Technical Assurance Review of a Specific Communications Security Establishment Activity


Backgrounder

A redacted version of the National Security and Intelligence Review Agency’s (NSIRA) Review of the Communications Security Establishment’s Deletion of Data from Select [**] Partners was recently released under the Access to Information Act.

This review is an example of a new Technical Assurance Review (TAR) format that NSIRA is using to communicate the results of its review work to the appropriate Minister. The format provides a focused assessment of a specific process, system or control, based on evidence gathered during the review.

Why This Matters

National security and intelligence organizations rely on complex technical systems to manage sensitive information. NSIRA’s role includes examining whether these systems and related controls work as intended.

A TAR allows NSIRA to take a focused look at a particular process and assess its effectiveness using evidence from the systems themselves, including system records, logs and selected data.

The Review

The review examined elements of the Communications Security Establishment’s (CSE) process for deleting signals intelligence (SIGINT) data following a deletion request.

In response to a compliance incident reported by CSE in March 2025 involving dataset sharing and deletion requests with international partners, NSIRA sought to assess how CSE handles the deletion of data in Canada when it involves information received from an international partner.

NSIRA selected three requests that were sent to its systems to delete data and examined the associated systems, records and audit logs to verify the controls were functioning. For selected information, NSIRA directly verified that it had been deleted from CSE’s systems.

Findings

NSIRA confirmed that the selected information had been deleted by the time of its assessment.

The review also identified weaknesses in the process. In one system, an automatic deletion request did not result in the expected deletion, requiring CSE staff to delete the information manually. CSE also identified another instance where information that should have been deleted remained in a system and subsequently deleted it.

NSIRA found that CSE’s deletion records did not contain enough detail to confirm exactly when individual pieces of information had been deleted.

These findings raised concerns about the reliability and timeliness of the deletion process, even though the selected information had ultimately been deleted.

Assurance Rating

NSIRA assigned a Medium Assurance rating to the effectiveness of CSE’s deletion process.

The rating reflects the issues identified during the review and limits on NSIRA’s ability to directly access CSE’s systems and independently verify when individual pieces of information were deleted.

Looking Ahead

TARs were first introduced as a pilot in 2025 to provide NSIRA with an additional tool to assess technical activities in the national security space, with an emphasis on delivering timely, concise and transparent reviews.

Following the pilot, NSIRA has adopted this new practice as a formal review type, alongside other review types to fulfill its broad review mandate, selecting the approach best suited to the nature, scope and complexity of each review.

Date Modified: