Free compliance framework explorer — browse controls, evidence, and implementation guidance.Subscribe for updates →
BETA
SOC 247
ITSP.10.17198
ISO 42001soon
ISO 27001soon
Browse
Ctrl+K
98 controls
03.01.01
Account management
Access control
3 evidence1 control
03.01.02
Access enforcement
Access control
2 evidence1 control
03.01.03
Information flow enforcement
Access control
2 evidence1 control
03.01.04
Separation of duties
Access control
3 evidence1 control
03.01.05
Least privilege
Access control
2 evidence1 control
03.01.06
Least privilege - privileged accounts
Access control
3 evidence1 control
03.01.07
Least privilege - privileged functions
Access control
2 evidence1 control
03.01.08
Unsuccessful logon attempts
Access control
2 evidence1 control
03.01.09
System use notification
Access control
2 evidence1 control
03.01.10
Device lock
Access control
2 evidence1 control
03.01.11
Session termination
Access control
2 evidence1 control
03.01.12
Remote access
Access control
3 evidence1 control
03.01.16
Wireless access
Access control
2 evidence1 control
03.01.18
Access control for mobile devices
Access control
3 evidence1 control
03.01.20
Use of external systems
Access control
2 evidence1 control
03.01.22
Publicly accessible content
Access control
3 evidence1 control
03.02.01
Literacy training and awareness
Awareness and training
3 evidence1 control
03.02.02
Role-based training
Awareness and training
2 evidence1 control
03.03.01
Event logging
Audit and accountability
3 evidence1 control
03.03.02
Audit record content
Audit and accountability
2 evidence1 control
03.03.03
Audit record generation
Audit and accountability
2 evidence1 control
03.03.04
Response to audit logging process failures
Audit and accountability
2 evidence1 control
03.03.05
Audit record review, analysis, and reporting
Audit and accountability
3 evidence1 control
03.03.06
Audit record reduction and report generation
Audit and accountability
2 evidence1 control
03.03.07
Time stamps
Audit and accountability
2 evidence1 control
03.03.08
Protection of audit information
Audit and accountability
3 evidence1 control
03.04.01
Baseline configuration
Configuration management
2 evidence1 control
03.04.02
Configuration settings
Configuration management
2 evidence1 control
03.04.03
Configuration change control
Configuration management
3 evidence1 control
03.04.04
Impact analyses
Configuration management
2 evidence1 control
03.04.05
Access restrictions for change
Configuration management
2 evidence1 control
03.04.06
Least functionality
Configuration management
2 evidence1 control
03.04.08
Authorized software - allow by exception
Configuration management
2 evidence1 control
03.04.10
System component inventory
Configuration management
2 evidence1 control
03.04.11
Information location
Configuration management
2 evidence1 control
03.04.12
System and component configuration for high-risk areas
Configuration management
2 evidence1 control
03.05.01
User identification, authentication, and re-authentication
Identification and authentication
2 evidence1 control
03.05.02
Device identification and authentication
Identification and authentication
2 evidence1 control
03.05.03
Multi-factor authentication
Identification and authentication
3 evidence1 control
03.05.04
Replay-resistant authentication
Identification and authentication
2 evidence1 control
03.05.05
Identifier management
Identification and authentication
2 evidence1 control
03.05.07
Password management
Identification and authentication
3 evidence1 control
03.05.11
Authentication feedback
Identification and authentication
2 evidence1 control
03.05.12
Authenticator management
Identification and authentication
3 evidence1 control
03.06.01
Incident handling
Incident response
3 evidence1 control
03.06.02
Incident monitoring, reporting, and response assistance
Incident response
3 evidence1 control
03.06.03
Incident response testing
Incident response
2 evidence1 control
03.06.04
Incident response training
Incident response
2 evidence1 control
03.06.05
Incident response plan
Incident response
3 evidence1 control
03.07.04
Maintenance tools
Maintenance
3 evidence1 control
03.07.05
Non-local maintenance
Maintenance
3 evidence1 control
03.07.06
Maintenance personnel
Maintenance
4 evidence1 control
03.08.01
Media storage
Media protection
3 evidence1 control
03.08.02
Media access
Media protection
3 evidence1 control
03.08.03
Media sanitization
Media protection
3 evidence1 control
03.08.04
Media marking
Media protection
3 evidence1 control
03.08.05
Media transport
Media protection
3 evidence1 control
03.08.07
Media use
Media protection
3 evidence1 control
03.08.09
System backup - cryptographic protection
Media protection
3 evidence1 control
03.09.01
Personnel screening
Personnel security
3 evidence1 control
03.09.02
Personnel termination and transfer
Personnel security
3 evidence1 control
03.10.01
Physical access authorizations
Physical protection
3 evidence1 control
03.10.02
Monitoring physical access
Physical protection
3 evidence1 control
03.10.06
Alternate work site
Physical protection
3 evidence1 control
03.10.07
Physical access control
Physical protection
3 evidence1 control
03.10.08
Access control for transmission
Physical protection
3 evidence1 control
03.11.01
Risk assessment
Risk assessment
3 evidence1 control
03.11.02
Vulnerability monitoring and scanning
Risk assessment
3 evidence1 control
03.11.04
Risk response
Risk assessment
3 evidence1 control
03.12.01
Security assessment
Security assessment and monitoring
3 evidence1 control
03.12.02
Plan of action and milestones
Security assessment and monitoring
3 evidence1 control
03.12.03
Continuous monitoring
Security assessment and monitoring
3 evidence1 control
03.12.05
Information exchange
Security assessment and monitoring
3 evidence1 control
03.13.01
Boundary protection
System and communications protection
3 evidence1 control
03.13.04
Information in shared system resources
System and communications protection
3 evidence1 control
03.13.06
Network communications - deny by default - allow by exception
System and communications protection
3 evidence1 control
03.13.08
Transmission and storage confidentiality
System and communications protection
3 evidence1 control
03.13.09
Network disconnect
System and communications protection
3 evidence1 control
03.13.10
Cryptographic key establishment and management
System and communications protection
3 evidence1 control
03.13.11
Cryptographic protection
System and communications protection
3 evidence1 control
03.13.12
Collaborative computing devices and applications
System and communications protection
3 evidence1 control
03.13.13
Mobile code
System and communications protection
3 evidence1 control
03.13.15
Session authenticity
System and communications protection
3 evidence1 control
03.14.01
Flaw remediation
System and information integrity
3 evidence1 control
03.14.02
Malicious code protection
System and information integrity
3 evidence1 control
03.14.03
Security alerts, advisories, and directives
System and information integrity
3 evidence1 control
03.14.06
System monitoring
System and information integrity
3 evidence1 control
03.14.08
Information management and retention
System and information integrity
3 evidence1 control
03.14.09
Dedicated administration workstation
System and information integrity
3 evidence1 control
03.15.01
Policy and procedures
Planning
3 evidence1 control
03.15.02System security planITSP.10.171Planning
Official Requirement
A. Develop a system security and privacy plan that: 1. defines the constituent system components 2. identifies the information types processed, stored, and transmitted by the system 3. describes specific threats to the system that are of concern to the organization 4. describes the operational environment for the system and any dependencies on or connections to other systems or system components 5. provides an overview of the security requirements for the system 6. describes the safeguards in place or planned for meeting the security requirements 7. identifies individuals that fulfill system roles and responsibilities 8. includes other relevant information necessary for the protection of specified information. B. Review and update the system security plan [Assignment: organization-defined frequency]. C. Protect the system security plan from unauthorized disclosure.
Source: Canadian Centre for Cyber Security ITSP.10.171 (2025), adapted from NIST SP 800-171 Rev. 3
In Plain English
You need a system security plan (SSP) that describes your system's components, the types of information it handles, threats, the operating environment, security requirements, implemented safeguards, and responsible personnel. The SSP must be reviewed and updated regularly, and it must be protected from unauthorized disclosure since it contains sensitive details about your security posture.
These are typical controls and implementation steps. Your systems and environment may differ.
Typical Control System security plan development and maintenance
Implementation Steps
Develop a system security plan (SSP) documenting system components, information types, threats (including supply chain), operational environment, security requirements, and safeguards
Identify and document individuals fulfilling security roles and responsibilities within the SSP
Store the SSP in a secure, access-controlled location with restricted read access to authorized personnel only
Review and update the SSP at the defined frequency (e.g., annually) and whenever significant system changes occur
Tools / Systems
SSP template (NIST-aligned format)Secure document repository with access controls (SharePoint, Confluence with restrictions)GRC platform for SSP managementSSP review and update tracking calendar
Typical Control System security plan development and maintenance
Evidence Artifacts
System security plan document with all required elements completed
Access control records showing SSP protection from unauthorized disclosure
SSP review and update records with revision dates and change summaries
📅Annual SSP review and update (or at defined frequency); per-event updates for significant system changes
Cross-framework mappings coming in v1.1
When we add ISO 42001 and ISO 27001, you'll see which controls map to this criterion.
ISO
ISO 42001
AI Management Systems
ISO
ISO 27001
Information Security
Mapping data will appear here automatically when the frameworks are published.
03.15.03
Rules of behaviour
Planning
3 evidence1 control
03.16.01
Security engineering principles
System and services acquisition
3 evidence1 control
03.16.02
Unsupported system components
System and services acquisition
3 evidence1 control
03.16.03
External system services
System and services acquisition
3 evidence1 control
03.17.01
Supply chain risk management plan
Supply chain risk management
3 evidence1 control
03.17.02
Acquisition strategies, tools, and methods
Supply chain risk management
3 evidence1 control
03.17.03
Supply chain requirements and processes
Supply chain risk management
3 evidence1 control
Help us build what matters.
Vote for the next framework, subscribe for updates, and let us know if you'd contribute.
What should we add next?
Vote for the framework you need most.
0
ISO 42001
0
ISO 27001
0
CMMC
0
CPCSC
Stay Updated
Get notified when new frameworks and features are added.
On-premises implementation and evidence
System security plan development and maintenance
Implementation steps
Create a comprehensive SSP covering all required elements: system architecture, data types, threat environment, security requirements, safeguards, and personnel
Ensure the SSP is consistent with the organization's enterprise architecture and includes supply chain threat analysis
Protect the SSP from unauthorized disclosure by storing it in a secured location with access restricted to authorized individuals
Schedule and conduct SSP reviews at the defined frequency; update when system components, threats, or requirements change
Tools / systems
SSP document template aligned with NIST requirements
Secure document management with access controls
GRC platform or secure file share for SSP storage
Review and revision tracking system
Evidence artifacts
Completed SSP with management approval and effective date
SSP access control records showing restricted distribution
Revision history documenting reviews, updates, and triggering events
Evidence frequency: Annual SSP review and update (or at defined frequency); per-event updates for significant system changes