Cybersecurity
Cybersecurity Reference Documents
This library of reference materials contain documents published by authoritative and informed sources that can assist your organization with practical, helpful guidance towards reducing cybersecurity risks and protecting personal information.
Return to Main Page
About this Library
For the purposes of this Library, sources are defined as:
- Authoritative Source: a privacy or cyber-security organization dedicated to establishing standards and best practices.
- Informed Source: a news source, blog or information from a commercial vendor that provides informed privacy and data security advice.
Click here for important information
Cybersecurity and Privacy Breach Emergency Planning
Five Key Considerations for Developing a Cybersecurity Emergency Action Plan
Includes guidance for emergency checklists, notification matrices, emergency indicators, response expectations, and approved actions.
Authoritative Source: Information System Audit and Control Association (ISACA)
Open Resource
Privacy Breach Checklist
A printable template to help document and report a suspected or confirmed privacy breach.
Authoritative Source: Office of the Information and Privacy Commissioner BC (OIPC)
Open Resource
Privacy Breaches: Tools and Resources
A resource guide to help respond to a privacy breach in accordance with BC privacy legislation.
Authoritative Source: Office of the Information and Privacy Commissioner BC (OIPC)
Open Resource
Ransomware Risk Mitigation
Preparing Your Organization for Ransomware Attacks
Practical steps on protecting against ransomware threats and recovering from ransomware attacks.
Authoritative Source: NIST National Institute of Standards and Technology
Open Resource
Ransomware: Facts, Threats, and Countermeasures
Short, straightforward advice on securing networks and systems, securing the end user, and responding to a compromise or attack.
Authoritative Source: Center for Internet Security
Open Resource
COVID-19 Cybersecurity Guidance
Coronavirus: Scammers follow the headlines
Practical recommendations for staff, including avoiding unknown links, suspicious emails, fake offers, donation scams, and investment schemes.
Authoritative Source: US Federal Trade Commission
Open Resource
Cyber Hygiene for COVID-19
Guidance to protect against malicious emails, attachments, websites, and other fake COVID-related cyber activity.
Authoritative Source: Canadian Centre for Cyber Security
Open Resource
Cybersecurity and the COVID-19 pandemic
Recommendations from a lawyer specializing in cybersecurity on managing COVID-19 cybersecurity risks from a people, process, and technology perspective.
Informed Source: BLG (Borden Ladner Gervais LLP)
Open Resource
Cyber security is essential when preparing for COVID-19
Practical recommendations to create a secure remote environment and educate staff in cybersecurity practices.
Authoritative Source: Australian Cyber Security Centre
Open Resource
Risk Management for Novel Coronavirus (COVID-19)
A brief summary for executives with suggestions on physical, supply chain, and cybersecurity issues connected to COVID-19.
Authoritative Source: US Department of Homeland Security: Cybersecurity & Infrastructure Security Agency (CISA)
Open Resource
Working from Home and Outside the Office
CSI Best Practices to Securing your Home Network
Practical advice for securing home networks, including routing devices, wireless network segmentation, confidentiality, and more.
Authoritative Source: National Security Agency
Open Resource
Cyber-Safety for Mobile Workers
Guidance on secure wireless networks, phishing, protecting information, locking devices, storing documents securely, and reporting lost or stolen devices.
Authoritative Source: BC Office of the Information and Privacy Protection Commissioner (OIPC)
Open Resource
Home working: preparing your organisation and staff
Recommendations for staff working from home, including new accounts, access, chat rooms, video teleconferencing, document sharing, and SaaS applications.
Authoritative Source: National Cyber Security Centre
Open Resource
Securing a Remote Workforce
Guidance on password management, security patches and updates, phishing, and online social distancing.
Authoritative Source: Cyber Readiness Institute
Open Resource
Security Tips for Remote Workers
A shareable PDF with practical guidance for working outside of the office.
Authoritative Source: National Cyber Security Alliance
Open Resource
Telework Security Basics
Practical advice designed to be shared with teleworking home and remote office users.
Authoritative Source: National Institute of Standards and Technology (NIST)
Open Resource
Videoconferencing Products and Services
Considerations when using video-teleconference products and services
Mitigations and general guidance, including product-specific guidance for Google Hangouts, Slack, Microsoft Teams, Zoom, and GoTo Meeting.
Authoritative Source: Canadian Centre for Cyber Security
Open Resource
Best Practices for Securing Your Zoom Meetings
A Zoom publication with guidance on waiting rooms, admitting participants, removing participants, and other meeting security settings.
Informed Source: Zoom Communications
Open Resource
Secure Email for Small to Medium Sized Organizations
Secure + Encrypted Email Providers
Information on encrypted email providers and why email encryption matters.
Informed Source: Privacy Canada
Open Resource
Trustworthy Email
NIST Special Publication 800-177 Revision 1, a technical reference for small to medium organizations.
Authoritative Source: National Institute of Standards and Technology (NIST)
Open Resource
Cloud Services and Cybersecurity
Cloud services – Guidance for managing cybersecurity risks
Guidance on risk/benefit assessment, cloud services contracts, and oversight/monitoring.
Informed Source: BLG (Borden Ladner Gervais LLP)
Open Resource
Cybersecurity Risk Assessment Standards and Best Practices
Baseline Cyber Security Controls for Small and Medium Organizations
Canadian Government recommendations designed for small and medium sized organizations.
Authoritative Source: Canadian Centre for Cyber Security
Open Resource
Securing Personal Information: A Self-Assessment Tool for Organizations
A security self-assessment designed for organizations, with simple questions and minimum security requirements.
Authoritative Source: BC Office of the Information and Privacy Protection Commissioner (OIPC)
Open Resource
References Supporting Standards Cited in the CCCS Baseline Controls
Note: Some references cited below are identified as originating from informed sources, rather than authoritative ones. Discretion should be used when reviewing information from informed sources, including the potential for author bias.
Funding is generously provided through the Ronald S. Roadburg Foundation