Who this applies to
Small and medium organizations that need a defensible starting point and do not have a security program yet.
What to know
- It is written by the Canadian Centre for Cyber Security for organizations that meet the federal definition of small or medium, under 500 employees.
- The controls are grouped into 13 categories, among them incident response planning, patching, anti-malware and firewalls, secure configuration, multi-factor authentication, awareness training, backups, mobile devices, network perimeter, cloud providers, website security, access control, and portable media.
- It also asks the organization to document its systems, assess potential harm, name its main cyber threat, and commit leadership and budget.
- The list is deliberately short. It is a floor, not a full security program.
What to do
- Score your organization against each category and write down the gaps.
- Fix multi-factor authentication, patching, and backups first, because they stop the most common attacks.
- Test a restore from your backups before you need one.
This guide is a plain-language summary for general information. It is not legal advice and it does not replace the official source. Requirements change, so check the linked source before you act.