Research
The six domains that structure the Centre's research and advice, and why adversaries move across all of them at once.
There is no such thing as war in cyberspace. There is just war.
General John E. Hyten, commander, United States Strategic Command, 2017
The Centre’s research and advisory work is organised across six security domains. Together they form a structured framework for analysis and advice, and each is recognised within Government of Canada security policy.
The six divide into two groups. The first three are technological: they address vulnerabilities in electronic systems, signals, and emissions. The latter three are non-technological: they address vulnerabilities in people, information discipline, and the built environment.
The domains are not adversarial categories. They are the terrain on which adversaries operate, and every threat actor moves across all six at once.
Threat actors
Security domains
Every threat actor operates across every domain. The domains are the terrain, not the adversary.
Protecting information systems, networks, and data from unauthorised access, disruption, or exploitation.
Protecting communications from interception and exploitation, through encryption, key management, and secure transmission.
Suppressing compromising electronic emissions that could be used to reconstruct information, the concern of the TEMPEST standard.
Reducing the risk that people become a route to insider threat, foreign influence, or compromise.
Protecting the indicators that, in aggregate, could reveal sensitive operations or intentions.
Protecting people, facilities, and assets from physical threats, from unauthorised access to sabotage.
These six domains follow the structure of the Government of Canada’s Policy on Government Security (Treasury Board of Canada Secretariat, 2019). The Centre’s outputs align with this framework to stay relevant and interoperable with federal security programs.
Policy on Government Security, Treasury Board of Canada Secretariat