Canadian Baseline Cyber Security Controls
50 mapped evidence workpapers: eight organizational items and 42 baseline controls across 13 categories
All available frameworksWhat the app checks
Technical checks run for the selected scope, available connectors and credentials. Results provide evidence for review; missing data is not a pass.
Explicit requirement-to-test mappings
| Requirement | Collector / test | What it checks or supports |
|---|---|---|
| OC.2 | WINDOWS / WIN-INVENTORY-COVERAGE-001 | Supporting observation only for authorised in-scope IT assets. Independently verify actual enforcement, operating procedures, scope and operating evidence. Registration does not prove MFA enforcement; firewall state does not prove segmentation. Patch age does not prove prescribed remediation deadlines, backup configuration does not prove restoration, and device encryption does not prove all backup copies are protected. |
| BC.2.1 | WINDOWS / WIN-PATCH-FRESHNESS-001 | Supporting observation only for authorised in-scope IT assets. Independently verify actual enforcement, operating procedures, scope and operating evidence. Registration does not prove MFA enforcement; firewall state does not prove segmentation. Patch age does not prove prescribed remediation deadlines, backup configuration does not prove restoration, and device encryption does not prove all backup copies are protected. |
| BC.2.1 | VULN / VULN-IMPORT-001 | Supporting observation only for authorised in-scope IT assets. Independently verify actual enforcement, operating procedures, scope and operating evidence. Registration does not prove MFA enforcement; firewall state does not prove segmentation. Patch age does not prove prescribed remediation deadlines, backup configuration does not prove restoration, and device encryption does not prove all backup copies are protected. |
| BC.3.1 | WINDOWS / WIN-AV-001 | Supporting observation only for authorised in-scope IT assets. Independently verify actual enforcement, operating procedures, scope and operating evidence. Registration does not prove MFA enforcement; firewall state does not prove segmentation. Patch age does not prove prescribed remediation deadlines, backup configuration does not prove restoration, and device encryption does not prove all backup copies are protected. |
| BC.3.2 | WINDOWS / WIN-FW-001 | Supporting observation only for authorised in-scope IT assets. Independently verify actual enforcement, operating procedures, scope and operating evidence. Registration does not prove MFA enforcement; firewall state does not prove segmentation. Patch age does not prove prescribed remediation deadlines, backup configuration does not prove restoration, and device encryption does not prove all backup copies are protected. |
| BC.4.1 | WINDOWS / WIN-SMB1-001 | Supporting observation only for authorised in-scope IT assets. Independently verify actual enforcement, operating procedures, scope and operating evidence. Registration does not prove MFA enforcement; firewall state does not prove segmentation. Patch age does not prove prescribed remediation deadlines, backup configuration does not prove restoration, and device encryption does not prove all backup copies are protected. |
| BC.5.1 | ENTRA / ENTRA-MFA-REG-001 | Supporting observation only for authorised in-scope IT assets. Independently verify actual enforcement, operating procedures, scope and operating evidence. Registration does not prove MFA enforcement; firewall state does not prove segmentation. Patch age does not prove prescribed remediation deadlines, backup configuration does not prove restoration, and device encryption does not prove all backup copies are protected. |
| BC.7.1 | BACKUP / VEEAM-REPO-001 | Supporting observation only for authorised in-scope IT assets. Independently verify actual enforcement, operating procedures, scope and operating evidence. Registration does not prove MFA enforcement; firewall state does not prove segmentation. Patch age does not prove prescribed remediation deadlines, backup configuration does not prove restoration, and device encryption does not prove all backup copies are protected. |
| BC.7.2 | STORAGE / STOR-AT-REST-ENCRYPTION-001 | Supporting observation only for authorised in-scope IT assets. Independently verify actual enforcement, operating procedures, scope and operating evidence. Registration does not prove MFA enforcement; firewall state does not prove segmentation. Patch age does not prove prescribed remediation deadlines, backup configuration does not prove restoration, and device encryption does not prove all backup copies are protected. |
| BC.10.4 | CERTTLS / CERTTLS-POSTURE-001 | Supporting observation only for authorised in-scope IT assets. Independently verify actual enforcement, operating procedures, scope and operating evidence. Registration does not prove MFA enforcement; firewall state does not prove segmentation. Patch age does not prove prescribed remediation deadlines, backup configuration does not prove restoration, and device encryption does not prove all backup copies are protected. |
| BC.10.5 | ENTRA / ENTRA-MFA-REG-001 | Supporting observation only for authorised in-scope IT assets. Independently verify actual enforcement, operating procedures, scope and operating evidence. Registration does not prove MFA enforcement; firewall state does not prove segmentation. Patch age does not prove prescribed remediation deadlines, backup configuration does not prove restoration, and device encryption does not prove all backup copies are protected. |
| BC.12.1 | ADSEC / AD-PRIV-001 | Supporting observation only for authorised in-scope IT assets. Independently verify actual enforcement, operating procedures, scope and operating evidence. Registration does not prove MFA enforcement; firewall state does not prove segmentation. Patch age does not prove prescribed remediation deadlines, backup configuration does not prove restoration, and device encryption does not prove all backup copies are protected. |
| BC.12.3 | ADSEC / AD-LIFECYCLE-001 | Supporting observation only for authorised in-scope IT assets. Independently verify actual enforcement, operating procedures, scope and operating evidence. Registration does not prove MFA enforcement; firewall state does not prove segmentation. Patch age does not prove prescribed remediation deadlines, backup configuration does not prove restoration, and device encryption does not prove all backup copies are protected. |
What requires manual review
Confirm scope and applicability, review the requirement guidance, collect policies and records, conduct interviews or observations where needed, and assess evidence relevance and freshness. Record owners, rationale, workpaper conclusions and remediation. An assessor makes the final decision; a technical pass does not approve the whole framework.
IT Audit Factory original assessment workpapers mapped by identifier to Canadian Centre for Cyber Security Baseline Cyber Security Controls v1.2 (February 2020). Consult the official publication for authoritative wording. Not an official reproduction, CAN/CIOSC 104 assessment, CyberSecure Canada certification or government endorsement.
Where it is available
This preparation framework is listed in the C32 Professional/MSP application catalog. Free retains its ISO assessment limits. Availability of a framework is separate from the extent of automated scanning.
Coverage shown here comes from the application’s C32 requirement and mapping catalogs.