ODPs: The Make-or-Break Factor in CPCSC Compliance – Cyber Defence
BY ARNOLD VILLENEUVE

If you’ve spent time decoding the new CPCSC standard, you’ve already encountered the term Organization-Defined Parameter (ODP). And if your eyes glossed over it, you’re not alone—but that’s a mistake. Because in the world of ITSP.10.171 compliance, ODPs are not filler—they’re foundational.
In fact, a misstep in setting or defending your ODPs can tank an otherwise strong security posture. You can be doing “all the right things,” but if your parameter choices are weak, unjustified, or undocumented, you’ll fail the assessment. Full stop.
READ THE LATEST: CPCSC Level 1: What suppliers actually need to secure – and how to prove it
WHAT ARE ODPs?
ODPs are variables within ITSP.10.171 controls that must be explicitly defined by each organization. Unlike fixed requirements (like “implement multi-factor authentication”), ODPs give you flexibility—but not freedom without accountability.
An ODP might ask: • How often do you review user access privileges? • What is your maximum session timeout period? • Within how many days must a vulnerability be remediated?
These aren’t trivia questions; they’re testable commitments. And you’ll be judged not just on whether you picked a number, but why you chose that number and how you enforce it.
WHY ODPs EXIST
ODPs are not loopholes. They exist because not all organizations face the same threat environment, asset value, or operational reality. A 30-person engineering consultancy shouldn’t be held to the same log retention period as a multinational defence manufacturer. But both need to think, justify, and document their reasoning.
ITSP.10.171 leans on ODPs to force organizations to exercise maturity in risk-based decision-making. That’s a subtle but essential hallmark of the CPCSC approach: it’s not just about checking boxes—it’s about understanding your own environment well enough to defend your choices with clarity and evidence.
HOW ODPs ARE EVALUATED
As an Assessor, I’ve seen this pattern repeatedly: organizations treat ODPs as administrative side notes. They say things like “our scan frequency is monthly because that’s what we’ve always done,” or worse, “we picked that number because the consultant said so.” That’s a one-way ticket to a “Not Met” finding.
To score a “Met,” your ODPs must meet three criteria: Defined – The parameter is clearly stated in a policy, standard, or procedure; Justified – There’s a documented rationale based on risk, business need, or compliance alignment; Implemented – Evidence shows the parameter is enforced in practice (e.g., log files, scan reports, audit trails).
If you can’t hit all three, you’re vulnerable to an adverse determination, regardless of whether the underlying activity is happening.
COMMON ODP PITFALLS
Copy-Paste Syndrome: Lifting parameters from NIST templates without tailoring them to your environment.
Overly Conservative Defaults: Adopting aggressive values to appear secure but failing to meet them consistently.
Missing Traceability: Not mapping ODPs back to documented policy, SOPs, or the System Security Plan (SSP).
Stakeholder Silos: Having IT set ODPs without business input, leading to impractical or unenforced parameters.
The CPCSC assessment process will identify these issues. You don’t want to get caught explaining why your session timeout is “15 minutes” when every machine is configured to allow two hours.
BEST PRACTICES FOR ODP SUCCESS
1) Create an ODP Register: Maintain a central spreadsheet or database listing all ODPs, their rationale, approving authority, and last review date. 2) Tie ODPs to Risk Management: Use your threat model or risk register to justify each parameter. 3) Engage Stakeholders Early: Security, operations, and compliance must align on what’s feasible and enforceable. 4) Audit Your ODPs Quarterly: Don’t treat ODPs as static. Revisit them as your threat landscape, systems, or contracts evolve. 5) Train Your Assessors: If you’re using internal readiness teams, ensure they understand how to evaluate ODPs critically and consistently.
TREAT ODPs LIKE CONTRACT TERMS
You wouldn’t sign a defence contract without reading the fine print. Don’t approach ITSP.10.171 any differently.
Each ODP is a micro-contract promise your organization makes to the Crown, to your clients, and your Assessor. Define it. Defend it. Demonstrate it. Because in the world of CPCSC, ODPs are not optional—they’re operational.
Arnold Villeneuve is Director of Achieva Tech Incorporated. For more information, visit, www.achievatech.com. The views expressed here are his own and do not necessarily represent a CDR editorial position.

