Skip to content
FioSec Consulting

Frameworks · Canadian & regulatory

Canadian Centre for Cyber Security Baseline Controls

Canada’s own no-nonsense starting point for small and medium organizations.

Maintained by
Canadian Centre for Cyber Security (the Cyber Centre, part of CSE)
Origin
Canada · Baseline Cyber Security Controls for Small and Medium Organizations
Certifiable?
No. It is voluntary, pragmatic guidance from Canada’s national cyber authority.

What it is

The Baseline Cyber Security Controls are a practical, prioritized set of measures published by the Canadian Centre for Cyber Security (the Cyber Centre), Canada’s national authority on cyber security and part of the Communications Security Establishment. They are written specifically for small and medium organizations that do not have a dedicated security team.

Their whole design philosophy is "maximum protection for minimum effort." Instead of asking a small organization to adopt a sprawling framework, the Cyber Centre distilled the highest-value actions, drawing on the same evidence behind its widely cited Top 10 IT Security Actions, into a baseline that a non-specialist can understand and act on.

They are voluntary guidance, not a regulation or certification. The value is in their authority and clarity: free, Canadian-context advice from the national cyber agency, framed in plain language.

How it's structured

The baseline is organized into a set of recommended controls covering the essentials: governing your security, protecting accounts and information, securing devices and connections, and being ready to recover. It pairs naturally with the Cyber Centre’s Top 10 IT Security Actions: measures such as patching, enforcing strong authentication, hardening configurations, segmenting networks, training employees, and backing up data.

Because it is aimed at smaller organizations, the baseline favours concrete, achievable actions over exhaustive coverage. The areas below capture the essentials it emphasizes. Consult the Cyber Centre’s current publication for the full detail.

Govern your security

Develop an incident response plan, assign responsibility, and consider cyber insurance: basic organizational readiness.

Protect accounts

Enforce strong, multi-factor authentication and manage administrative privileges carefully.

Secure devices & software

Patch and update promptly, harden configurations, and use modern malware protection on devices.

Secure connections

Protect the network and perimeter, secure remote access, and use secure cloud and mobile practices.

Protect information

Back up data securely and test recovery; protect information at rest and in transit.

Train your people

Educate employees so they can recognize and resist the most common attacks.

Who it's for

The baseline is built for Canadian small and medium organizations: the businesses, charities, and not-for-profits that know they need to improve their security but lack the time, budget, or in-house expertise for a full framework.

It is an ideal first step: a credible, free, government-backed checklist that delivers most of the practical risk reduction with a fraction of the overhead. Many organizations use it to get protected quickly, then graduate to NIST CSF or the CIS Controls as they mature.

It is intentionally not comprehensive enough for organizations with complex environments, high-value targets, or formal compliance obligations. Those should treat it as a floor, not a ceiling, and adopt a fuller framework.

How it compares

The baseline is essentially a Canadian, small-business-friendly distillation of the same priorities found in the CIS Controls’ IG1 and NIST CSF: strong authentication, patching, backups, awareness, and a response plan. Adopting it puts you well along the path toward those broader frameworks.

Because it comes from the Cyber Centre, it also aligns with how Canadian regulators and insurers think about baseline diligence, which makes it a useful reference point alongside obligations like PIPEDA, PHIPA, or CIRO’s expectations.

How it maps to a Layered Defence

CCCS Baseline is technology-neutral; FioSec's seven layers are where its outcomes become real controls. Here is roughly where each one lands.

Free readiness checklist

How ready are you for CCCS Baseline?

Answer honestly across the 5 areas below for an instant read on where you stand. "Not sure" is a valid answer. Nothing is sent anywhere; your answers are scored right here in your browser.

Govern & prepare

The organizational basics.

Do you have an incident response plan and someone responsible for security?

Protect accounts

The single highest-value control.

Is multi-factor authentication (MFA) enforced on email, remote access, and admin accounts?
Are administrator privileges limited to those who genuinely need them?

Secure devices & connections

Closing the common entry points.

Are devices and software patched promptly and protected against malware?
Is remote access secured and your network protected at the perimeter?

Protect information

So you can recover.

Do you back up important data securely and test that you can restore it?

Train people

Your human firewall.

Do employees get practical training to recognize phishing and other common attacks?

No email required; scored in your browser, never sent anywhere.

Authoritative source: Canadian Centre for Cyber Security: Baseline Controls (cyber.gc.ca)

Explore other frameworks

Need help putting CCCS Baseline into practice?

FioSec helps Ontario organizations turn frameworks into working controls, vendor-agnostic, from assessment and design through implementation and ongoing support.