A cropped image showing the upper corner of a blue and black rectangular object, possibly a screen or monitor used in defence and security solutions Canada, set against a light background.

Insights

Make Haste Slowly

The ancient maxim "make haste slowly" reminds us that moving quickly should never come at the expense of sound judgment. The rollout of the Canadian Program for Cyber Security Certification (CPCSC) presents a similar challenge.

By Allan McDougall MA BMASc CMAS CISSP CPP
Senior Security Program Manager and Acting Chief Information Security Officer (CISO), ADGA Group

Canada set an April 1 deadline for Level 1, and many companies rushed to meet it. That threshold involved a relatively small number of requirements—13 in total—which might be understood more as basic cyber hygiene than as a robust cybersecurity posture.

Industry is now moving toward Level 2 certification, which involves 98 requirements and a third-party assessment. 

But here is where industry must be cautious. As organizations prepare for CPCSC, a growing number of tools are emerging that claim to score CPCSC compliance. While there is some validity to arguing that a careful reading of ITSP.10.171 can tease out certain critical elements (something we’ve done ourselves at ADGA), it cannot argue that this will result in a pass nor can it argue that a certain score is required to pass. 

"Until the CPCSC Secretariat publishes the assessment regime, any scoring methodology represents an interpretation of the standard—not the certification standard itself."

Why is this?

Simply put: because the regime necessary to pass the certification has not been publicly defined. The public releases of information do not indicate any more than that a regime will be put forward. It is true that the CMMC 2.0 uses a scoring system that indicates certain critical controls, but Canada’s structure is not available yet. Concurrently, the CMMC 2.0 controls are based on an earlier version of the NIST SP 800-171 meaning that there are significant differences between the two standards. Those who wish to see what those differences are can go straight to the source (NIST) where the differences between the NIST SP 800-171 Version 2 (CMMC) and Version 3 (CPCSC) are mapped by the originating standards body. 

In certification, the pass-fail threshold is set by the standard-setting body. This would be the CPCSC Secretariat and its associated partner organizations. While they have provided some guidance with respect to Level 2 being tied to the requirements of ITSP.10.171, they have not communicated any special criteria for passing, conditional passing, etc. And it should be clear that any company that argues that they have such tools are in a situation where the cart is before the horse. 

Why does this pressure work?

Simply put, this approach relies on two things. First, companies are likely to become more concerned with either (1) clearly demonstrating that they pass or (2) being able to defend their results as the deadline approaches. The second is that many organizations may seek to influence emerging implementation approaches by promoting methodologies they’ve already developed. 

Where are we now?

Organizations should continue preparing for CPCSC Level 2 by strengthening their cyber security posture against the requirements of ITSP.10.171. At the same time, they should be cautious of claims suggesting that certification outcomes can already be predicted with certainty. Until the CPCSC Secretariat publishes the assessment regime, any scoring methodology represents an interpretation of the standardnot the certification standard itself. 

Quick Actions

Read more stories

Share this posting