Security & Compliance
Lynx Compliance - CyberSecure Canada (CAN/CIOSC 104)
The federal certification programme for small and medium organisations - the CAN/CIOSC 104 baseline controls plus the ISED certification process, cross-referenced to ISO 27001 Annex A.
lynx_compliance_cybersecure_ca
· v19.0.1.0.0
· Add-on
Beta
What this solves
Lynx Compliance - CyberSecure Canada (CAN/CIOSC 104)
This pack is different in kind from most of the suite. CAN/CIOSC 104 is a baseline, not a maturity model: it is the floor a small organisation can actually reach, and it is deliberately prescriptive where other frameworks are risk-based. "Automatically patch" means automatically, not "patch promptly", and an assessor reads it that way.
It also matters commercially. CyberSecure Canada is increasingly required in Government of Canada and prime-contractor supply chains, which makes it the certification a small supplier is most likely to be asked for first.
Two additions to the published baseline ship here.
The certification process itself is modelled as controls. This is a real certification with an accredited body, a validity period and a displayable mark, and the process obligations are where organisations most often stall: an honest self-assessment before engaging a body, an accredited body from the current list, recertification before expiry, and use of the mark only within its licensed scope. They are coded CSC-CERT.n to stay distinct from the standard's own numbering.
ISO 27001 Annex A references are populated throughout, because an organisation growing out of this baseline into a 27001 certification should carry its assessments forward rather than start again.
Key Features
53 controls across five functions - the CAN/CIOSC 104 baseline under its own clause numbering, plus four certification-process controls.
The certification lifecycle treated as assessable - self-assessment, accredited body, recertification and correct use of the mark, which the standard itself does not cover.
Badge publication on certification - the optional showcase bridge seeds a lynx.compliance.badge, so a current certificate publishes to the public compliance page instead of sitting in a folder.
ISO 27001 Annex A references throughout - so the growth path out of the baseline reuses the work rather than repeating it.
Guidance written for organisations without a security team - the evidence asked for is what a twenty-person company can actually produce, and the residual-risk examples are the states those organisations are usually in.
Prescriptive where the standard is prescriptive - automatic patching, tested restores and multi-factor coverage are assessed as the binary conditions the baseline makes them.
Integrates With
lynx_compliance_certification - the ISO 27001 Annex A controls this pack references, and the natural next certification.
lynx_compliance_showcase - via the optional bridge, publishes the certificate as a public badge.
lynx_compliance_training - awareness training completion is three of the fifty-three controls.
Try Lynx Compliance - CyberSecure Canada (CAN/CIOSC 104) on your team.
Free trial, no credit card. Talk to sales when you're ready.