounts to perform administrative activities (and not user-level activities such as accessing email or browsing the web).

General implementation guidance

Ensure that administrator accounts are used exclusively for administrative tasks and are not used for regular user activities like email access or web browsing. Implement technical controls to enforce this separation of duties.

Evidence an auditor may examine

Policies outlining the acceptable use of administrator accounts. System logs or reports demonstrating compliance with these policies.

5.8.3.1The organization should implement a centralized authentication system such as a directory or identity service.

Requirement

The organization should implement a centralized authentication system such as a directory or identity service.

General implementation guidance

Consider implementing a centralized system for managing user authorizations across various systems and applications. Such a system can streamline the process of granting, adjusting, and revoking access, ensuring consistency and auditability.

Evidence an auditor may examine

If a centralized authorization system is implemented, provide documentation of the system and its configuration. If not implemented, document the rationale and describe any alternative measures in place for managing user access.

6.1.3.1The organization using mobile devices (i.e., cellphones) shall decide on an ownership model for mobile devices and document the rationale and associated risks.

Requirement

The organization using mobile devices (i.e., cellphones) shall decide on an ownership model for mobile devices and document the rationale and associated risks.

General implementation guidance

Choose between a COPE or BYOD model based on organizational needs. Assess the risks associated with each model, such as data security and device management.

Evidence an auditor may examine

Document outlining the chosen model, the rationale behind this choice, and a risk assessment related to mobile device usage in the organization.

6.1.3.2(a)require separation between work and personal data on mobile devices with access to corporate IT resources and document the details of this separation;

Requirement context

The organization using mobile devices (i.e., cellphones) shall:

Requirement

require separation between work and personal data on mobile devices with access to corporate IT resources and document the details of this separation;

General implementation guidance

Use mobile device management (MDM) solutions to create a clear separation between work and personal data, such as secure containers or profiles.

Evidence an auditor may examine

Policy documents detailing the separation measures and records of MDM settings on devices.

6.1.3.2(b)ensure that employees only download mobile device applications (i.e., apps) from the organization’s list of trusted sources;

Requirement context

The organization using mobile devices (i.e., cellphones) shall:

Requirement

ensure that employees only download mobile device applications (i.e., apps) from the organization’s list of trusted sources;

General implementation guidance

Establish a policy that restricts app downloads to organization-approved sources and regularly update the list of approved sources.

Evidence an auditor may examine

Policy documentation and a list of approved app sources.

6.1.3.2(c)require that all mobile devices store all sensitive information in a secure, encrypted state;

Requirement context

The organization using mobile devices (i.e., cellphones) shall:

Requirement

require that all mobile devices store all sensitive information in a secure, encrypted state;

General implementation guidance

Enforce encryption of sensitive data stored on mobile devices, using built-in encryption features or third-party tools.

Evidence an auditor may examine

Technical documentation or configuration settings showing encryption enforcement on devices.

6.1.3.2(d)implement an enterprise mobility management solution for all mobile devices or document the risks assumed to the audit, management, and security functionality of mobile devices by not implementing such a solution;

Requirement context

The organization using mobile devices (i.e., cellphones) shall:

Requirement

implement an enterprise mobility management solution for all mobile devices or document the risks assumed to the audit, management, and security functionality of mobile devices by not implementing such a solution;

General implementation guidance

If feasible, implement an EMM solution for enhanced device management. If not implemented, document the risks and alternative strategies.

Evidence an auditor may examine

Documentation of the EMM solution or a written rationale for not implementing it.

6.1.3.2(e)enforce users to: - disable automatic connections to open networks; - avoid connecting to untrusted Wi-Fi networks; - limit the use of Bluetooth and NFC for the exchange of sensitive information; - use corporate Wi-Fi or cellular data network connectivity rather than public Wi-Fi; and - use secure connectivity (VPN, Virtual Desktop etc.) when connecting to public Wi-Fi networks or provide the rationale for not doing so.

Requirement context

The organization using mobile devices (i.e., cellphones) shall:

Requirement

enforce users to: - disable automatic connections to open networks; - avoid connecting to untrusted Wi-Fi networks; - limit the use of Bluetooth and NFC for the exchange of sensitive information; - use corporate Wi-Fi or cellular data network connectivity rather than public Wi-Fi; and - use secure connectivity (VPN, Virtual Desktop etc.) when connecting to public Wi-Fi networks or provide the rationale for not doing so.

General implementation guidance

Conduct regular training sessions for employees on safe mobile device usage, focusing on secure connections and avoiding unsecured networks. Encourage the use of VPNs or other secure methods when connecting to public Wi-Fi. Document the reasons if these technologies are not implemented.

Evidence an auditor may examine

Training records, policy documents, and employee acknowledgments. "Policy documents on secure connectivity, VPN configuration settings, or a statement explaining the absence of such technologies. "

6.2.2.1Organization using cloud applications and/or outsourcing IT services shall evaluate their risk tolerance level with how their outsourced IT providers handle and access their sensitive information.

Requirement

Organization using cloud applications and/or outsourcing IT services shall evaluate their risk tolerance level with how their outsourced IT providers handle and access their sensitive information.

General implementation guidance

Assess the risk associated with how outsourced IT providers handle and access sensitive information. Consider factors like data security, privacy policies, and compliance with relevant regulations.

Evidence an auditor may examine

Risk assessment reports, including evaluations of IT service providers and the criteria used for these assessments.

6.2.3.1(a)complete a risk assessment of externally provided services. NOTE: Refer to Vendor Risk Analysis Questionnaire template in Annex C.

Requirement context

The organization using cloud applications and/or outsourcing IT services shall:

Requirement

complete a risk assessment of externally provided services. NOTE: Refer to Vendor Risk Analysis Questionnaire template in Annex C.

General implementation guidance

Assess each externally provided service before use and at planned intervals. Evaluate the service, data involved, access, availability dependencies, subcontractors and exit requirements.

Evidence an auditor may examine

Completed vendor risk assessments; service inventory; review approvals; reassessment schedule; identified risks; and treatment actions.

6.2.3.1(b)require that all their external providers share a report that states that they achieved compliance with SOC 2, ISO/IEC 27001, PCI-DSS, ISO/IEC 20000, CAN/DGSI 104:2021 or equivalent, or provide a documented business case as why they chose not to; NOTE: The organization determines equivalence to the standard depending on the type of IT service that is outsourced.

Requirement context

The organization using cloud applications and/or outsourcing IT services shall:

Requirement

require that all their external providers share a report that states that they achieved compliance with SOC 2, ISO/IEC 27001, PCI-DSS, ISO/IEC 20000, CAN/DGSI 104:2021 or equivalent, or provide a documented business case as why they chose not to; NOTE: The organization determines equivalence to the standard depending on the type of IT service that is outsourced.

General implementation guidance

Obtain and review relevant independent assurance reports or certifications from external providers. If suitable assurance is unavailable, document the business case, risk and compensating controls.

Evidence an auditor may examine

Current SOC 2, ISO/IEC 27001, PCI DSS, ISO/IEC 20000, CAN/DGSI 104 or equivalent reports; review notes; validity checks; or approved exception business cases.

6.2.3.1(c)complete a risk assessment of their data transmittal and data storage process (e.g., risks associated with legal jurisdictions);

Requirement context

The organization using cloud applications and/or outsourcing IT services shall:

Requirement

complete a risk assessment of their data transmittal and data storage process (e.g., risks associated with legal jurisdictions);

General implementation guidance

Assess how data is transmitted and stored, including encryption, geographic location, legal jurisdiction, retention, backup and deletion obligations.

Evidence an auditor may examine

Data-flow diagrams; data-location records; legal or privacy assessment; contract clauses; encryption configuration; and approved risk decisions.

6.2.3.1(d)ensure that their IT infrastructure and users communicate securely with all cloud services and applications; and

Requirement context

The organization using cloud applications and/or outsourcing IT services shall:

Requirement

ensure that their IT infrastructure and users communicate securely with all cloud services and applications; and

General implementation guidance

Require secure protocols and approved configurations for all user and infrastructure connections to cloud services and applications. Disable insecure or obsolete connection methods.

Evidence an auditor may examine

Architecture diagrams; TLS, VPN or secure-access configuration; identity-provider settings; security policies; and connection or monitoring logs.

6.2.3.1(e)ensure that all administrative accounts for cloud services use multi-factor authentication and differ from internal administrator accounts.

Requirement context

The organization using cloud applications and/or outsourcing IT services shall:

Requirement

ensure that all administrative accounts for cloud services use multi-factor authentication and differ from internal administrator accounts.

General implementation guidance

Protect every cloud administrative account with multi-factor authentication and use cloud administrator identities that are separate from internal administrator accounts.

Evidence an auditor may examine

Cloud identity inventory; MFA enforcement settings; separate administrator account records; privileged-access reviews; and authentication logs.

6.3.3.1The organization shall remediate the high and medium OWASP Top 10 risks (for primary marketing websites) to an acceptable risk tolerance level. NOTE: For a comprehensive list of vulnerability scanning tools, refer to the Community Page for “Vulnerability Scanning Tools” on the OWASP website.

Requirement

The organization shall remediate the high and medium OWASP Top 10 risks (for primary marketing websites) to an acceptable risk tolerance level. NOTE: For a comprehensive list of vulnerability scanning tools, refer to the Community Page for “Vulnerability Scanning Tools” on the OWASP website.

General implementation guidance

Conduct regular security assessments of websites to identify and address the OWASP top 10 vulnerabilities. Implement necessary security measures to mitigate these vulnerabilities, such as input validation, authentication controls, and secure configuration practices.

Evidence an auditor may examine

Security assessment reports showing the evaluation of websites against the OWASP top 10 vulnerabilities. Documentation of security measures implemented to address identified vulnerabilities.

6.3.3.2The organization shall define the OWASP ASVS level they need to meet for each of their websites.

Requirement

The organization shall define the OWASP ASVS level they need to meet for each of their websites.

General implementation guidance

Determine the appropriate OWASP Application Security Verification Standard (ASVS) level for each website based on its functionality and the sensitivity of the data it handles. Implement security controls and practices to meet the identified ASVS level. This may involve code reviews, penetration testing, and regular security audits.

Evidence an auditor may examine

Documentation outlining the ASVS levels determined for each website and the rationale behind these determinations. Evidence of security measures and practices in place to meet the ASVS levels, such as audit reports, test results, and security control documentation.

6.4.2.1Organizations using portable media shall mandate the sole use of organization-owned secure portable media.

Requirement

Organizations using portable media shall mandate the sole use of organization-owned secure portable media.

General implementation guidance

Implement a policy that restricts the use of portable media to only those devices provided and secured by the organization. Ensure these devices are commercially encrypted and track their distribution among employees.

Evidence an auditor may examine

Policy document mandating the use of organization-owned portable media. Records of issued devices and their encryption status.

6.4.3.1(a)have strong asset controls for these devices;

Requirement context

The organization using portable media shall:

Requirement

have strong asset controls for these devices;

General implementation guidance

Develop a system for tracking and monitoring the issuance, return, and usage of portable media devices. Conduct regular audits to account for all issued devices.

Evidence an auditor may examine

Asset tracking logs or a database showing the issuance and current status of each device. Audit reports demonstrating regular checks of portable media assets.

6.4.3.1(b)require the use of encryption on all of these devices; and

Requirement context

The organization using portable media shall:

Requirement

require the use of encryption on all of these devices; and

General implementation guidance

Enforce the use of encryption on all portable media devices. This can include hardware encryption or software-based encryption solutions. Regularly verify that the encryption is active and up-to-date.

Evidence an auditor may examine

Documentation of the encryption standards used and procedures for ensuring encryption on all devices. Records showing regular checks or audits of device encryption status.

6.4.3.1(c)have processes for the sanitization or destruction of portable media prior to disposal.

Requirement context

The organization using portable media shall:

Requirement

have processes for the sanitization or destruction of portable media prior to disposal.

General implementation guidance

Establish processes for the secure sanitization or destruction of portable media devices prior to their disposal. This can include physical destruction, degaussing, or software-based data wiping methods.

Evidence an auditor may examine

Procedures for device sanitization or destruction. Records of devices that have been sanitized or destroyed, including the methods used.

6.5.2.1The organization using point of sale terminals and financial systems shall follow the Payment Card Industry Data Security Standard (PCI DSS).

Requirement

The organization using point of sale terminals and financial systems shall follow the Payment Card Industry Data Security Standard (PCI DSS).

General implementation guidance

Conduct a comprehensive review of all POS terminals and financial systems to ensure they align with the requirements of the PCI DSS. Implement necessary controls as outlined in the PCI DSS, such as network segmentation, firewall implementation, encryption of transmission data, regular updates and patches, and strict access controls. Train staff on PCI DSS requirements and secure handling of payment card data. Regularly update and review the security measures to ensure ongoing compliance with the PCI DSS.

Evidence an auditor may examine

Documentation showing the organization’s PCI DSS compliance status, including self-assessment questionnaires or reports from external PCI DSS assessments. Records of security controls in place for POS and financial systems, such as network diagrams, firewall configurations, access control lists, and encryption protocols. Training records demonstrating staff education on PCI DSS and secure handling of payment card data. Logs or reports showing regular monitoring, testing, and updates of security measures related to POS and financial systems.

6.6.3.1The organization shall have a policy on log management (including log backup), and a procedure to implement the policy. NOTE:The retention period for logs depends on various factors, including legal requirements, business needs, and best practices.

Requirement

The organization shall have a policy on log management (including log backup), and a procedure to implement the policy. NOTE:The retention period for logs depends on various factors, including legal requirements, business needs, and best practices.

General implementation guidance

Assess the organization's current logging capabilities, identifying what security logs are being captured, such as user login events, file accesses, system configurations, firewall logs, and intrusion detection system logs. Develop a log management policy that outlines how logs are collected, stored, analyzed, and protected. The policy should address the retention period, access controls, and procedures for reviewing and analyzing logs. Implement tools and systems for effective log management, ensuring they can handle the volume and variety of logs generated. Train IT staff on the importance of log management and the procedures outlined in the policy. Regularly review and update the log management policy and tools to ensure they remain effective and align with the organization's evolving needs.

Evidence an auditor may examine

The log management policy document, detailing procedures for log collection, storage, analysis, and protection. Records of the log management system configuration and capabilities. Training records showing staff education on log management practices. Examples of logs being collected and reports generated from log analysis. Documentation of regular reviews and updates to the log management policy and systems.

Use in sequence

Videos and Usage Instructions

Below videos are intended to be used alongside the standard. Please purchase the standard first.

The videos are presented in sequence and should be watched in order.

If you have questions or comments, please email us at info@complade.com.

Introduction

Introduction to Standards

Overview of frameworks such as ISO, National Institute of Standards and Technology Cybersecurity Framework (NIST CSF), and System and Organization Controls 2 (SOC 2)

Video 01

CyberSecure Canada, Video 1

Standard here ( this is an older version but close to the current version). Use it as a reference only. You will be certified in the new standard here

Video 02

CyberSecure Canada Video 2

Reference links

Additional resources:

  1. 01
  2. 02
    Audit Sheet (make a copy and track your implementation):https://docs.google.com/spreadsheets/d/14JbN6yBnOYZjRiXft1-26KE3cwgc_c6Id8KAwW4z3sg
  3. 03
  4. 04
    Standard training by Complade (This is for the older version, but quite similar):/training/cybersecure-canada-training
  5. 05
Join our audit team

Audit careers at Complade

Complade recruits experienced external auditors and offers an Auditor in Training program with supervised external audit days.

Disclaimer

Complade provides these resources as a free service to enhance understanding of ISO 27001 and CyberSecure Canada. These resources are not a substitute for tailored implementation guidance. For customized support, we recommend working with qualified ISO consultants.