Policies and standards on government security
The GC-wide policy topic index for government security. The starting point for the Policy on Government Security and its related directives and standards.
Research
A curated register of Canadian authoritative guidance for national-security research and practice.
This page points to the Canadian authoritative sources for security policy and guidance, and highlights the documents that align most closely with the Centre's research. It is a curated register, not a catalogue. Follow the links to read the material at its source.
Cross-cutting anchors that underpin most other guidance. Read these first.
The GC-wide policy topic index for government security. The starting point for the Policy on Government Security and its related directives and standards.
The GC-wide policy topic index for service and digital, including the Policy on Service and Digital and the Directive on Service and Digital, both of which carry security implications.
The full published catalogue of the Cyber Centre's guidance. The register below picks out documents most relevant to the Centre's research; the whole library sits here.
The published guidance library from the Lead Security Agency for Physical Security. The GC-wide entry point for physical-security work.
Information Technology Security. Baseline controls, risk management, and technical safeguards for federal IT systems. Owned in the Government of Canada by the Canadian Centre for Cyber Security (Communications Security Establishment) and partly by the Treasury Board of Canada Secretariat.
The foundational GC IT security control catalogue and risk-management lifecycle. Referenced across almost every subsequent piece of technical guidance.
A concise practitioner-facing set of security actions for AI systems, useful when scoping controls for AI in national-security contexts.
The authoritative GC guidance on authenticator selection, assurance levels, and lifecycle management for IT systems.
Recent guidance on the secure configuration of common network protocols. Useful for practitioners hardening network-facing services.
Baseline requirements for network security zoning across GC environments. Foundational reference for network architecture and segmentation decisions.
The cloud-specific companion to ITSP.80.022, addressing how network security zones translate into cloud environments.
Communications Security. Cryptography, keying material, and secure communications infrastructure. Owned by the Canadian Centre for Cyber Security, with much of the working material appropriately controlled and not published openly.
The approved algorithm set for GC unclassified and protected information. Sets the current cryptographic baseline against which quantum-readiness work is measured.
The GC roadmap for the transition to post-quantum cryptography. Reference document for quantum-readiness planning across departments.
A practitioner-level companion to the post-quantum roadmap, useful when briefing organizational leadership on the transition.
Emissions Security. Protection against compromising emanations from information systems and equipment. Owned by the Canadian Centre for Cyber Security; most working material sits behind clearance and is not published openly.
The published Canadian EMSEC guidance. Working material on compromising emanations is otherwise appropriately controlled and not linked here.
Personnel Security. Security screening, ongoing suitability, and insider-risk management. Framed by the Treasury Board of Canada Secretariat at the policy level; each department and agency writes and applies its own program aligned to that framework.
The GC-wide directive setting out the requirements for personnel security screening.
A practitioner-facing overview of the screening process, useful for those preparing or supporting a screening application.
A short primer on insider-threat indicators and mitigations. Useful complement to formal screening programs.
A critical-infrastructure perspective on insider risk, framed around resilience and organizational culture.
Personnel security programs are written and applied by each department and agency, aligned to the Treasury Board framework. Consult the security office of the relevant organization for its program.
Operational Security. Protecting sensitive information and activities from adversary observation. Framed at the policy level by the Treasury Board of Canada Secretariat, with technical guidance from the Canadian Centre for Cyber Security; each department and agency owns its own program.
The topic index containing the Policy on Government Security and the Directive on Security Management, which frame OPSEC across the Government of Canada.
Operational security programs are written and applied by each department and agency, aligned to the Treasury Board framework and technical guidance from the Cyber Centre.
Physical Security. Protection of facilities, assets, and people from physical threats. Owned in the Government of Canada by the Royal Canadian Mounted Police as the Lead Security Agency for Physical Security.
Baseline concepts and control measures for managing physical access to GC facilities and zones.
The RCMP LSA guidance for the physical security posture of remote and telework arrangements, where policy and practice have converged only recently.
The RCMP LSA operational guide covering the day-to-day physical-security posture of GC facilities, from threat conditions to safeguarding practices.
Definitions and application of physical security zones (Public, Reception, Operations, Security, High-Security). Referenced widely across the RCMP LSA library.
The companion guide to the RCMP LSA Threat and Risk Assessment course. Sets out the seven-phase TRA process used across GC physical-security work.
Recent guidance on physical security in shared and multi-tenant workspaces, an area of growing operational concern.