Canada ITSG-33 - IT Security Risk Management
Evidence request list. 26 controls, 26 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
ITSG-33: IT Security Risk Management Process
ITSG-33 Annex 1: departmental-level IT security risk management - establishing the departmental security control profile, governance, and the IT security function that supports information system risk management across the organisation.
- documented departmental security control profile / risk-management process records
- security categorization and control-selection records
- authorization (ATO) and continuous-monitoring evidence
- process defined but not applied per system
- no security categorization performed
- no continuous monitoring after authorization
ITSG-33 Annex 2: the Information System Security Implementation Process (ISSIP) - integrating security into the system development life cycle of each information system.
- documented departmental security control profile / risk-management process records
- security categorization and control-selection records
- authorization (ATO) and continuous-monitoring evidence
- process defined but not applied per system
- no security categorization performed
- no continuous monitoring after authorization
ITSG-33: determine the security category of the information system based on injury (confidentiality, integrity, availability) to select an appropriate control profile.
- documented departmental security control profile / risk-management process records
- security categorization and control-selection records
- authorization (ATO) and continuous-monitoring evidence
- process defined but not applied per system
- no security categorization performed
- no continuous monitoring after authorization
ITSG-33: select and tailor security controls using the Annex 4A profiles (e.g. PROTECTED B / Medium / Medium - PBMM) appropriate to the system security category.
- documented departmental security control profile / risk-management process records
- security categorization and control-selection records
- authorization (ATO) and continuous-monitoring evidence
- process defined but not applied per system
- no security categorization performed
- no continuous monitoring after authorization
ITSG-33: assess implemented security controls and grant an authorization to operate (ATO) based on residual risk acceptance.
- documented departmental security control profile / risk-management process records
- security categorization and control-selection records
- authorization (ATO) and continuous-monitoring evidence
- process defined but not applied per system
- no security categorization performed
- no continuous monitoring after authorization
ITSG-33: maintain ongoing awareness of security state, vulnerabilities and threats to support risk-based decisions throughout the system life cycle.
- documented departmental security control profile / risk-management process records
- security categorization and control-selection records
- authorization (ATO) and continuous-monitoring evidence
- process defined but not applied per system
- no security categorization performed
- no continuous monitoring after authorization
ITSG-33: Management Class Controls
ITSG-33 Annex 3A management family: Security Assessment and Authorization.
- the family policy and procedures for Security Assessment and Authorization
- evidence the family controls from ITSG-33 Annex 3A / the selected profile are implemented
- assessment results for the family controls
- family policy missing or stale
- controls selected but not implemented or assessed
- profile tailoring undocumented
ITSG-33 Annex 3A management family: Planning.
- the family policy and procedures for Planning
- evidence the family controls from ITSG-33 Annex 3A / the selected profile are implemented
- assessment results for the family controls
- family policy missing or stale
- controls selected but not implemented or assessed
- profile tailoring undocumented
ITSG-33 Annex 3A management family: Risk Assessment.
- the family policy and procedures for Risk Assessment
- evidence the family controls from ITSG-33 Annex 3A / the selected profile are implemented
- assessment results for the family controls
- family policy missing or stale
- controls selected but not implemented or assessed
- profile tailoring undocumented
ITSG-33 Annex 3A management family: System and Services Acquisition.
- the family policy and procedures for System and Services Acquisition
- evidence the family controls from ITSG-33 Annex 3A / the selected profile are implemented
- assessment results for the family controls
- family policy missing or stale
- controls selected but not implemented or assessed
- profile tailoring undocumented
ITSG-33: Operational Class Controls
ITSG-33 Annex 3A operational family: Awareness and Training.
- the family policy and procedures for Awareness and Training
- evidence the family controls from ITSG-33 Annex 3A / the selected profile are implemented
- assessment results for the family controls
- family policy missing or stale
- controls selected but not implemented or assessed
- profile tailoring undocumented
ITSG-33 Annex 3A operational family: Configuration Management.
- the family policy and procedures for Configuration Management
- evidence the family controls from ITSG-33 Annex 3A / the selected profile are implemented
- assessment results for the family controls
- family policy missing or stale
- controls selected but not implemented or assessed
- profile tailoring undocumented
ITSG-33 Annex 3A operational family: Contingency Planning (Continuity Planning).
- the family policy and procedures for Contingency Planning
- evidence the family controls from ITSG-33 Annex 3A / the selected profile are implemented
- assessment results for the family controls
- family policy missing or stale
- controls selected but not implemented or assessed
- profile tailoring undocumented
ITSG-33 Annex 3A operational family: Incident Response.
- the family policy and procedures for Incident Response
- evidence the family controls from ITSG-33 Annex 3A / the selected profile are implemented
- assessment results for the family controls
- family policy missing or stale
- controls selected but not implemented or assessed
- profile tailoring undocumented
ITSG-33 Annex 3A operational family: Maintenance.
- the family policy and procedures for Maintenance
- evidence the family controls from ITSG-33 Annex 3A / the selected profile are implemented
- assessment results for the family controls
- family policy missing or stale
- controls selected but not implemented or assessed
- profile tailoring undocumented
ITSG-33 Annex 3A operational family: Media Protection.
- the family policy and procedures for Media Protection
- evidence the family controls from ITSG-33 Annex 3A / the selected profile are implemented
- assessment results for the family controls
- family policy missing or stale
- controls selected but not implemented or assessed
- profile tailoring undocumented
ITSG-33 Annex 3A operational family: Physical and Environmental Protection.
- the family policy and procedures for Physical and Environmental Protection
- evidence the family controls from ITSG-33 Annex 3A / the selected profile are implemented
- assessment results for the family controls
- family policy missing or stale
- controls selected but not implemented or assessed
- profile tailoring undocumented
ITSG-33 Annex 3A operational family: Personnel Security.
- the family policy and procedures for Personnel Security
- evidence the family controls from ITSG-33 Annex 3A / the selected profile are implemented
- assessment results for the family controls
- family policy missing or stale
- controls selected but not implemented or assessed
- profile tailoring undocumented
ITSG-33 Annex 3A operational family: System and Information Integrity.
- the family policy and procedures for System and Information Integrity
- evidence the family controls from ITSG-33 Annex 3A / the selected profile are implemented
- assessment results for the family controls
- family policy missing or stale
- controls selected but not implemented or assessed
- profile tailoring undocumented
ITSG-33: Technical Class Controls
ITSG-33 Annex 3A technical family: Access Control.
- the family policy and procedures for Access Control
- evidence the family controls from ITSG-33 Annex 3A / the selected profile are implemented
- assessment results for the family controls
- family policy missing or stale
- controls selected but not implemented or assessed
- profile tailoring undocumented
ITSG-33 Annex 3A technical family: Audit and Accountability.
- the family policy and procedures for Audit and Accountability
- evidence the family controls from ITSG-33 Annex 3A / the selected profile are implemented
- assessment results for the family controls
- family policy missing or stale
- controls selected but not implemented or assessed
- profile tailoring undocumented
ITSG-33 Annex 3A technical family: Identification and Authentication.
- the family policy and procedures for Identification and Authentication
- evidence the family controls from ITSG-33 Annex 3A / the selected profile are implemented
- assessment results for the family controls
- family policy missing or stale
- controls selected but not implemented or assessed
- profile tailoring undocumented
ITSG-33 Annex 3A technical family: System and Communications Protection.
- the family policy and procedures for System and Communications Protection
- evidence the family controls from ITSG-33 Annex 3A / the selected profile are implemented
- assessment results for the family controls
- family policy missing or stale
- controls selected but not implemented or assessed
- profile tailoring undocumented
Security Controls
Controls organised into families: access control, audit, certification, configuration management, contingency, identification, incident response, maintenance, media, physical, planning, personnel, risk, and system protection.
- Control selection records
- Tailoring decisions
- Baseline mapping
- Inheritance documentation
- No tailoring
- No inheritance
- No baseline
- Selection undocumented
Baseline security profiles for Protected A, Protected B, and classified systems. Profiles specify minimum security controls. Tailoring guidance for specific system characteristics and threat environments.
- Security profile documentation
- Tailoring rationale
- Profile approval records
- Cross-reference to baseline
- No profile
- Tailoring undocumented
- No approvals
- No cross-reference
GC cloud security controls and assessment. CCCS cloud security assessment programme. Approved cloud service providers for GC data. Protected B cloud requirements.
- Cloud risk assessment
- Provider attestations
- Shared responsibility matrix
- Cloud control inheritance
- No matrix
- Inheritance unverified
- No attestations
- No assessment
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Canada ITSG-33 - IT Security Risk Management framework page.