Cybersecurity Reference

Cybersecurity

Cybersecurity Reference Documents

This library of reference materials contain documents published by authoritative and informed sources that can assist your organization with practical, helpful guidance towards reducing cybersecurity risks and protecting personal information.

Return to Main Page

About this Library

For the purposes of this Library, sources are defined as:

  • Authoritative Source: a privacy or cyber-security organization dedicated to establishing standards and best practices.
  • Informed Source: a news source, blog or information from a commercial vendor that provides informed privacy and data security advice.

Click here for important information

Browse by Topic

Cybersecurity and Privacy Breach Emergency Planning

Five Key Considerations for Developing a Cybersecurity Emergency Action Plan

Includes guidance for emergency checklists, notification matrices, emergency indicators, response expectations, and approved actions.

Authoritative Source: Information System Audit and Control Association (ISACA)

Open Resource

Privacy Breach Checklist

A printable template to help document and report a suspected or confirmed privacy breach.

Authoritative Source: Office of the Information and Privacy Commissioner BC (OIPC)

Open Resource

Privacy Breaches: Tools and Resources

A resource guide to help respond to a privacy breach in accordance with BC privacy legislation.

Authoritative Source: Office of the Information and Privacy Commissioner BC (OIPC)

Open Resource

Ransomware Risk Mitigation

Preparing Your Organization for Ransomware Attacks

Practical steps on protecting against ransomware threats and recovering from ransomware attacks.

Authoritative Source: NIST National Institute of Standards and Technology

Open Resource

Ransomware: Facts, Threats, and Countermeasures

Short, straightforward advice on securing networks and systems, securing the end user, and responding to a compromise or attack.

Authoritative Source: Center for Internet Security

Open Resource

COVID-19 Cybersecurity Guidance

Coronavirus: Scammers follow the headlines

Practical recommendations for staff, including avoiding unknown links, suspicious emails, fake offers, donation scams, and investment schemes.

Authoritative Source: US Federal Trade Commission

Open Resource

Cyber Hygiene for COVID-19

Guidance to protect against malicious emails, attachments, websites, and other fake COVID-related cyber activity.

Authoritative Source: Canadian Centre for Cyber Security

Open Resource

Cybersecurity and the COVID-19 pandemic

Recommendations from a lawyer specializing in cybersecurity on managing COVID-19 cybersecurity risks from a people, process, and technology perspective.

Informed Source: BLG (Borden Ladner Gervais LLP)

Open Resource

Cyber security is essential when preparing for COVID-19

Practical recommendations to create a secure remote environment and educate staff in cybersecurity practices.

Authoritative Source: Australian Cyber Security Centre

Open Resource

Risk Management for Novel Coronavirus (COVID-19)

A brief summary for executives with suggestions on physical, supply chain, and cybersecurity issues connected to COVID-19.

Authoritative Source: US Department of Homeland Security: Cybersecurity & Infrastructure Security Agency (CISA)

Open Resource

Working from Home and Outside the Office

CSI Best Practices to Securing your Home Network

Practical advice for securing home networks, including routing devices, wireless network segmentation, confidentiality, and more.

Authoritative Source: National Security Agency

Open Resource

Cyber-Safety for Mobile Workers

Guidance on secure wireless networks, phishing, protecting information, locking devices, storing documents securely, and reporting lost or stolen devices.

Authoritative Source: BC Office of the Information and Privacy Protection Commissioner (OIPC)

Open Resource

Home working: preparing your organisation and staff

Recommendations for staff working from home, including new accounts, access, chat rooms, video teleconferencing, document sharing, and SaaS applications.

Authoritative Source: National Cyber Security Centre

Open Resource

Securing a Remote Workforce

Guidance on password management, security patches and updates, phishing, and online social distancing.

Authoritative Source: Cyber Readiness Institute

Open Resource

Security Tips for Remote Workers

A shareable PDF with practical guidance for working outside of the office.

Authoritative Source: National Cyber Security Alliance

Open Resource

Telework Security Basics

Practical advice designed to be shared with teleworking home and remote office users.

Authoritative Source: National Institute of Standards and Technology (NIST)

Open Resource

Videoconferencing Products and Services

Considerations when using video-teleconference products and services

Mitigations and general guidance, including product-specific guidance for Google Hangouts, Slack, Microsoft Teams, Zoom, and GoTo Meeting.

Authoritative Source: Canadian Centre for Cyber Security

Open Resource

Best Practices for Securing Your Zoom Meetings

A Zoom publication with guidance on waiting rooms, admitting participants, removing participants, and other meeting security settings.

Informed Source: Zoom Communications

Open Resource

Secure Email for Small to Medium Sized Organizations

Secure + Encrypted Email Providers

Information on encrypted email providers and why email encryption matters.

Informed Source: Privacy Canada

Open Resource

Trustworthy Email

NIST Special Publication 800-177 Revision 1, a technical reference for small to medium organizations.

Authoritative Source: National Institute of Standards and Technology (NIST)

Open Resource

Cloud Services and Cybersecurity

Cloud services – Guidance for managing cybersecurity risks

Guidance on risk/benefit assessment, cloud services contracts, and oversight/monitoring.

Informed Source: BLG (Borden Ladner Gervais LLP)

Open Resource

Cybersecurity Risk Assessment Standards and Best Practices

Baseline Cyber Security Controls for Small and Medium Organizations

Canadian Government recommendations designed for small and medium sized organizations.

Authoritative Source: Canadian Centre for Cyber Security

Open Resource

Securing Personal Information: A Self-Assessment Tool for Organizations

A security self-assessment designed for organizations, with simple questions and minimum security requirements.

Authoritative Source: BC Office of the Information and Privacy Protection Commissioner (OIPC)

Open Resource

References Supporting Standards Cited in the CCCS Baseline Controls

Note: Some references cited below are identified as originating from informed sources, rather than authoritative ones. Discretion should be used when reviewing information from informed sources, including the potential for author bias.

Secure Wi-Fi, preferably WPA2-Enterprise

Authoritative Source

Open Resource

A Secure Approach to Deploying Wireless Networks

Authoritative Source

Open Resource

PCI DSS Quick Reference Guide

Authoritative Source

Open Resource

Configuring DMARC with Google Workspace

Informed Source

Open Resource

Configuring DMARC with Microsoft 365

Informed Source

Open Resource

Funding is generously provided through the Ronald S. Roadburg Foundation

Ronald S. Roadburg Foundation logo