Canada ITSP.10.033 Security and Privacy Controls and Assurance Activities Catalogue
SA: System and services acquisition – Canada ITSP.10.033 Security and Privacy Controls and Assurance Activities Catalogue

Canada ITSP.10.033 Security and Privacy Controls and Assurance Activities Catalogue SA-400: SA-400 Sovereignty and jurisdiction

Canada-specific control: the organisation requires its business function to run a sovereignty and jurisdiction threat and risk assessment at the selected organisation, mission or system level that assesses the maximum injury from external legal compulsion of business functions or information assets (considering business needs for security including laws requiring non-disclosure, updating the security categorization, and documenting the consequences of compulsion), performs a jurisdiction-specific threat assessment of the likelihood of being targeted, assesses how the foreign jurisdiction could exploit the functions or assets, and completes a jurisdiction-specific risk assessment. The GC discussion cites the TBS Directive on Service and Digital requirement that Protected B and C data be located in Canadian jurisdiction as the principal option, and the Cyber Centre recommendation to keep all significantly sensitive data and functions in Canada. 9 enhancements.

Maintained by Gerard Blokdyk

Other controls in SA: System and services acquisition – Canada ITSP.10.033 Security and Privacy Controls and Assurance Activities Catalogue

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.