Se rendre au contenu

Sécurité et conformité

Lynx Compliance - CyberSecure Canada (CAN/CIOSC 104)

The federal certification programme for small and medium organisations - the CAN/CIOSC 104 baseline controls plus the ISED certification process, cross-referenced to ISO 27001 Annex A.

lynx_compliance_cybersecure_ca · v19.0.1.0.0 · Complément Bêta

Ce que cela résout

Lynx Compliance - CyberSecure Canada (CAN/CIOSC 104)

This pack is different in kind from most of the suite. CAN/CIOSC 104 is a baseline, not a maturity model: it is the floor a small organisation can actually reach, and it is deliberately prescriptive where other frameworks are risk-based. "Automatically patch" means automatically, not "patch promptly", and an assessor reads it that way.

It also matters commercially. CyberSecure Canada is increasingly required in Government of Canada and prime-contractor supply chains, which makes it the certification a small supplier is most likely to be asked for first.

Two additions to the published baseline ship here.

The certification process itself is modelled as controls. This is a real certification with an accredited body, a validity period and a displayable mark, and the process obligations are where organisations most often stall: an honest self-assessment before engaging a body, an accredited body from the current list, recertification before expiry, and use of the mark only within its licensed scope. They are coded CSC-CERT.n to stay distinct from the standard's own numbering.

ISO 27001 Annex A references are populated throughout, because an organisation growing out of this baseline into a 27001 certification should carry its assessments forward rather than start again.

Key Features

  • 53 controls across five functions - the CAN/CIOSC 104 baseline under its own clause numbering, plus four certification-process controls.

  • The certification lifecycle treated as assessable - self-assessment, accredited body, recertification and correct use of the mark, which the standard itself does not cover.

  • Badge publication on certification - the optional showcase bridge seeds a lynx.compliance.badge, so a current certificate publishes to the public compliance page instead of sitting in a folder.

  • ISO 27001 Annex A references throughout - so the growth path out of the baseline reuses the work rather than repeating it.

  • Guidance written for organisations without a security team - the evidence asked for is what a twenty-person company can actually produce, and the residual-risk examples are the states those organisations are usually in.

  • Prescriptive where the standard is prescriptive - automatic patching, tested restores and multi-factor coverage are assessed as the binary conditions the baseline makes them.

Integrates With

  • lynx_compliance_certification - the ISO 27001 Annex A controls this pack references, and the natural next certification.

  • lynx_compliance_showcase - via the optional bridge, publishes the certificate as a public badge.

  • lynx_compliance_training - awareness training completion is three of the fifty-three controls.

Essayer Lynx Compliance - CyberSecure Canada (CAN/CIOSC 104) de votre équipe.

Essai gratuit, sans carte de crédit. Parlez à l'équipe des ventes quand vous êtes prêt.