Research
Advise
Convene
Membership

Research

Resources

A curated register of Canadian authoritative guidance for national-security research and practice.

This page points to the Canadian authoritative sources for security policy and guidance, and highlights the documents that align most closely with the Centre's research. It is a curated register, not a catalogue. Follow the links to read the material at its source.

Foundations

Cross-cutting anchors that underpin most other guidance. Read these first.

Treasury Board of Canada Secretariat

Policies and standards on government security

The GC-wide policy topic index for government security. The starting point for the Policy on Government Security and its related directives and standards.

Read at tbs-sct.canada.ca

Treasury Board of Canada Secretariat

Policies and standards on service and digital

The GC-wide policy topic index for service and digital, including the Policy on Service and Digital and the Directive on Service and Digital, both of which carry security implications.

Read at tbs-sct.canada.ca

Canadian Centre for Cyber Security

Cyber Centre guidance library

The full published catalogue of the Cyber Centre's guidance. The register below picks out documents most relevant to the Centre's research; the whole library sits here.

Read at cyber.gc.ca

Royal Canadian Mounted Police

Guidance and publications

The published guidance library from the Lead Security Agency for Physical Security. The GC-wide entry point for physical-security work.

Read at rcmp.ca

ITSEC

Information Technology Security. Baseline controls, risk management, and technical safeguards for federal IT systems. Owned in the Government of Canada by the Canadian Centre for Cyber Security (Communications Security Establishment) and partly by the Treasury Board of Canada Secretariat.

Canadian Centre for Cyber Security

IT security risk management: a lifecycle approach ITSG-33

The foundational GC IT security control catalogue and risk-management lifecycle. Referenced across almost every subsequent piece of technical guidance.

Read at cyber.gc.ca

Canadian Centre for Cyber Security

Top 10 artificial intelligence security actions: a primer ITSAP.10.049

A concise practitioner-facing set of security actions for AI systems, useful when scoping controls for AI in national-security contexts.

Read at cyber.gc.ca

Canadian Centre for Cyber Security

User authentication guidance for information technology systems ITSP.30.031

The authoritative GC guidance on authenticator selection, assurance levels, and lifecycle management for IT systems.

Read at cyber.gc.ca

Canadian Centre for Cyber Security

Guidance on securely configuring network protocols ITSP.40.062

Recent guidance on the secure configuration of common network protocols. Useful for practitioners hardening network-facing services.

Read at cyber.gc.ca

Canadian Centre for Cyber Security

Baseline security requirements for network security zones ITSP.80.022

Baseline requirements for network security zoning across GC environments. Foundational reference for network architecture and segmentation decisions.

Read at cyber.gc.ca

Canadian Centre for Cyber Security

Cloud network security zones ITSP.80.023

The cloud-specific companion to ITSP.80.022, addressing how network security zones translate into cloud environments.

Read at cyber.gc.ca

COMSEC

Communications Security. Cryptography, keying material, and secure communications infrastructure. Owned by the Canadian Centre for Cyber Security, with much of the working material appropriately controlled and not published openly.

Canadian Centre for Cyber Security

Cryptographic algorithms for UNCLASSIFIED, PROTECTED A, and PROTECTED B information ITSP.40.111

The approved algorithm set for GC unclassified and protected information. Sets the current cryptographic baseline against which quantum-readiness work is measured.

Read at cyber.gc.ca

Canadian Centre for Cyber Security

Roadmap for the migration to post-quantum cryptography for the Government of Canada ITSM.40.001

The GC roadmap for the transition to post-quantum cryptography. Reference document for quantum-readiness planning across departments.

Read at cyber.gc.ca

Canadian Centre for Cyber Security

Preparing your organization for the quantum threat to cryptography ITSAP.00.017

A practitioner-level companion to the post-quantum roadmap, useful when briefing organizational leadership on the transition.

Read at cyber.gc.ca

EMSEC

Emissions Security. Protection against compromising emanations from information systems and equipment. Owned by the Canadian Centre for Cyber Security; most working material sits behind clearance and is not published openly.

Canadian Centre for Cyber Security

Emission security (EMSEC) guidance ITSG-11A

The published Canadian EMSEC guidance. Working material on compromising emanations is otherwise appropriately controlled and not linked here.

Read at cyber.gc.ca

PERSEC

Personnel Security. Security screening, ongoing suitability, and insider-risk management. Framed by the Treasury Board of Canada Secretariat at the policy level; each department and agency writes and applies its own program aligned to that framework.

Treasury Board of Canada Secretariat

Directive on Security Screening

The GC-wide directive setting out the requirements for personnel security screening.

Read at tbs-sct.canada.ca

Public Services and Procurement Canada

Personnel security screening overview

A practitioner-facing overview of the screening process, useful for those preparing or supporting a screening application.

Read at canada.ca

Canadian Centre for Cyber Security

How to protect your organization from insider threats ITSAP.10.003

A short primer on insider-threat indicators and mitigations. Useful complement to formal screening programs.

Read at cyber.gc.ca

Public Safety Canada

Resilience to insider risk

A critical-infrastructure perspective on insider risk, framed around resilience and organizational culture.

Read at publicsafety.gc.ca

Each department and agency

Departmental and agency programs

Personnel security programs are written and applied by each department and agency, aligned to the Treasury Board framework. Consult the security office of the relevant organization for its program.

OPSEC

Operational Security. Protecting sensitive information and activities from adversary observation. Framed at the policy level by the Treasury Board of Canada Secretariat, with technical guidance from the Canadian Centre for Cyber Security; each department and agency owns its own program.

Treasury Board of Canada Secretariat

Policies and standards on government security

The topic index containing the Policy on Government Security and the Directive on Security Management, which frame OPSEC across the Government of Canada.

Read at tbs-sct.canada.ca

Each department and agency

Departmental and agency programs

Operational security programs are written and applied by each department and agency, aligned to the Treasury Board framework and technical guidance from the Cyber Centre.

PHYSEC

Physical Security. Protection of facilities, assets, and people from physical threats. Owned in the Government of Canada by the Royal Canadian Mounted Police as the Lead Security Agency for Physical Security.

Royal Canadian Mounted Police

Access management guide GCPSG-006

Baseline concepts and control measures for managing physical access to GC facilities and zones.

Read at rcmp.ca

Royal Canadian Mounted Police

Physical security considerations for remote and telework environments GCPSG-008

The RCMP LSA guidance for the physical security posture of remote and telework arrangements, where policy and practice have converged only recently.

Read at rcmp.ca

Royal Canadian Mounted Police

Operational physical security guide GCPSG-010

The RCMP LSA operational guide covering the day-to-day physical-security posture of GC facilities, from threat conditions to safeguarding practices.

Read at rcmp.ca

Royal Canadian Mounted Police

Guide to the application of physical security zones GCPSG-015

Definitions and application of physical security zones (Public, Reception, Operations, Security, High-Security). Referenced widely across the RCMP LSA library.

Read at rcmp.ca

Royal Canadian Mounted Police

Threat and risk assessment guide GCPSG-022

The companion guide to the RCMP LSA Threat and Risk Assessment course. Sets out the seven-phase TRA process used across GC physical-security work.

Read at rcmp.ca

Royal Canadian Mounted Police

Physical security considerations in shared space GCPSG-023

Recent guidance on physical security in shared and multi-tenant workspaces, an area of growing operational concern.

Read at rcmp.ca