Woman making a frame around the sun with her hands at sunrise
Woman making a frame around the sun with her hands at sunrise
Woman making a frame around the sun with her hands at sunrise

Top of the Class: New Cybersecurity Program to Certify Privacy-Minded Businesses

August 2019 Privacy Bulletin 2 minutes read

On August 14, 2019, the federal government launched a new cybersecurity certification program aimed at helping small and medium-sized businesses protect against cyber threats.

The release of CyberSecure Canada (“CyberSecure”) is just one of the measures implemented by the government following its announcement of the Digital Charter earlier this year. (See McMillan’s summary of the Digital Charter). The certification is intended to further the government’s goal of assisting Canadian businesses in developing trust with consumers and remaining globally competitive in the digital age.

CyberSecure is a voluntary certification program wherein businesses implement numerous basic cyber security controls designed to safeguard against the most common kinds of cyber threats.

These basic cyber security controls are intended to be relatively easy and inexpensive for businesses with less than 500 employees and medium risk exposure to implement. Examples of the basic cyber security controls include:

  • Developing an incident response plan to manage cyber security incidents;
  • Implementing a security information and event management system;
  • Enabling automatic updates for software and hardware where available;
  • Configuring and enabling up-to-date anti-virus and anti-malware software;
  • Implementing two-factor authentication;
  • Developing policies regarding passwords;
  • Providing employee awareness training to minimize human error;
  • Backing up and encrypting data;
  • Establishing appropriate perimeter defences, such as firewalls; and
  • Implementing the principle of “least privilege” by providing users with only the minimal functionality required to perform their duties and responsibilities.

The Standards Council of Canada will be responsible for accrediting certification bodies, who will evaluate business’ compliance with CyberSecure and grant the certification. Businesses who are found to be in compliance with CyberSecure will be able to display a certification mark or logo on their website or other promotional materials.

The CyberSecure program will be in a pilot phase until a national standard for compliance is established. Businesses can now sign up as “early adopters” to help with the testing and development of the certification process. Those interested in enrolling as early adopters can contact the CyberSecure team at 1-800-328-6189 or by email at ISED-ISDE@canada.ca.

Businesses who do not wish to sign up as early adopters can still get ahead of the curve by beginning to review and implement the basic security controls.

It is also important to note that, while the CyberSecure certification is voluntary, many organizations are required by applicable privacy legislation – including the Personal Information Protection and Electronic Documents Act (“PIPEDA”) – to implement appropriate security safeguards to protect personal information against loss, theft or unauthorized access, disclosure, copying, use or modification.  Organizations are therefore advised to continuously evaluate the maturity of their privacy and data security compliance program in the face of ever-evolving threats to cybersecurity and developments in Canadian and international privacy laws.

by Kristen Pennington

A Cautionary Note

The foregoing provides only an overview and does not constitute legal advice. Readers are cautioned against making any decisions based on this material alone. Rather, specific legal advice should be obtained.

© McMillan LLP 2019

Related Publications (5 Posts)

Featured Insight

McMillan’s Employment Law Breakfast Series

McMillan’s Vancouver Labour and Employment Group is proud to launch it’s first ever Breakfast Series covering key employment and human rights issues!

Details
May 25, 2021 - 10:00 am - 11:15 am PDT
Featured Insight

Advertising in the Virtual World

Join members of the Marketing and Advertising Group on Thursday, June 17, 2021 at 12 pm ET as we discuss current trends in marketing and advertising in an increasingly virtual world, and during the ongoing global pandemic.

Details
June 17, 2021 - 12:00 pm to 1:30 pm ET
Featured Insight

Ontario’s New Excess Soil Regulations – Construction Contract Implications

Ontario’s new On-Site and Excess Soil Management Regulation, O. Reg 406/19 may impact existing and future construction contracts

Read More
May 5, 2021
Featured Insight

End of the Bellatrix GasEDI Saga Marks Beginning of Market Fallout

The Alberta Court of Appeal's dismissal of Bellatrix's appeal leaves substantial uncertainty for natural gas market and all derivatives counterparties.

Read More
May 5, 2021
Featured Insight

Federal Procurement Update #1: Filing a Complaint at the Canadian International Trade Tribunal: A Sprint Rather than a Marathon

A review of when and how to file a federal procurement complaint to the Canadian International Trade Tribunal (CITT)

Read More
May 5, 2021