Canadian Defence & Cybersecurity Compliance
25 chapters
1. 1 The Defence Industrial Strategy (DIS)
[Verse 1]
Canada stands with purpose clear and bright
Defense industrial strategy takes flight
Security sovereignty prosperity's call
Three pillars standing strong and tall
Build Partner Buy the framework we embrace
Finding our nation's rightful place
[Chorus]
Ten sovereign capabilities we must defend
Digital systems where our futures blend
Secure cloud AI quantum in our hands
High assurance comms across our lands
Build it Partner up or Buy the best
DIS will put us to the test
[Verse 2]
Build means domestic capacity we grow
Innovation ecosystems help us know
Research and development on our soil
Canadian talent worth the toil
Partner with allies sharing common ground
Together strength in unity is found
[Chorus]
Ten sovereign capabilities we must defend
Digital systems where our futures blend
Secure cloud AI quantum in our hands
High assurance comms across our lands
Build it Partner up or Buy the best
DIS will put us to the test
[Verse 3]
Buy from markets when it makes the most sense
Cost and timeline guide our preference
Compliance consulting fits the frame
Helping industry play the game
Frameworks mapping to each sovereign need
Standards help our forces succeed
[Bridge]
Space and satellites above
Cyber security we love
Advanced manufacturing
Chemical biological screening
Nuclear systems maritime might
Air systems keeping us in flight
[Chorus]
Ten sovereign capabilities we must defend
Digital systems where our futures blend
Secure cloud AI quantum in our hands
High assurance comms across our lands
Build it Partner up or Buy the best
DIS will put us to the test
[Outro]
From Arctic waters to the southern shore
Defense industrial strategy and more
Security sovereignty prosperity's song
Together we are Canada strong
2. 2 Defence Investment Agency (DIA)
[Verse 1]
Gone are the days of PSPC's old way
Scattered procurement causing delay
Now there's a single voice to lead the charge
Defence Investment Agency running large
Streamlined structure, consolidated might
Bringing defence procurement into the light
[Chorus]
D-I-A, one mandate clear
Defence investment drawing near
Structure strong, replacing old
Canadian industry taking hold
Track the Forum, watch reforms unfold
ITB Policy, stories to be told
[Verse 2]
Defence Advisory Forum takes the stage
Announcements coming, turn the page
Industry voices heard at last
Learning from the troubled past
Keep your eyes on every word they say
Shaping tomorrow's defence today
[Chorus]
D-I-A, one mandate clear
Defence investment drawing near
Structure strong, replacing old
Canadian industry taking hold
Track the Forum, watch reforms unfold
ITB Policy, stories to be told
[Bridge]
Industrial and Technological Benefits rise
Foreign primes can't compromise
Reinvest in Canadian ground
Subcontractor compliance all around
Reforms coming, rules will change
ITB Policy expanding range
[Verse 3]
When foreign companies win the bid
Canadian investment can't be hid
ITB ensures the money flows
Back to where our industry grows
Compliance demand will multiply
As Canadian suppliers reach the sky
[Chorus]
D-I-A, one mandate clear
Defence investment drawing near
Structure strong, replacing old
Canadian industry taking hold
Track the Forum, watch reforms unfold
ITB Policy, stories to be told
[Outro]
From fragmented past to unified might
DIA leads us toward the light
Canadian defence industry's new day
The consolidated procurement way
3. 3 Funding Mechanisms
[Verse 1]
When defence SMBs need capital to grow
Four billion from BDC is where they'll go
Venture capital and advisory too
Defence Platform's waiting there for you
Check eligibility, make your case
Funding mechanisms in the right place
[Chorus]
Three fifty-seven Regional Defence
Two forty-four IRAP makes sense
Six fifty-six Strategic Response
BOREALIS keeps research strong
BDC Platform four billion strong
Funding defence where we belong
[Verse 2]
Regional Development Agencies know
Where local defence investments should flow
Western Economic Diversification
PacifiCan builds our nation
Three fifty-seven million to invest
Regional Defence Initiative's the best
[Chorus]
Three fifty-seven Regional Defence
Two forty-four IRAP makes sense
Six fifty-six Strategic Response
BOREALIS keeps research strong
BDC Platform four billion strong
Funding defence where we belong
[Verse 3]
NRC-IRAP's got two forty-four
For R and D that opens every door
Defence and dual-use technology
Small and medium companies can see
Innovation funding stream so bright
IRAP assists and gets it right
[Bridge]
Strategic Response Fund leads the way
Innovative Solutions Canada today
Six fifty-six point nine to spend
Commercialization till the end
BOREALIS coordinates research flow
Sixty-eight million helps it grow
Defence Innovation Secure Hubs unite
Keeping our technology burning bright
[Chorus]
Three fifty-seven Regional Defence
Two forty-four IRAP makes sense
Six fifty-six Strategic Response
BOREALIS keeps research strong
BDC Platform four billion strong
Funding defence where we belong
[Outro]
Five funding streams to know by heart
Defence readiness where we start
Billions invested in our defence
Strategic funding that makes sense
4. 4 Key Reading
[Verse 1]
North Strong and Free the policy declares
Eighty-one point eight billion shows Canada cares
Five years of investment in our defense line
Reading through the numbers shows the grand design
Budget twenty-twenty-five maps out the way
Industrial strategy for a stronger day
[Chorus]
Four key readings keep us sharp and ready
Policy Budget NATO plans held steady
CANSEC clients future partnerships we see
Defense industrial strategy sets us free
Read the docs and know the flow
That's how readiness will grow
[Verse 2]
NATO's Production Action Plan unfolds
Allied expectations written clear and bold
Canada's DIS must align with friends
Interoperability that never ends
Defense procurement mapped to global needs
Strategic partnerships through collaborative deeds
[Chorus]
Four key readings keep us sharp and ready
Policy Budget NATO plans held steady
CANSEC clients future partnerships we see
Defense industrial strategy sets us free
Read the docs and know the flow
That's how readiness will grow
[Bridge]
CANSEC conference halls reveal tomorrow's clients
Exhibitor lists show technology's giants
Study every booth and every demonstration
Building future contracts across the nation
From small suppliers to the major primes
Reading between the lines for future times
[Verse 3]
Connect the dots from policy to floor
Budget allocations open every door
NATO standards guide our production path
CANSEC networking does the business math
Four documents that tell the complete story
Defense industrial readiness and glory
[Chorus]
Four key readings keep us sharp and ready
Policy Budget NATO plans held steady
CANSEC clients future partnerships we see
Defense industrial strategy sets us free
Read the docs and know the flow
That's how readiness will grow
[Outro]
When you master all four readings clear
Defense opportunities will appear
North Strong and Free with industry might
Reading comprehension makes the future bright
5. 1 Program Structure
[Verse 1]
March twenty twenty-five the standard comes alive
Canadian cyber security takes the lead
Three levels of protection for our nation's defense
Building readiness is what we truly need
From basic to advanced the framework's taking shape
Mirroring CMMC two point zero's way
Phase one introduction sets the foundation strong
Accreditation body opens up today
[Chorus]
Three levels rising up the certification ladder
Phase by phase the program's getting stronger
CCCS governs all that really matters
Defense industrial readiness grows longer
Level one two three remember the progression
March to full deployment is our mission
Canada's cyber shield needs your protection
Join the certification expedition
[Verse 2]
Phase two brings requirements to selected contracts first
Testing out the waters with a careful hand
Not every deal will need it but the chosen few must prove
They can meet the standards of our cyber plan
Contractors learning quickly what it takes to qualify
Security controls become the price of entry
Building up their systems for the bigger wave ahead
When certification becomes mandatory
[Chorus]
Three levels rising up the certification ladder
Phase by phase the program's getting stronger
CCCS governs all that really matters
Defense industrial readiness grows longer
Level one two three remember the progression
March to full deployment is our mission
Canada's cyber shield needs your protection
Join the certification expedition
[Bridge]
Twenty twenty-six and beyond the rules are clear
Every new procurement needs certification here
No more picking choose your battles carefully
Full mandatory coverage is the key
Canadian Centre leads the way forward
Cyber Security sets the standard
Three phases rolling out across the board
Defense industry must understand
[Verse 3]
From introduction through selective to complete
The timeline tells a story of strategic growth
Industry adaptation meets security needs
As Canada fulfills its cyber oath
Level by level building stronger defenses
Contract by contract raising up the bar
CCCS ensuring all our readiness
Takes us where we need to go so far
[Chorus]
Three levels rising up the certification ladder
Phase by phase the program's getting stronger
CCCS governs all that really matters
Defense industrial readiness grows longer
Level one two three remember the progression
March to full deployment is our mission
Canada's cyber shield needs your protection
Join the certification expedition
[Outro]
Structure guides us through the transformation
Program phases build our cyber nation
Ready for defense procurement's future
Canada's industrial cyber suture
6. 2 ITSP 10.171 (The Canadian Standard)
[Verse 1]
From CCCS comes the standard we need
ITSP ten-one-seven-one to heed
Canadian controls for security's sake
Mirror NIST eight hundred seventy-one we'll take
Download and study every line with care
Map each control to show what we can share
[Chorus]
Build the bridge between standards today
CMMC to CPCSC paves the way
Rev two to rev three we must compare
Find the delta hiding everywhere
Crosswalk document worth its weight in gold
CMMC CPCSC SOC2 story told
[Verse 2]
Start with NIST SP eight-oh-oh dash one-seven-one
Revision three is where our mapping's begun
Compare it close to the Canadian twin
ITSP controls let the analysis begin
Each requirement numbered line by line
Control families in perfect design
[Chorus]
Build the bridge between standards today
CMMC to CPCSC paves the way
Rev two to rev three we must compare
Find the delta hiding everywhere
Crosswalk document worth its weight in gold
CMMC CPCSC SOC2 story told
[Bridge]
What changed from rev two to revision three
New controls added for security
Identify gaps in the current CMMC base
CPCSC foundation takes its place
Document differences side by side
Make your crosswalk the perfect guide
[Verse 3]
SOC2 Trust Services in the mix
Type two reports with controls that stick
Map availability and confidential care
Processing integrity everywhere
Security principles align the three
Standards working in harmony
[Final Chorus]
Build the bridge between standards today
CMMC to CPCSC paves the way
Rev two to rev three delta's clear
Sellable asset drawing near
Crosswalk document worth its weight in gold
CMMC CPCSC SOC2 story told
[Outro]
Defence industrial readiness calls
One crosswalk document conquers all
Canadian controls meet US compliance needs
Your mapping work plants profitable seeds
7. 3 Assessment & Certification Process
[Verse 1]
When you're ready to prove your defense compliance worth
Three levels of assessment will test what you know
Level One starts with you doing the work
Self-assessment questionnaire, check every row
Document your controls and policies tight
Show evidence that your systems are right
It's the foundation step before you can grow
But higher levels need more than you can show
[Chorus]
One Two Three, that's the way to be certified
Self assess, third party, government verified
C Three P A O, that's who you need to know
Certified Third Party Assessment Organizations
One Two Three, climbing up the ladder high
Each level proves you're qualified to fly
[Verse 2]
Level Two brings in outside eyes to see
Third party assessors with credentials and skill
In Canada they're called T P A Os free
To validate controls and check your will
They audit your systems with independent view
Interview your staff and test what you do
More rigorous than self assessment still
But Level Three takes it up another hill
[Chorus]
One Two Three, that's the way to be certified
Self assess, third party, government verified
T P A O, that's who you need to know
Third Party Assessment Organizations
One Two Three, climbing up the ladder high
Each level proves you're qualified to fly
[Bridge]
Government led assessment at the top
Level Three means federal teams arrive
They scrutinize everything, they never stop
Most critical systems need this to survive
Want to be an assessor in this game?
Training and certification stake your claim
Learn the standards, pass the tests with pride
Join the ranks of those who can provide
[Verse 3]
Accreditation pipeline has its flow
Authorized bodies grant the power to assess
Years of training help assessors grow
Knowledge of standards they must possess
From trainee to lead assessor you climb
Each step requires investment of time
But once you're qualified you can attest
That organizations meet the compliance test
[Chorus]
One Two Three, that's the way to be certified
Self assess, third party, government verified
Know the path from trainee to the lead
Assessment skills are what the defense industry needs
One Two Three, climbing up the ladder high
Each level proves you're qualified to fly
[Outro]
Assessment and certification, that's the way
Three levels keep our nation's secrets safe today
8. 4 Dual-Compliance Architecture
[Verse 1]
Two frameworks stand before you now
CMMC and CPCSC somehow
Different paths but same destination
Dual compliance for the nation
Study gaps between the two
Find what's shared and what is new
Reciprocity's the key to see
Where they match and disagree
[Chorus]
Build the bridge with dual compliance
Map the gaps with full reliance
Shared controls in the middle ground
Framework-specific all around
Minimum viable is the way
Satisfy both frameworks today
Less duplication, more precision
That's our dual compliance mission
[Verse 2]
Start by mapping every control
See which ones can play both roles
Common ground is where you save
Effort time and money made
Access control works for both
Information handling oath
But some requirements stand alone
Each framework claims its own
[Chorus]
Build the bridge with dual compliance
Map the gaps with full reliance
Shared controls in the middle ground
Framework-specific all around
Minimum viable is the way
Satisfy both frameworks today
Less duplication, more precision
That's our dual compliance mission
[Bridge]
Methodology in four steps clear
First assess what you have here
Second map the overlapping parts
Third identify where difference starts
Fourth create your master plan
Minimum viable compliance span
[Verse 3]
Companies need both certifications
Serving multiple organizations
Defense contracts demand CMMC
Critical infrastructure CPCSC
Don't build twice what serves both needs
Smart compliance always succeeds
Architecture with dual design
Makes both frameworks align
[Chorus]
Build the bridge with dual compliance
Map the gaps with full reliance
Shared controls in the middle ground
Framework-specific all around
Minimum viable is the way
Satisfy both frameworks today
Less duplication, more precision
That's our dual compliance mission
[Outro]
Two frameworks one solution
Dual compliance evolution
Shared controls minimize the cost
Framework-specific nothing lost
9. 5 Key Reading
[Verse 1]
Five documents hold the key to cyber readiness today
CCCS program guides us through each certification phase
From basic to enhanced, the levels build security strong
Canada's defense industrial base must sing this compliance song
[Chorus]
Read the five, know them well, NIST and CCCS combined
Eight-oh-one-seven-one revision three, procedures well-defined
Eight-oh-two protects the crown jewels, Level Three enhanced
Crowell Moring shows the path while Gowling gets youanced
Five key readings, cyber shield, compliance is the way
[Verse 2]
Start with CCCS documentation, all phases in your hand
Basic moderate and high levels across this northern land
Each phase builds upon the last, requirements getting tight
From self-assessment tools to audits, everything's in sight
[Chorus]
Read the five, know them well, NIST and CCCS combined
Eight-oh-one-seven-one revision three, procedures well-defined
Eight-oh-two protects the crown jewels, Level Three enhanced
Crowell Moring shows the path while Gowling gets youanced
Five key readings, cyber shield, compliance is the way
[Verse 3]
NIST eight-seventeen-one gives us controlled unclassified
One hundred ten requirements that cannot be denied
Assessment procedures guide the way to proper validation
Revision three brings clarity to cyber obligation
[Bridge]
When sensitive data flows through your defense supply chain
Enhanced security controls help reduce the cyber pain
Level Three demands much more, eight-seventeen-two's the guide
Additional safeguards that you cannot set aside
[Verse 4]
Crowell Moring breaks it down, Canadian CMMC in sight
Analysis of what's to come, compliance burning bright
Gowling WLG confirms the trend, certification's near
The legal landscape's shifting fast, the message crystal clear
[Chorus]
Read the five, know them well, NIST and CCCS combined
Eight-oh-one-seven-one revision three, procedures well-defined
Eight-oh-two protects the crown jewels, Level Three enhanced
Crowell Moring shows the path while Gowling gets youanced
Five key readings, cyber shield, compliance is the way
[Outro]
Master these five documents well, your readiness will grow
Defense industrial strategy needs this knowledge flow
From coast to coast to coast we stand, cyber strong and true
Five key readings guide us home, compliance sees us through
10. 1 CMMC Current State
[Verse 1]
November twenty twenty-five the final rule arrives
DFARS implementation comes alive
Defense contractors must prepare their cyber stance
No more delays, no second chance
The current state assessment shows where we stand
Before the stricter rules command
[Chorus]
Phase One live, self-assess and score
SPRS posting, can't ignore
Phase Two coming, third-party eyes
Officials liable, no disguise
CMMC current state, know where you are
Before compliance raises the bar
[Verse 2]
Self-assessment questionnaire in your hands
Document your security where it stands
Supply Performance Risk System needs your score
Post it high for all to see and more
This phase one foundation sets the stage
For stricter oversight coming of age
[Chorus]
Phase One live, self-assess and score
SPRS posting, can't ignore
Phase Two coming, third-party eyes
Officials liable, no disguise
CMMC current state, know where you are
Before compliance raises the bar
[Bridge]
Affirming officials bear the weight
Legal liability you can't escape
Third-party assessors will verify
Every control you can't deny
Timeline ticking toward phase two
Current state mapping guides you through
[Verse 3]
From self-reporting to external review
The journey's mapped for me and you
Know your baseline, know your gaps
Before the stricter timeline snaps
Defense industrial base must rise
To meet these cybersecurity ties
[Final Chorus]
Phase One live, self-assess and score
SPRS posting, can't ignore
Phase Two coming, third-party eyes
Officials liable, no disguise
CMMC current state, your starting line
For defense cyber by design
[Outro]
Current state assessment shows the way
To CMMC compliance day by day
11. 2 Canadian-Specific CMMC Issues
[Verse 1]
When Canada meets the U.S. defense supply chain
DFARS clauses flow down like drops of rain
From prime contractors to subs across the border
Every requirement needs to be in order
Two-fifty-four dash seven-oh-four appears
In contracts that cross our frontiers
Cybersecurity standards can't be ignored
When you're supporting the Pentagon's sword
[Chorus]
DFARS flows down, SPRS scores up
Canadian subs need to fill their cup
Cross-border data needs careful scoping
ITAR and EAR keep lawyers hoping
Cloud solutions north of forty-nine
Must match GCC-High's security line
Two nations, one mission, compliance aligned
Defence industrial readiness refined
[Verse 2]
SPRS registration for the northern crew
Non-U.S. entities need their breakthrough
Upload your POA&M to the federal site
Self-assess your score and get it right
One-ten is the magic number to achieve
Without it, contracts you won't receive
Basic, Moderate, High - pick your NIST lane
Document controls to prove you're not in vain
[Chorus]
DFARS flows down, SPRS scores up
Canadian subs need to fill their cup
Cross-border data needs careful scoping
ITAR and EAR keep lawyers hoping
Cloud solutions north of forty-nine
Must match GCC-High's security line
Two nations, one mission, compliance aligned
Defence industrial readiness refined
[Bridge]
CUI crossing borders brings complexity
ITAR technical data, no simplicity
Export Administration Regulations too
Know your categories, know what you can do
Microsoft GCC-High south of the line
Canadian equivalents must be just as fine
Sovereign cloud with equivalent control
Cross-border compliance is the ultimate goal
[Verse 3]
When technical data flows from south to north
License requirements must be set forth
Dual-use technology under EAR's domain
Canadian cloud providers feel the strain
Azure Government in the States stands tall
Canadian equivalents must answer the call
Protected B and Secret classifications
Require specialized cloud implementations
[Chorus]
DFARS flows down, SPRS scores up
Canadian subs need to fill their cup
Cross-border data needs careful scoping
ITAR and EAR keep lawyers hoping
Cloud solutions north of forty-nine
Must match GCC-High's security line
Two nations, one mission, compliance aligned
Defence industrial readiness refined
[Outro]
From Ottawa to Washington the standards flow
CMMC readiness helps our partnership grow
Canadian industry rising to the call
Defence industrial base standing strong and tall
12. 3 Building the Dual-Market Offering
[Verse 1]
Canadian defence SMBs need a winning strategy
Two markets calling but they're built differently
Government contracts want CPCSC compliance tight
While US defence demands CMMC to get it right
[Chorus]
Build the dual market offering strong
CPCSC and CMMC belong
Together in your service line
Price them smart and you'll be fine
Dual assessments, dual success
Framework expertise, nothing less
[Verse 2]
Position paper makes the case crystal clear
Why single framework limits growth year after year
Bundle pricing brings the value clients seek
Discount the combo, make your margins peak
[Chorus]
Build the dual market offering strong
CPCSC and CMMC belong
Together in your service line
Price them smart and you'll be fine
Dual assessments, dual success
Framework expertise, nothing less
[Bridge]
ServiceNow and Archer platforms handle both
Rsam and MetricStream support your growth
While Carbide focuses on CMMC alone
And RSM spreads wide, we own SMB zone
[Verse 3]
Study Deloitte's enterprise approach
Our differentiator is hands-on coach
Speed and architecture for smaller firms
SMB focus is where our advantage turns
[Chorus]
Build the dual market offering strong
CPCSC and CMMC belong
Together in your service line
Price them smart and you'll be fine
Dual assessments, dual success
Framework expertise, nothing less
[Outro]
Know your competitors, know your space
SMB defence needs your expert face
Dual market mastery sets you apart
Build the offering, win every heart
13. 2 Zero Trust Architecture for Defence
[Verse 1]
Gone are the days of castle walls and moats
Trust but verify was just empty quotes
NIST eight-oh-seven shows the modern way
Never trust, always verify, every single day
Perimeters dissolved, the network's everywhere
Mobile workers, cloud servers, threats beyond compare
[Chorus]
Zero Trust Architecture, verify each call
Never trust, always verify, applies to one and all
Least privilege access, monitor every flow
Continuous authentication, that's how defenders grow
N-I-S-T framework, D-N-D leads the charge
Zero trust mindset, protection running large
[Verse 2]
Department of National Defence takes the lead
Canadian Armed Forces plants the zero trust seed
Identity-centric model, users are the key
Multi-factor always on, encrypted end-to-end you see
Micro-segmentation breaks the network down
Lateral movement stopped, threats can't get around
[Chorus]
Zero Trust Architecture, verify each call
Never trust, always verify, applies to one and all
Least privilege access, monitor every flow
Continuous authentication, that's how defenders grow
N-I-S-T framework, D-N-D leads the charge
Zero trust mindset, protection running large
[Verse 3]
DISA reference architecture shows the U-S way
Interoperability matters when allies need to play
Seven tenets guide us through the transformation
Data protection, network inspection across the nation
Policy engine central, decision point in place
Adaptive response ready at cybersecurity's pace
[Bridge]
Small to medium business, budgets running tight
Cloud-based solutions bring zero trust to light
Software-defined perimeter, identity as service
Step by step migration, staying cool and nervous
Risk-based assessment, prioritize your crown jewels
Phased implementation using open source tools
[Chorus]
Zero Trust Architecture, verify each call
Never trust, always verify, applies to one and all
Least privilege access, monitor every flow
Continuous authentication, that's how defenders grow
N-I-S-T framework, D-N-D leads the charge
Zero trust mindset, protection running large
[Outro]
From enterprise networks to the smallest firm
Zero trust principles help security confirm
Never trust the location, always verify the user
Continuous monitoring makes cyber threats the loser
Defence industrial base, ready for the fight
Zero trust architecture, cyber security's light
14. 4 Key Reading
[Verse 1]
In the world of cyber defense we stand
Four frameworks guide us through the land
ITSG thirty-three leads the way
Risk management every single day
Categories baseline controls in line
Assess implement monitor refine
[Chorus]
Four key readings for defense today
ITSG CCCS Treasury NIST the way
Risk and cloud and management flow
Framework twenty builds what we need to know
Four foundations strong and true
Cyber readiness starts with you
[Verse 2]
Cloud security guidance from CCCS
Government workloads need the best
Shared responsibility model clear
Provider tenant roles we hold dear
Data residency encryption tight
Access controls done just right
[Chorus]
Four key readings for defense today
ITSG CCCS Treasury NIST the way
Risk and cloud and management flow
Framework twenty builds what we need to know
Four foundations strong and true
Cyber readiness starts with you
[Verse 3]
Treasury Board Directive shows the path
Security management aftermath
Governance policies must align
Deputy heads the bottom line
Risk assessment continuous care
Security culture everywhere
[Chorus]
Four key readings for defense today
ITSG CCCS Treasury NIST the way
Risk and cloud and management flow
Framework twenty builds what we need to know
Four foundations strong and true
Cyber readiness starts with you
[Bridge]
NIST twenty brings it all together
Identify protect detect recover
Respond and govern six functions strong
Cybersecurity where we belong
From risk to cloud to management wide
These frameworks are our trusted guide
[Final Chorus]
Four key readings for defense today
ITSG CCCS Treasury NIST the way
Risk and cloud and management flow
Framework twenty builds what we need to know
Four foundations strong and true
Cyber readiness starts with you
Defense industrial strategy through
[Outro]
Read them learn them know them well
Four frameworks with stories to tell
15. 1 Kubernetes Ecosystem
[Verse 1]
In the world of containers where clusters take flight
We need the right tools to deploy and fight
EKS and AKS from the cloud providers call
But RKE2 and K3s stand ready to install
For defense infrastructure in air-gapped space
RKE2 leads the charge with security's embrace
[Chorus]
Kubernetes ecosystem, tools in formation
Terraform and OpenTofu for infrastructure creation
ArgoCD syncing code from Git repositories
Istio mesh connecting all our services
Vault keeps secrets locked away so tight
Prometheus watching through the day and night
K8s ecosystem, defense ready and strong
All the pieces working where they belong
[Verse 2]
Infrastructure as Code makes deployments clean
Terraform's the standard but OpenTofu's seen
Better licensing freedom for open source teams
GitOps brings the power to automated dreams
ArgoCD pulls the changes from your repository
Flux is there too but defense loves the story
[Chorus]
Kubernetes ecosystem, tools in formation
Terraform and OpenTofu for infrastructure creation
ArgoCD syncing code from Git repositories
Istio mesh connecting all our services
Vault keeps secrets locked away so tight
Prometheus watching through the day and night
K8s ecosystem, defense ready and strong
All the pieces working where they belong
[Verse 3]
Service mesh connects the pods across the wire
Istio and Linkerd set networking on fire
Multi-cluster federation needs Istio's might
External Secrets Operator brings Vault's insight
Enterprise key management keeps data secure
HashiCorp's solution that we know is pure
[Bridge]
Monitor with Grafana showing all the stats
Thanos aggregates when clusters multiply
OPA Gatekeeper enforces policy pacts
Kyverno's easier but Gatekeeper's our guy
Velero backs it up when systems crash and fall
Zarf packages it tight for DoD's call
[Verse 4]
Policy enforcement keeps the cluster clean
Gatekeeper's maturity sets the defense scene
Backup and restore with Velero's grace
Standard solution for the Kubernetes space
Air-gap deployments need a special touch
Zarf and Hauler deliver without clutch
[Chorus]
Kubernetes ecosystem, tools in formation
Terraform and OpenTofu for infrastructure creation
ArgoCD syncing code from Git repositories
Istio mesh connecting all our services
Vault keeps secrets locked away so tight
Prometheus watching through the day and night
K8s ecosystem, defense ready and strong
All the pieces working where they belong
[Outro]
From distribution to the final deploy
These are the tools that defense teams employ
Kubernetes ecosystem, learn them all today
For infrastructure delivery, this is the way
16. 2 Kafka Ecosystem
[Verse 1]
When data streams through defense networks fast
You need an ecosystem built to last
Kafka's the backbone but it needs support
Tools and operators of every sort
Strimzi's open source, runs on Kubernetes
Confluent for K8s when budgets are serious
Managing clusters with declarative ways
YAML configurations through all your days
[Chorus]
Operator, Schema, Replication too
Monitoring, Testing - five categories through
Strimzi, Registry, MirrorMaker's flow
JMX and Cruise Control help your data go
[Verse 2]
Schema Registry keeps your formats clean
Confluent's the standard in enterprise scene
But Apicurio when you want open source
Evolution and compatibility stay on course
Data structures versioned, compatibility checked
Forward and backward, your schemas protected
Avro, JSON, Protobuf in the mix
Registry ensures nothing ever breaks
[Chorus]
Operator, Schema, Replication too
Monitoring, Testing - five categories through
Strimzi, Registry, MirrorMaker's flow
JMX and Cruise Control help your data go
[Verse 3]
Cross-cluster replication keeps data in sync
MirrorMaker Two is the open source link
Cluster Linking's commercial but smoother to run
Exactly-once semantics when precision is done
Active-active, active-passive modes
Disaster recovery down different roads
Offset translation and consumer groups migrate
Real-time replication at enterprise rate
[Bridge]
Monitor with Kafka Exporter's metrics
JMX Exporter shows the analytics
Cruise Control rebalances partition load
Testing with perf-test tools on the road
Conduktor's GUI makes debugging clear
Built-in tools often are all that you need here
[Chorus]
Operator, Schema, Replication too
Monitoring, Testing - five categories through
Strimzi, Registry, MirrorMaker's flow
JMX and Cruise Control help your data go
[Outro]
Five pillars standing in Kafka's domain
Open source options or commercial gain
Defense infrastructure needs them all
Ecosystem ready when duty calls
17. 3 Compliance and Security
[Verse 1]
Security starts with scanning every line
OSCAP automates the STIG compliance sign
Check your systems with InSpec's reliable test
Compliance standards help you build the very best
[Chorus]
Scan and sign, scan and sign
STIG and SBOM keep systems in line
Trivy finds what hackers might
Cosign seals it watertight
Compliance first, security tight
[Verse 2]
Vulnerabilities hiding in your container stack
Trivy's widely adopted to keep threats off track
Grype and Anchore scan your images deep
Finding every weakness before they can creep
[Chorus]
Scan and sign, scan and sign
STIG and SBOM keep systems in line
Trivy finds what hackers might
Cosign seals it watertight
Compliance first, security tight
[Verse 3]
SIEM solutions watch your data flow
Splunk and Elastic help your security grow
Wazuh monitors while clients decide the tool
Real-time alerting keeps attackers fooled
[Bridge]
Build time SBOM with Syft generation
CycloneDX or SPDX documentation
Every component tracked and known
Software supply chain fully shown
[Verse 4]
Cosign signatures verify what's real
Keyless or key-based cryptographic seal
OpenSSL FIPS and BoringCrypto too
NIST validation proves the crypto's true
[Chorus]
Scan and sign, scan and sign
STIG and SBOM keep systems in line
Trivy finds what hackers might
Cosign seals it watertight
Compliance first, security tight
[Outro]
From scanning tools to crypto keys
Defense infrastructure guarantees
Security woven through each layer
Compliance makes the system stronger
18. Phase 1: Foundations (Weeks 1–3)
[Verse 1]
In the cluster there's a master, API server takes command
etcd stores the state we're after, distributed across the land
Controller manager watches objects, keeps the desired state in line
Scheduler finds the perfect socket, pods get placed by design
[Chorus]
Kube-Kafka-NIST we build it right
Pods and topics, security tight
One-seven-one controls to memorize
Defense infrastructure in the skies
[Verse 2]
Producers send to Kafka brokers, partitions split the load
Consumer groups are data smokers, pulling from the road
Log segments hold the messages, offsets mark the place
Replication keeps it flawless, no data we'll erase
[Chorus]
Kube-Kafka-NIST we build it right
Pods and topics, security tight
One-seven-one controls to memorize
Defense infrastructure in the skies
[Verse 3]
KRaft removes the Zookeeper, controller quorum leads
Metadata logs run deeper, consensus that succeeds
No more split-brain scenarios, partition tolerance wins
Kafka four-point-zero heroes, new architecture begins
[Bridge]
One hundred ten controls to master
Access control comes first and faster
Audit trails and crypto strong
Media protection all along
System integrity we defend
Personnel security to the end
[Verse 4]
From CUI to system hardening, each control has its place
Risk assessment, never pardoning, threats we always face
Configuration management, incident response prepared
Maintenance and system elements, security layers shared
[Chorus]
Kube-Kafka-NIST we build it right
Pods and topics, security tight
One-seven-one controls to memorize
Defense infrastructure in the skies
[Outro]
Foundations built on solid ground
Phase one knowledge, safe and sound
Kubernetes flows with Kafka streams
NIST guards our defense dreams
19. Phase 2: Hands-On (Weeks 4–6)
[Verse 1]
Two clusters standing side by side
EKS or RKE2, your choice to decide
Multi-cluster magic, now we begin
Defense infrastructure, let the learning spin
Kubectl contexts switching left and right
Both environments running through the night
[Chorus]
Kafka Strimzi KRaft mode strong
Mirror Maker Two replicates along
STIG and FIPS, security first
Performance benchmarks, quench your thirst
Hands-on learning, weeks four through six
Multi-cluster Kubernetes tricks
[Verse 2]
Strimzi operator takes the stage
KRaft consensus, turn the page
No ZooKeeper needed anymore
Kafka running smooth to the core
Custom resources define the way
Your message streaming starts today
[Chorus]
Kafka Strimzi KRaft mode strong
Mirror Maker Two replicates along
STIG and FIPS, security first
Performance benchmarks, quench your thirst
Hands-on learning, weeks four through six
Multi-cluster Kubernetes tricks
[Bridge]
Cross-cluster replication flows
Mirror Maker Two, that's how it goes
Topics syncing cluster A to B
Data streaming wild and free
Config connect and heartbeat too
Three connectors working for you
[Verse 3]
STIG compliance, check each rule
Document findings like a pro would do
Deviations noted, reasons clear
Security hardening we hold dear
FIPS mode enabled, crypto strong
TLS performance won't take long
[Chorus]
Kafka Strimzi KRaft mode strong
Mirror Maker Two replicates along
STIG and FIPS, security first
Performance benchmarks, quench your thirst
Hands-on learning, weeks four through six
Multi-cluster Kubernetes tricks
[Outro]
Benchmark results, the numbers tell
How encryption performs so well
Defense ready, infrastructure sound
Multi-cluster knowledge, safe and found
20. Phase 3: Integration (Weeks 7–9)
[Verse 1]
Week seven starts our integration phase
GitOps pipeline sets the stage
ArgoCD watches both our clusters now
Declarative state shows us how
Sync the configs, track the drift
Automated healing gives us lift
Both environments stay aligned
Defense infrastructure by design
[Chorus]
STIG scan, SSP, failover test
Monitor all, secure the rest
Integration makes us strong
GitOps keeps us moving on
STIG scan, SSP, failover test
Automated defense at its best
[Verse 2]
Security scanning in CI flow
STIG compliance helps us know
Every build gets checked for flaws
Following the security laws
Red Hat scans and CIS benchmarks
Finding issues before they spark
Pipeline gates won't let things through
Until our standards make it true
[Chorus]
STIG scan, SSP, failover test
Monitor all, secure the rest
Integration makes us strong
GitOps keeps us moving on
STIG scan, SSP, failover test
Automated defense at its best
[Bridge]
System Security Plan control statements
Document how we meet requirements
Every control gets implementation
Proof of our security foundation
Write the narrative, map the tech
Cross-reference every spec
[Verse 3]
Failover testing validates
When primary cluster terminates
Secondary takes the load
Document every episode
RTO and RPO metrics tracked
Disaster recovery stays intact
Traffic shifts without a pause
Resilience built into our cause
[Chorus]
STIG scan, SSP, failover test
Monitor all, secure the rest
Integration makes us strong
GitOps keeps us moving on
STIG scan, SSP, failover test
Automated defense at its best
[Verse 4]
Prometheus scrapes both cluster nodes
Grafana dashboards show the loads
Alertmanager sends the warning
When performance needs adorning
Cross-cluster visibility
Ensures our availability
Metrics flow from every pod
Monitoring like we're defense gods
[Outro]
Weeks seven through nine complete
Integration can't be beat
STIG and SSP align
Failover works every time
GitOps pipeline running clean
Best defense infrastructure seen
21. Phase 4: Program Execution (Weeks 10–12)
[Verse 1]
Week ten begins our execution phase
CDR presentation takes the stage
With lab environment as our guide
Reference implementation by our side
Practice makes perfect, rehearse with care
Show stakeholders we're prepared
[Chorus]
Plan and Test, Build and Run
Document all when phase is done
CDR, Test Plans, Runbooks too
CMMC mock assessment, lessons through
Execute, execute, see it through
Defense infrastructure, strong and true
[Verse 2]
Draft your test plans line by line
Procedures clear and well-defined
Every scenario mapped with thought
Edge cases caught, nothing forgot
Validation steps and expected results
Testing framework that never faults
[Chorus]
Plan and Test, Build and Run
Document all when phase is done
CDR, Test Plans, Runbooks too
CMMC mock assessment, lessons through
Execute, execute, see it through
Defense infrastructure, strong and true
[Verse 3]
Build runbooks for operations day
Step by step procedures pave the way
Incident response and maintenance calls
Troubleshooting guides when system falls
Operational scenarios clearly laid
For when the system is deployed and made
[Bridge]
CMMC Level Two controls in sight
Mock assessment proves we got it right
Access controls and incident response
Configuration management, proper defense
Audit trails and awareness training
System integrity we're maintaining
[Verse 4]
Lessons learned documentation grows
Capture what worked and what we know
Refine approach for future builds
Knowledge transfer, filling skills
Retrospective on what went well
And improvement stories we can tell
[Chorus]
Plan and Test, Build and Run
Document all when phase is done
CDR, Test Plans, Runbooks too
CMMC mock assessment, lessons through
Execute, execute, see it through
Defense infrastructure, strong and true
[Outro]
Phase four complete, execution done
From planning stage to final run
Defense delivery curriculum learned
Infrastructure knowledge truly earned
22. 2 ITSP 10.171 (La norme canadienne)
[Verse 1]
Il faut d'abord obtenir l'ITSP
Du Centre canadien pour la cybersécurité
Dix point cent soixante et onze c'est la norme
Qui guide notre sécurité sous toutes ses formes
Étudier chaque contrôle avec attention
Pour comprendre chaque réglementation
[Chorus]
ITSP à NIST on fait la correspondance
Révision trois c'est notre référence
CMMC vers PCCSC on trace le chemin
SOC2 complète notre dessin
Correspondance croisée, notre livrable précieux
Un document qui nous rend victorieux
[Verse 2]
Le NIST huit cents soixante et onze révision trois
Reflète l'ITSP qu'on étudie avec foi
Mais attention aux écarts importants
Entre révision deux et trois maintenant
Révision deux c'est la base du CMMC
Révision trois fonde le PCCSC
[Chorus]
ITSP à NIST on fait la correspondance
Révision trois c'est notre référence
CMMC vers PCCSC on trace le chemin
SOC2 complète notre dessin
Correspondance croisée, notre livrable précieux
Un document qui nous rend victorieux
[Bridge]
Identifier chaque différence
Entre les révisions c'est notre science
Construire un pont entre les normes
Créer un guide sous toutes ses formes
[Verse 3]
Le document de correspondance croisée
Devient notre produit valorisé
CMMC PCCSC SOC2 alignés
Un livrable que l'on peut commercialiser
Trois normes unies dans un seul document
Pour nos clients c'est l'outil gagnant
[Chorus]
ITSP à NIST on fait la correspondance
Révision trois c'est notre référence
CMMC vers PCCSC on trace le chemin
SOC2 complète notre dessin
Correspondance croisée, notre livrable précieux
Un document qui nous rend victorieux
[Outro]
CCC nous donne la norme canadienne
Avec NIST on trace notre antenne
Du CMMC au PCCSC on navigue
SOC2 notre succès intrigue
23. 4 Lectures essentielles
[Verse 1]
ITSG trente-trois guide nos pas
Cadre de gestion, trois étapes là
Catégoriser d'abord nos systèmes
Sélectionner les contrôles qu'on aime
Implémenter puis évaluer
La sécurité pour mieux protéger
[Chorus]
Quatre lectures pour la défense
ITSG, nuage, Conseil, NIST en cadence
Catégoriser, sélectionner, implémenter
Évaluer pour mieux sécuriser
Retenons bien cette séquence
Pour la cyberdéfense
[Verse 2]
Les directives du nuage fédéral
Charges de travail gouvernementales
Chiffrement bout en bout requis
Authentification, contrôle aussi
Données sensibles bien isolées
Dans le cloud autorisé
[Chorus]
Quatre lectures pour la défense
ITSG, nuage, Conseil, NIST en cadence
Catégoriser, sélectionner, implémenter
Évaluer pour mieux sécuriser
Retenons bien cette séquence
Pour la cyberdéfense
[Verse 3]
Directive du Conseil du Trésor
Gestion sécuritaire, règles d'or
Gouvernance et responsabilités
Programmes de sécurité intégrés
Formation du personnel clé
Incidents bien documentés
[Bridge]
NIST deux point zéro arrive
Identifier, protéger, détecter
Répondre et récupérer
Cinq fonctions qui nous guident
Vers une cyber-résilience
[Chorus]
Quatre lectures pour la défense
ITSG, nuage, Conseil, NIST en cadence
Identifier, protéger, détecter
Répondre et récupérer
Retenons bien cette séquence
Pour la cyberdéfense
[Outro]
Stratégie industrielle du Canada
Ces quatre piliers nous guidera
ITSG, directives et cadres unis
Pour un avenir cyber garanti
24. 2 Enjeux CMMC propres au Canada
[Verse 1]
Quand un sous-traitant canadien travaille pour l'Oncle Sam
Les exigences DFARS arrivent comme un programme
Transfert de données sensibles, faut bien protéger
Les informations critiques qu'on va partager
[Chorus]
CMMC au Canada, deux enjeux à retenir
SPRS et DFARS, il faut s'en souvenir
CUI transfrontalier, bien délimiter
GCC-High équivalent, faut l'identifier
[Verse 2]
Dans le système SPRS, chaque entité non-US
Doit s'inscrire et montrer sa note sans surplus
La notation cybersécurité devient obligatoire
Pour prouver qu'on mérite cette relation d'affaire
[Chorus]
CMMC au Canada, deux enjeux à retenir
SPRS et DFARS, il faut s'en souvenir
CUI transfrontalier, bien délimiter
GCC-High équivalent, faut l'identifier
[Bridge]
ITAR et EAR se croisent dans nos flux
Données contrôlées qui traversent entre nous
Délimitation claire du CUI sensible
Pour rester conforme et rester responsable
[Verse 3]
Microsoft GCC-High reste côté américain
Mais au Canada on cherche l'équivalent certain
Infonuagique sécurisée, options nationales
Pour héberger nos données gouvernementales
[Chorus]
CMMC au Canada, deux enjeux à retenir
SPRS et DFARS, il faut s'en souvenir
CUI transfrontalier, bien délimiter
GCC-High équivalent, faut l'identifier
[Outro]
Stratégie industrielle, défense du pays
CMMC nous guide vers la cybersécurité
Sous-traitants canadiens, prêts à collaborer
Avec nos standards hauts pour nous protéger
25. 4 The Privacy Act Framework
[Verse 1]
When you fill out that SF-86 form
There's a law that keeps your data warm
Privacy Act of nineteen seventy-four
Five U-S-C five-fifty-two-a at the core
OPM must tell you where it goes
Publishing routine uses so everyone knows
[Chorus]
Privacy Act protects your information
But there's exceptions for the nation
Intelligence, law enforcement too
Congressional offices need authorization from you
Inspectors general, Merit Board as well
Insider threats and counterintel
[Verse 2]
Most disclosures need your written consent
But some exceptions the law has sent
Federal Register shows the routine ways
Your personal data travels through government maze
Security clearance background checks
Need special rules for what comes next
[Chorus]
Privacy Act protects your information
But there's exceptions for the nation
Intelligence, law enforcement too
Congressional offices need authorization from you
Inspectors general, Merit Board as well
Insider threats and counterintel
[Bridge]
Executive Order thirteen-five-eight-seven
Gives insider threat programs access to heaven
Of background data for security sake
To catch the threats before they break
Notarized signature for Congress requests
All other agencies follow what the law suggests
[Verse 3]
Your SF-86 isn't just a form
It's governed by a privacy storm
Of legal protections and disclosure rules
Understanding these are security tools
Know your rights and know the exceptions
For your clearance and your protections
[Chorus]
Privacy Act protects your information
But there's exceptions for the nation
Intelligence, law enforcement too
Congressional offices need authorization from you
Inspectors general, Merit Board as well
Insider threats and counterintel
[Outro]
Five-fifty-two-a keeps you safe
While national security finds its place
Back to Home