Account Management
Apply account management to control who can access in-scope systems, how information flows, and which access paths are allowed for CPCSC Level 2 readiness.
Open Level 2 control guideLast updated June 25, 2026
CPCSC Level 2 is the planned externally assessed certification path for Canadian defence suppliers. Levels 2 and 3 are still under development, so use this as a readiness library: 98 active ITSP.10.171 controls translated into practical pages that help teams move from official wording to implementation, evidence, and assessor-ready explanation.
Use the hub to find a control by family, then open the page for the formal control language, plain-English interpretation, implementation guidance, evidence examples, common auditor questions, and related control links.
Work by family when building readiness. Access, logging, configuration, incident response, risk, monitoring, planning, acquisition, and supply-chain controls all need evidence before an external assessment.
Apply account management to control who can access in-scope systems, how information flows, and which access paths are allowed for CPCSC Level 2 readiness.
Open Level 2 control guideApply access enforcement to control who can access in-scope systems, how information flows, and which access paths are allowed for CPCSC Level 2 readiness.
Open Level 2 control guideApply information flow enforcement to control who can access in-scope systems, how information flows, and which access paths are allowed for CPCSC Level 2 readiness.
Open Level 2 control guideApply separation of duties to control who can access in-scope systems, how information flows, and which access paths are allowed for CPCSC Level 2 readiness.
Open Level 2 control guideApply least privilege to control who can access in-scope systems, how information flows, and which access paths are allowed for CPCSC Level 2 readiness.
Open Level 2 control guideApply least privilege - privileged accounts to control who can access in-scope systems, how information flows, and which access paths are allowed for CPCSC Level 2 readiness.
Open Level 2 control guideApply least privilege - privileged functions to control who can access in-scope systems, how information flows, and which access paths are allowed for CPCSC Level 2 readiness.
Open Level 2 control guideApply unsuccessful logon attempts to control who can access in-scope systems, how information flows, and which access paths are allowed for CPCSC Level 2 readiness.
Open Level 2 control guideApply system use notification to control who can access in-scope systems, how information flows, and which access paths are allowed for CPCSC Level 2 readiness.
Open Level 2 control guideApply device lock to control who can access in-scope systems, how information flows, and which access paths are allowed for CPCSC Level 2 readiness.
Open Level 2 control guideApply session termination to control who can access in-scope systems, how information flows, and which access paths are allowed for CPCSC Level 2 readiness.
Open Level 2 control guideApply remote access to control who can access in-scope systems, how information flows, and which access paths are allowed for CPCSC Level 2 readiness.
Open Level 2 control guideApply wireless access to control who can access in-scope systems, how information flows, and which access paths are allowed for CPCSC Level 2 readiness.
Open Level 2 control guideApply access control for mobile devices to control who can access in-scope systems, how information flows, and which access paths are allowed for CPCSC Level 2 readiness.
Open Level 2 control guideApply use of external systems to control who can access in-scope systems, how information flows, and which access paths are allowed for CPCSC Level 2 readiness.
Open Level 2 control guideApply publicly accessible content to control who can access in-scope systems, how information flows, and which access paths are allowed for CPCSC Level 2 readiness.
Open Level 2 control guideApply literacy training and awareness to make sure people understand their responsibilities before they handle specified information for CPCSC Level 2 readiness.
Open Level 2 control guideApply role-based training to make sure people understand their responsibilities before they handle specified information for CPCSC Level 2 readiness.
Open Level 2 control guideApply event logging to produce reliable logs and review routines that show what happened in the environment for CPCSC Level 2 readiness.
Open Level 2 control guideApply audit record content to produce reliable logs and review routines that show what happened in the environment for CPCSC Level 2 readiness.
Open Level 2 control guideApply audit record generation to produce reliable logs and review routines that show what happened in the environment for CPCSC Level 2 readiness.
Open Level 2 control guideApply response to audit logging process failures to produce reliable logs and review routines that show what happened in the environment for CPCSC Level 2 readiness.
Open Level 2 control guideApply audit record review, analysis, and reporting to produce reliable logs and review routines that show what happened in the environment for CPCSC Level 2 readiness.
Open Level 2 control guideApply audit record reduction and report generation to produce reliable logs and review routines that show what happened in the environment for CPCSC Level 2 readiness.
Open Level 2 control guideApply time stamps to produce reliable logs and review routines that show what happened in the environment for CPCSC Level 2 readiness.
Open Level 2 control guideApply protection of audit information to produce reliable logs and review routines that show what happened in the environment for CPCSC Level 2 readiness.
Open Level 2 control guideApply baseline configuration to keep systems configured, changed, inventoried, and hardened in a controlled way for CPCSC Level 2 readiness.
Open Level 2 control guideApply configuration settings to keep systems configured, changed, inventoried, and hardened in a controlled way for CPCSC Level 2 readiness.
Open Level 2 control guideApply configuration change control to keep systems configured, changed, inventoried, and hardened in a controlled way for CPCSC Level 2 readiness.
Open Level 2 control guideApply impact analyses to keep systems configured, changed, inventoried, and hardened in a controlled way for CPCSC Level 2 readiness.
Open Level 2 control guideApply access restrictions for change to keep systems configured, changed, inventoried, and hardened in a controlled way for CPCSC Level 2 readiness.
Open Level 2 control guideApply least functionality to keep systems configured, changed, inventoried, and hardened in a controlled way for CPCSC Level 2 readiness.
Open Level 2 control guideApply authorized software - allow by exception to keep systems configured, changed, inventoried, and hardened in a controlled way for CPCSC Level 2 readiness.
Open Level 2 control guideApply system component inventory to keep systems configured, changed, inventoried, and hardened in a controlled way for CPCSC Level 2 readiness.
Open Level 2 control guideApply information location to keep systems configured, changed, inventoried, and hardened in a controlled way for CPCSC Level 2 readiness.
Open Level 2 control guideApply system and component configuration for high-risk areas to keep systems configured, changed, inventoried, and hardened in a controlled way for CPCSC Level 2 readiness.
Open Level 2 control guideApply user identification, authentication, and re-authentication to prove that users, devices, and authenticators are unique, protected, and trustworthy for CPCSC Level 2 readiness.
Open Level 2 control guideApply device identification and authentication to prove that users, devices, and authenticators are unique, protected, and trustworthy for CPCSC Level 2 readiness.
Open Level 2 control guideApply multi-factor authentication to prove that users, devices, and authenticators are unique, protected, and trustworthy for CPCSC Level 2 readiness.
Open Level 2 control guideApply replay-resistant authentication to prove that users, devices, and authenticators are unique, protected, and trustworthy for CPCSC Level 2 readiness.
Open Level 2 control guideApply identifier management to prove that users, devices, and authenticators are unique, protected, and trustworthy for CPCSC Level 2 readiness.
Open Level 2 control guideApply password management to prove that users, devices, and authenticators are unique, protected, and trustworthy for CPCSC Level 2 readiness.
Open Level 2 control guideApply authentication feedback to prove that users, devices, and authenticators are unique, protected, and trustworthy for CPCSC Level 2 readiness.
Open Level 2 control guideApply authenticator management to prove that users, devices, and authenticators are unique, protected, and trustworthy for CPCSC Level 2 readiness.
Open Level 2 control guideApply incident handling to prepare the organization to identify, report, contain, and learn from security incidents for CPCSC Level 2 readiness.
Open Level 2 control guideApply incident monitoring, reporting, and response assistance to prepare the organization to identify, report, contain, and learn from security incidents for CPCSC Level 2 readiness.
Open Level 2 control guideApply incident response testing to prepare the organization to identify, report, contain, and learn from security incidents for CPCSC Level 2 readiness.
Open Level 2 control guideApply incident response training to prepare the organization to identify, report, contain, and learn from security incidents for CPCSC Level 2 readiness.
Open Level 2 control guideApply incident response plan to prepare the organization to identify, report, contain, and learn from security incidents for CPCSC Level 2 readiness.
Open Level 2 control guideApply maintenance tools to control maintenance tools, remote maintenance, and the people who service in-scope systems for CPCSC Level 2 readiness.
Open Level 2 control guideApply non-local maintenance to control maintenance tools, remote maintenance, and the people who service in-scope systems for CPCSC Level 2 readiness.
Open Level 2 control guideApply maintenance personnel to control maintenance tools, remote maintenance, and the people who service in-scope systems for CPCSC Level 2 readiness.
Open Level 2 control guideApply media storage to protect storage media through its lifecycle from storage and access through transport, reuse, and disposal for CPCSC Level 2 readiness.
Open Level 2 control guideApply media access to protect storage media through its lifecycle from storage and access through transport, reuse, and disposal for CPCSC Level 2 readiness.
Open Level 2 control guideApply media sanitization to protect storage media through its lifecycle from storage and access through transport, reuse, and disposal for CPCSC Level 2 readiness.
Open Level 2 control guideApply media marking to protect storage media through its lifecycle from storage and access through transport, reuse, and disposal for CPCSC Level 2 readiness.
Open Level 2 control guideApply media transport to protect storage media through its lifecycle from storage and access through transport, reuse, and disposal for CPCSC Level 2 readiness.
Open Level 2 control guideApply media use to protect storage media through its lifecycle from storage and access through transport, reuse, and disposal for CPCSC Level 2 readiness.
Open Level 2 control guideApply system backup - cryptographic protection to protect storage media through its lifecycle from storage and access through transport, reuse, and disposal for CPCSC Level 2 readiness.
Open Level 2 control guideApply personnel screening to manage personnel trust, screening, termination, and transfer processes around specified information for CPCSC Level 2 readiness.
Open Level 2 control guideApply personnel termination and transfer to manage personnel trust, screening, termination, and transfer processes around specified information for CPCSC Level 2 readiness.
Open Level 2 control guideApply physical access authorizations to protect facilities, work sites, transmission paths, and physical access to systems and media for CPCSC Level 2 readiness.
Open Level 2 control guideApply monitoring physical access to protect facilities, work sites, transmission paths, and physical access to systems and media for CPCSC Level 2 readiness.
Open Level 2 control guideApply alternate work site to protect facilities, work sites, transmission paths, and physical access to systems and media for CPCSC Level 2 readiness.
Open Level 2 control guideApply physical access control to protect facilities, work sites, transmission paths, and physical access to systems and media for CPCSC Level 2 readiness.
Open Level 2 control guideApply access control for transmission to protect facilities, work sites, transmission paths, and physical access to systems and media for CPCSC Level 2 readiness.
Open Level 2 control guideApply risk assessment to identify, prioritize, scan, and respond to risks that could affect specified information for CPCSC Level 2 readiness.
Open Level 2 control guideApply vulnerability monitoring and scanning to identify, prioritize, scan, and respond to risks that could affect specified information for CPCSC Level 2 readiness.
Open Level 2 control guideApply risk response to identify, prioritize, scan, and respond to risks that could affect specified information for CPCSC Level 2 readiness.
Open Level 2 control guideApply security assessment to assess controls, track remediation, monitor effectiveness, and manage information exchanges for CPCSC Level 2 readiness.
Open Level 2 control guideApply plan of action and milestones to assess controls, track remediation, monitor effectiveness, and manage information exchanges for CPCSC Level 2 readiness.
Open Level 2 control guideApply continuous monitoring to assess controls, track remediation, monitor effectiveness, and manage information exchanges for CPCSC Level 2 readiness.
Open Level 2 control guideApply information exchange to assess controls, track remediation, monitor effectiveness, and manage information exchanges for CPCSC Level 2 readiness.
Open Level 2 control guideApply boundary protection to protect system boundaries, communications, cryptography, shared resources, and sessions for CPCSC Level 2 readiness.
Open Level 2 control guideApply information in shared system resources to protect system boundaries, communications, cryptography, shared resources, and sessions for CPCSC Level 2 readiness.
Open Level 2 control guideApply network communications - deny by default - allow by exception to protect system boundaries, communications, cryptography, shared resources, and sessions for CPCSC Level 2 readiness.
Open Level 2 control guideApply transmission and storage confidentiality to protect system boundaries, communications, cryptography, shared resources, and sessions for CPCSC Level 2 readiness.
Open Level 2 control guideApply network disconnect to protect system boundaries, communications, cryptography, shared resources, and sessions for CPCSC Level 2 readiness.
Open Level 2 control guideApply cryptographic key establishment and management to protect system boundaries, communications, cryptography, shared resources, and sessions for CPCSC Level 2 readiness.
Open Level 2 control guideApply cryptographic protection to protect system boundaries, communications, cryptography, shared resources, and sessions for CPCSC Level 2 readiness.
Open Level 2 control guideApply collaborative computing devices and applications to protect system boundaries, communications, cryptography, shared resources, and sessions for CPCSC Level 2 readiness.
Open Level 2 control guideApply mobile code to protect system boundaries, communications, cryptography, shared resources, and sessions for CPCSC Level 2 readiness.
Open Level 2 control guideApply session authenticity to protect system boundaries, communications, cryptography, shared resources, and sessions for CPCSC Level 2 readiness.
Open Level 2 control guideApply flaw remediation to find flaws, detect threats, monitor activity, and retain information appropriately for CPCSC Level 2 readiness.
Open Level 2 control guideApply malicious code protection to find flaws, detect threats, monitor activity, and retain information appropriately for CPCSC Level 2 readiness.
Open Level 2 control guideApply security alerts, advisories, and directives to find flaws, detect threats, monitor activity, and retain information appropriately for CPCSC Level 2 readiness.
Open Level 2 control guideApply system monitoring to find flaws, detect threats, monitor activity, and retain information appropriately for CPCSC Level 2 readiness.
Open Level 2 control guideApply information management and retention to find flaws, detect threats, monitor activity, and retain information appropriately for CPCSC Level 2 readiness.
Open Level 2 control guideApply dedicated administration workstation to find flaws, detect threats, monitor activity, and retain information appropriately for CPCSC Level 2 readiness.
Open Level 2 control guideApply policy and procedures to document how the system is scoped, protected, used, and governed for CPCSC Level 2 readiness.
Open Level 2 control guideApply system security plan to document how the system is scoped, protected, used, and governed for CPCSC Level 2 readiness.
Open Level 2 control guideApply rules of behaviour to document how the system is scoped, protected, used, and governed for CPCSC Level 2 readiness.
Open Level 2 control guideApply security engineering principles to build security expectations into engineering, unsupported components, and external services for CPCSC Level 2 readiness.
Open Level 2 control guideApply unsupported system components to build security expectations into engineering, unsupported components, and external services for CPCSC Level 2 readiness.
Open Level 2 control guideApply external system services to build security expectations into engineering, unsupported components, and external services for CPCSC Level 2 readiness.
Open Level 2 control guideApply supply chain risk management plan to manage supplier, acquisition, and supply chain risks that affect the in-scope environment for CPCSC Level 2 readiness.
Open Level 2 control guideApply acquisition strategies, tools, and methods to manage supplier, acquisition, and supply chain risks that affect the in-scope environment for CPCSC Level 2 readiness.
Open Level 2 control guideApply supply chain requirements and processes to manage supplier, acquisition, and supply chain risks that affect the in-scope environment for CPCSC Level 2 readiness.
Open Level 2 control guideFormal control language is sourced from the Canadian Centre for Cyber Security ITSP.10.171 publication. CPCSC Level 2 timing and assessment model references the Government of Canada CPCSC program overview and supplier support guidance.
Government of Canada information is used under the Open Government Licence - Canada. Confirm current requirements in the contract, RFP, and official CPCSC guidance before making certification decisions.
CPCSC Program OverviewSupplier Support GuidanceITSP.10.171ITSP.10.171-01Open Government Licence - Canada