CPCSC
6 min readWhat specified information means under CPCSC, and how to draw your assessment boundary
Specified information is any Government of Canada information a non-government organization must protect when it handles, processes or stores it. Under CPCSC, every device, person, facility and service provider that can reach it is in scope. Here is how to draw the boundary so the assessment is small and defensible.
Specified information is any Government of Canada information that must be protected when a non-government organization handles, processes or stores it. That is the definition in the CPCSC scoping guide, and it is the hinge the whole program turns on. Every laptop, phone, file share, server, printer, person, office and service provider that can access that information is inside your CPCSC boundary. Everything that cannot is outside. Scoping is the first decision in a CPCSC engagement and the one that most affects cost, so it deserves more care than it usually gets.
Where the information comes from
Specified information arrives through the contract. It is the drawings, specifications, schedules, correspondence and data the Department of National Defence or another department shares with you to do the work, plus anything you produce that contains it. The solicitation and the security requirements checklist tell you what you will receive. If you are a subcontractor, it flows down from the prime, and the prime's boundary decisions do not relieve you of drawing your own.
What is in scope
The scoping guide lists the asset classes you must include when they can access the information:
- Laptops and desktop computers
- Mobile devices such as phones and tablets
- File shares, cloud storage and collaboration platforms
- Servers, virtual machines and applications that host the information
- Printers and scanners that can store information
- The people who use those assets, and the facilities where the information is handled
- External service providers, such as a Microsoft 365 tenant or a managed service provider, that operate within your boundary
The rule that catches people out
The guide states it plainly: you cannot exclude a device because someone thinks it is not important. Inclusion is decided by access, not by opinion. The finance laptop that never opens a drawing is out of scope only if it genuinely cannot reach the share where the drawings live. If it can, it is in, along with every control that implies.
The same logic applies to service providers. Your cloud tenant and your outsourced IT firm are inside the boundary when they touch the information, and you remain responsible for verifying that they operate within the agreed security scope. A vendor's own certification helps, but it does not transfer the obligation.
Enterprise-wide or bounded enclave
The guide frames scoping as a business decision with two broad shapes. Enterprise-wide means your whole organization is the boundary. It is simple to describe and expensive to assess, because every device and every person carries the 13 Level 1 controls, and the 98 Level 2 controls if you go further. A bounded enclave means a defined team, on defined devices, using a defined set of systems, with the information kept inside that perimeter. It is more work to set up and much cheaper to maintain.
For most small and mid-sized suppliers the enclave wins. A dozen engineers on managed laptops, a dedicated file store, a separate identity group with its own multi-factor authentication policy, and a documented rule that specified information does not leave the enclave. The rest of the company stays out of scope and out of the assessment.
How to draw the boundary in practice
The sequence we use takes a week for a typical supplier.
- Trace the information. Start from the contract deliverables and follow every path the information takes: inbound email, project folders, engineering tools, backups, printers, home offices.
- Inventory every asset on those paths. Devices, accounts, servers, cloud services, physical rooms. If it can reach the information, it is on the list.
- Decide the shape. If the list is most of the company, go enterprise-wide. If it is one team, build the enclave and move the information inside it.
- Document it. A boundary diagram, the asset list, a list of people with access, and a responsibility matrix for each service provider. This is the evidence an assessor or contracting authority asks for first.
- Set the rules that keep it true. Where the information may be stored, which devices may open it, how it leaves the enclave if it must, and how new people and tools get added to the scope.
Why scoping is a readiness question, not a paperwork one
A well-drawn boundary makes Level 1 a short exercise and makes Level 2 affordable. A poorly drawn one either leaves a gap an assessor will find, or drags the whole company into an assessment it did not need. HuCortex readiness engagements start with scoping for exactly that reason, and we hand you the boundary package as a standalone deliverable you can reuse at every renewal.
Ready to take the next step?
HuCortex works with Canadian businesses on CPCSC readiness, PIPEDA compliance, and managed security. Start with a free assessment.
