Canada / Petitions

e-7115 · Parliament 45

Mandatory federal secure-coding policy

AI summary

Petitioners ask the Government to require a mandatory secure-coding policy for all custom federal software, designate oversight, and ensure new and existing systems comply. The government responds that existing policies and guidance address secure coding.

AI summaries describe petitioners’ requests and claims. Consult the official record for the full text.

Official petition

Petition to the Government of Canada The Government of Canada develops, commissions, procures, and operates custom software systems to deliver federal programs and services and to manage sensitive government and personal information; There is no single, mandatory federal policy establishing baseline secure-coding requirements applicable across federal departments and Crown corporations for custom software systems; and Inconsistent secure-coding practices increase the risk of security incidents, service disruptions, and avoidable remediation costs affecting federal operations and Canadians. We, the undersigned, citizens of Canada, call upon the Government of Canada to 1. Consider establishing a mandatory federal secure-coding policy applicable to all custom software developed, commissioned, procured, or operated by the Government of Canada and its federal Crown corporations; 2. Designate an appropriate federal authority to provide oversight of secure-coding practices, including the development of baseline requirements, guidance for departments, and mechanisms for monitoring compliance; and 3. Require that new federal software systems adhere to established secure-coding requirements and that existing systems be reviewed and addressed, as appropriate, to reduce security risks. 1. Consider establishing a mandatory federal secure-coding policy applicable to all custom software developed, commissioned, procured, or operated by the Government of Canada and its federal Crown corporations; 2. Designate an appropriate federal authority to provide oversight of secure-coding practices, including the development of baseline requirements, guidance for departments, and mechanisms for monitoring compliance; and 3. Require that new federal software systems adhere to established secure-coding requirements and that existing systems be reviewed and addressed, as appropriate, to reduce security risks.

Government response

Response by the President of the Treasury Board Signed by Tom Osborne The Government of Canada (GC) manages sensitive government and personal information while commissioning, procuring, and operating custom software systems to deliver federal programs and services. This is achieved through various legislative frameworks, policies, and standards, some of which govern both federal departments and Crown corporations. These include the Privacy Act, Access to Information Act, Financial Administration Act, Communications Security Establishment Act, Policy on Service and Digital, Policy on Government Security, and additional supporting standards, policy instruments, and guidance. The Treasury Board of Canada Secretariat (TBS) works collaboratively with enterprise service organizations such as the Communications Security Establishment Canada’s Canadian Centre for Cyber Security (Cyber Centre), Public Services and Procurement Canada (PSPC), and Shared Services Canada (SSC) to advance information technology security objectives. Departments and agencies implement software applications in accordance with enterprise policy objectives, their mandate, and threat and risk profile. The GC remains committed to the continuous monitoring of policies, standards, and guidance to protect sensitive government and personal information. As new and emerging technologies and vulnerabilities are identified, the government’s policy, technology, and procurement approaches continue to adapt to maintain trust and integrity in the software systems that deliver vitally important programs and services to Canadians. In relation to establishing a mandatory federal secure coding policy applicable to all custom software developed, commissioned, procured, or operated by the GC and its federal Crown corporations, the Treasury Board shares responsibility with the Cyber Centre and PSPC to develop requirements mandating the protection of security, privacy, and other sensitive interests, while still achieving the goals of an open government and utilizing open digital practices. As the GC's unified source of cyber security advice, support, and guidance, the Cyber Centre provides training and resources to support secure coding practices and provides input into TBS policies. PSPC leads the procurement policy for software procured by the GC and the Canadian Program for Cyber Security Certification for companies supplying on defence-related contracts. TBS manages the Policy on Service and Digital (PSD) and the Policy on Government Security (PGS), which both include requirements that mandate security and risk management of services, systems, data, and IT across the life cycle of programs, information, assets and systems. Through these policy instruments, GC organizations are required to build security activities (including secure coding practices) into the life cycle of their information systems. Specific directives and requirements under these policies related to secure coding include: Directive on Security Management under the Policy on Government Security System Management Configuration Requirements under the Policy on Service and Digital Web Sites and Services Management Configuration Requirements under the Policy on Service and Digital In addition, TBS is currently developing a “Guideline on Secure Application Development” that supports the requirements above, providing GC organizations with actionable guidance based on policy, industry best practices, and the security requirements needed to reduce risk in an evolving threat landscape. In relation to designating an appropriate federal authority to provide oversight of secure-coding practices, including the development of baseline requirements, guidance for departments, and mechanisms for monitoring compliance, federal authorities for these activities are shared by the Cyber Centre, TBS, and PSPC. The Cyber Centre is the technical authority for cyber security in the GC. They provide advice and guidance, including recommended baseline cyber security controls that aim to protect the confidentiality, integrity, and availability of the GC’s information systems. The Cyber Centre, the Canada School of Public Service (CSPS), and TBS provide additional advice, guidance and training for employees related to secure coding practices. Suggested security controls and control enhancements (ITSG-33) - Canadian Centre for Cyber Security Guidance on the security categorization of cloud-based services (ITSP.50.103) Compliance is monitored by TBS, through a risk-based approach, using a combination of tools provided by internal enterprise service organizations, reporting structures, and data sharing arrangements. For systems that are procured, PSPC ensures the inclusion of contract security clauses in applicable agreements. Through the collaboration of various internal enterprise service organizations, the GC is able to deliver secure, reliable, and client-centric services to Canadians. In relation to requiring that new federal software systems adhere to established secure coding requirements and that existing systems be reviewed and addressed, as appropriate, to reduce security risks, the GC is committed to continuously managing government security in support of the trusted delivery of programs and services, the protection of information, individuals and assets, and providing assurance to Canadians, partners, oversight bodies and other stakeholders regarding security management in the GC. Through administrative policies such as the PGS and PSD, and supported by the Cyber Centre and PSPC, the GC provides a baseline set of security requirements to support the development of secure information systems, and requires that departments are responsible for ensuring the development and delivery of client-centric service by design, including access, inclusion, accessibility, security, and privacy, while maintaining program, service, and system integrity. The Directive on Security Management requires departments to implement Security Assessment and Authorization processes to ensure the appropriate selection, implementation, and assessment of security controls. Where applicable, these controls include secure coding requirements, security testing, and flaw remediation. To ensure developers building solutions in the GC can put secure coding principles into practice, the Cyber Centre provides advice, guidance, and training related to secure coding, including courses supporting Secure Software Development. To further support accountability, departmental compliance is reported and overseen through existing digital and service standard reporting, the Cyber Assurance and Risk Evaluation process, enterprise monitoring, cyber event reporting via the GC Cyber Security Event Management Plan, and architecture reviews for new and existing federal information systems to proactively manage security risks.