The Canadian Centre for Cyber Security publishes baseline controls to help smaller organisations improve cybersecurity through practical, prioritised measures. Its guidance covers 13 control categories and should be scoped to the organisation's needs and threats. See the CCCS overview of baseline measures.
Use in a programme
Start with the systems and information that matter most to the business. Assign owners for the selected controls, record implementation evidence and revisit gaps as the organisation changes.
The guidance offers a practical starting point; it does not guarantee a fixed percentage of risk reduction or remove the need to assess unusual exposure. More demanding environments may need additional measures.
Use in CSFaaS
The reviewed library contains CCCS SME V1.2 - EN. Confirm the edition against the publisher's V1.2 document before adopting it.
Use framework applicability and policy-control links to organise implementation. Preserve the rationale for exclusions and keep the reference's baseline recommendations separate from additional workspace requirements.