Identify the information
Record what specified information is involved, who provides it and which contractual requirement protects it.
Identify the people, devices, systems, facilities, providers and information flows that belong inside the assessment boundary before reviewing the 13 controls.
Specified information is Government of Canada information that must be protected when handled, processed or stored by a non-government organization. Start with the contract and map how that information is received, created, viewed, emailed, printed, copied, backed up, transferred, archived and destroyed.
Record what specified information is involved, who provides it and which contractual requirement protects it.
Follow the information from receipt through use, sharing, storage, backup, printing and disposal.
Include employees, contractors, administrators, facilities, home workspaces and physical storage points.
Include devices, email, cloud services, servers, networks, printers, scanners, removable media and security tools.
Identify external service providers, remote support, subcontractors and every connection into or out of the environment.
Record why each asset is in scope, out of scope or specialized, and maintain a simple network diagram.
A personal computer or phone belongs in scope when it can access specified information, even when it is used only for email.
Paper is storage. Multifunction devices may scan, cache and transmit information and should be considered accordingly.
Microsoft 365, backup providers, managed services, identity systems and remote-support tools can operate within the security scope.
Subcontractors perform their own scoping when they handle the same specified information. Prime contractors should document certification and access decisions.
VPNs, vendor connections, cloud integrations, email forwarding and unmanaged routes can expand the real boundary.
Include or exclude equipment based on whether it can access specified information, not whether somebody considers it “just a machine.”
An enterprise-wide scope may be simpler when specified information already moves throughout the business. A bounded enclave can reduce the number of systems and people subject to the controls, but only when the supplier can reliably restrict information flow, access and connections. Creating an enclave on paper while employees continue emailing, downloading or printing elsewhere is not a defensible boundary.
Source review completed July 27, 2026. Contract documents and current Government of Canada instructions control where they differ from general guidance.
CyberTECT supports Canadian defence suppliers with CPCSC Level 1 readiness, evidence organization and practical implementation planning.