Cyber and Infrastructure Resilience Assessments
The Regional Resilience Assessment Program
The Regional Resilience Assessment Program (RRAP) is a vulnerability and dependency assessment program for owners and operators of critical infrastructure (CI) facilities within the 10 CI sectors in Canada. This program involves site assessments to help organizations measure and improve their resilience to all hazards in Canada, such as cyber threats, accidental or intentional man-made events, and natural catastrophes.
These site assessments are voluntary, non-regulatory, free-of-charge and confidential. Participants are asked to complete three 5-minute surveys on their experience with the program after the assessment is conducted.
How it works
The RRAP is comprised of three tools:
- Critical Infrastructure Resilience Tool (CIRT) (1 day to complete)
- An on-site, survey-based tool that measures the resilience and protective measures of a facility.
- Outputs include a report and interactive dashboards that provide scores and peer comparisons, and highlight dependencies and resilience enhancement options for physical security, resilience, and cyber security.
- Critical Infrastructure Multimedia Tool (CIMT) (1/2 day to 1 day to complete)
- A virtual rendering of a facility based on floor plans. It features panoramic photographs of interior and exterior significant areas and can be shared with first responders and/or used in exercises.
- Although doing so is at the discretion of the organization, we highly encourage sharing the CIMT with first responders so it can be used as a tool to prepare for, and respond to, emergency situations.
- Canadian Cyber Resilience Review (CCRR) (1 to 1.5 day to complete)
- An on-site, survey-based tool that measures the cyber security posture of an organization.
- Outputs include two reports (brief and comprehensive) with scores across the 10 domains of the NIST Cyber Security Framework, peer comparisons, and resilience enhancement options.
Both the CIRT and CCRR require the presence of individuals who are subject matter experts on facility security, IT, and facility management. Organizations can request each one of the tools individually or as a package. Use of all three tools typically takes three days. Post-assessment check-ups may be conducted with the organization up to 24 months after the assessment.
Organizations may also signal interest in participating in a broader regional assessment. These projects typically involve the Department working with multiple organizations in a particular region. Examining a specific hazard, the objective is to help identify key interdependencies, as well as opportunities to individually and collectively minimize the impact and likelihood of a disruption. During a regional assessment, the individual assessment tools are deployed alongside modelling tools, workshops, stakeholder meetings, and subject matter expert interviews.
How it helps your organization
Results from assessments are intended to help owners and operators enhance their resiliency by identifying dependencies and vulnerabilities within their organization. Site assessments also identify a series of optional cost effective measures to help owners and operators mitigate risks and improve their ability to respond to and recover from disruptions.
Specifically, the RRAP helps to enable:
- Better risk management
- Increases an organization's understanding of its physical and procedural vulnerabilities.
- Strengthened government relationships
- Enhances relationships with multiple government departments, including municipal level representatives such as first responders.
- Improved cyber security awareness
- Identifies how well an organization is prepared for cyber-attacks and other cyber threats.
Other key considerations for CI owners and operators:
- Minimal investment of time and resources
- RRAP service is quick and is offered at no cost.
- Public Safety Canada will protect the confidentiality of documents and information provided by owners and operators of CI
Implementation of any/all resilience enhancements options and observations provided following an assessment are at the discretion of the owner/operator.
For more information or to request an assessment
For more information please see Frequently Asked Questions.
If you're a CI owner or operator, contact us to discuss the possibility of having an assessment of your facility. Members are also available to provide an interactive presentation to further explain the program and the products provided.
CI Talks: Regional Resilience Assessment Program
- Date modified: