Skip to content

Evidence request lists

Canada ITSG-33 - IT Security Risk Management

Evidence request list. 26 controls, 26 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

ITSG-33: IT Security Risk Management Process

ITSG33-RMP-1
Departmental IT Security Risk Management Activities (Annex 1)

ITSG-33 Annex 1: departmental-level IT security risk management - establishing the departmental security control profile, governance, and the IT security function that supports information system risk management across the organisation.

Artefacts an auditor will ask for
  • documented departmental security control profile / risk-management process records
  • security categorization and control-selection records
  • authorization (ATO) and continuous-monitoring evidence
Where this commonly fails
  • process defined but not applied per system
  • no security categorization performed
  • no continuous monitoring after authorization
ITSG33-RMP-2
Information System Security Risk Management Activities / ISSIP (Annex 2)

ITSG-33 Annex 2: the Information System Security Implementation Process (ISSIP) - integrating security into the system development life cycle of each information system.

Artefacts an auditor will ask for
  • documented departmental security control profile / risk-management process records
  • security categorization and control-selection records
  • authorization (ATO) and continuous-monitoring evidence
Where this commonly fails
  • process defined but not applied per system
  • no security categorization performed
  • no continuous monitoring after authorization
ITSG33-RMP-3
Security Categorization

ITSG-33: determine the security category of the information system based on injury (confidentiality, integrity, availability) to select an appropriate control profile.

Artefacts an auditor will ask for
  • documented departmental security control profile / risk-management process records
  • security categorization and control-selection records
  • authorization (ATO) and continuous-monitoring evidence
Where this commonly fails
  • process defined but not applied per system
  • no security categorization performed
  • no continuous monitoring after authorization
ITSG33-RMP-4
Security Control Selection and Profiles (Annex 4A)

ITSG-33: select and tailor security controls using the Annex 4A profiles (e.g. PROTECTED B / Medium / Medium - PBMM) appropriate to the system security category.

Artefacts an auditor will ask for
  • documented departmental security control profile / risk-management process records
  • security categorization and control-selection records
  • authorization (ATO) and continuous-monitoring evidence
Where this commonly fails
  • process defined but not applied per system
  • no security categorization performed
  • no continuous monitoring after authorization
ITSG33-RMP-5
Security Assessment and Authorization

ITSG-33: assess implemented security controls and grant an authorization to operate (ATO) based on residual risk acceptance.

Artefacts an auditor will ask for
  • documented departmental security control profile / risk-management process records
  • security categorization and control-selection records
  • authorization (ATO) and continuous-monitoring evidence
Where this commonly fails
  • process defined but not applied per system
  • no security categorization performed
  • no continuous monitoring after authorization
ITSG33-RMP-6
Continuous Monitoring

ITSG-33: maintain ongoing awareness of security state, vulnerabilities and threats to support risk-based decisions throughout the system life cycle.

Artefacts an auditor will ask for
  • documented departmental security control profile / risk-management process records
  • security categorization and control-selection records
  • authorization (ATO) and continuous-monitoring evidence
Where this commonly fails
  • process defined but not applied per system
  • no security categorization performed
  • no continuous monitoring after authorization

ITSG-33: Management Class Controls

ITSG33-CA
Security Assessment and Authorization (CA)

ITSG-33 Annex 3A management family: Security Assessment and Authorization.

Artefacts an auditor will ask for
  • the family policy and procedures for Security Assessment and Authorization
  • evidence the family controls from ITSG-33 Annex 3A / the selected profile are implemented
  • assessment results for the family controls
Where this commonly fails
  • family policy missing or stale
  • controls selected but not implemented or assessed
  • profile tailoring undocumented
ITSG33-PL
Planning (PL)

ITSG-33 Annex 3A management family: Planning.

Artefacts an auditor will ask for
  • the family policy and procedures for Planning
  • evidence the family controls from ITSG-33 Annex 3A / the selected profile are implemented
  • assessment results for the family controls
Where this commonly fails
  • family policy missing or stale
  • controls selected but not implemented or assessed
  • profile tailoring undocumented
ITSG33-RA
Risk Assessment (RA)

ITSG-33 Annex 3A management family: Risk Assessment.

Artefacts an auditor will ask for
  • the family policy and procedures for Risk Assessment
  • evidence the family controls from ITSG-33 Annex 3A / the selected profile are implemented
  • assessment results for the family controls
Where this commonly fails
  • family policy missing or stale
  • controls selected but not implemented or assessed
  • profile tailoring undocumented
ITSG33-SA
System and Services Acquisition (SA)

ITSG-33 Annex 3A management family: System and Services Acquisition.

Artefacts an auditor will ask for
  • the family policy and procedures for System and Services Acquisition
  • evidence the family controls from ITSG-33 Annex 3A / the selected profile are implemented
  • assessment results for the family controls
Where this commonly fails
  • family policy missing or stale
  • controls selected but not implemented or assessed
  • profile tailoring undocumented

ITSG-33: Operational Class Controls

ITSG33-AT
Awareness and Training (AT)

ITSG-33 Annex 3A operational family: Awareness and Training.

Artefacts an auditor will ask for
  • the family policy and procedures for Awareness and Training
  • evidence the family controls from ITSG-33 Annex 3A / the selected profile are implemented
  • assessment results for the family controls
Where this commonly fails
  • family policy missing or stale
  • controls selected but not implemented or assessed
  • profile tailoring undocumented
ITSG33-CM
Configuration Management (CM)

ITSG-33 Annex 3A operational family: Configuration Management.

Artefacts an auditor will ask for
  • the family policy and procedures for Configuration Management
  • evidence the family controls from ITSG-33 Annex 3A / the selected profile are implemented
  • assessment results for the family controls
Where this commonly fails
  • family policy missing or stale
  • controls selected but not implemented or assessed
  • profile tailoring undocumented
ITSG33-CP
Contingency Planning (CP)

ITSG-33 Annex 3A operational family: Contingency Planning (Continuity Planning).

Artefacts an auditor will ask for
  • the family policy and procedures for Contingency Planning
  • evidence the family controls from ITSG-33 Annex 3A / the selected profile are implemented
  • assessment results for the family controls
Where this commonly fails
  • family policy missing or stale
  • controls selected but not implemented or assessed
  • profile tailoring undocumented
ITSG33-IR
Incident Response (IR)

ITSG-33 Annex 3A operational family: Incident Response.

Artefacts an auditor will ask for
  • the family policy and procedures for Incident Response
  • evidence the family controls from ITSG-33 Annex 3A / the selected profile are implemented
  • assessment results for the family controls
Where this commonly fails
  • family policy missing or stale
  • controls selected but not implemented or assessed
  • profile tailoring undocumented
ITSG33-MA
Maintenance (MA)

ITSG-33 Annex 3A operational family: Maintenance.

Artefacts an auditor will ask for
  • the family policy and procedures for Maintenance
  • evidence the family controls from ITSG-33 Annex 3A / the selected profile are implemented
  • assessment results for the family controls
Where this commonly fails
  • family policy missing or stale
  • controls selected but not implemented or assessed
  • profile tailoring undocumented
ITSG33-MP
Media Protection (MP)

ITSG-33 Annex 3A operational family: Media Protection.

Artefacts an auditor will ask for
  • the family policy and procedures for Media Protection
  • evidence the family controls from ITSG-33 Annex 3A / the selected profile are implemented
  • assessment results for the family controls
Where this commonly fails
  • family policy missing or stale
  • controls selected but not implemented or assessed
  • profile tailoring undocumented
ITSG33-PE
Physical and Environmental Protection (PE)

ITSG-33 Annex 3A operational family: Physical and Environmental Protection.

Artefacts an auditor will ask for
  • the family policy and procedures for Physical and Environmental Protection
  • evidence the family controls from ITSG-33 Annex 3A / the selected profile are implemented
  • assessment results for the family controls
Where this commonly fails
  • family policy missing or stale
  • controls selected but not implemented or assessed
  • profile tailoring undocumented
ITSG33-PS
Personnel Security (PS)

ITSG-33 Annex 3A operational family: Personnel Security.

Artefacts an auditor will ask for
  • the family policy and procedures for Personnel Security
  • evidence the family controls from ITSG-33 Annex 3A / the selected profile are implemented
  • assessment results for the family controls
Where this commonly fails
  • family policy missing or stale
  • controls selected but not implemented or assessed
  • profile tailoring undocumented
ITSG33-SI
System and Information Integrity (SI)

ITSG-33 Annex 3A operational family: System and Information Integrity.

Artefacts an auditor will ask for
  • the family policy and procedures for System and Information Integrity
  • evidence the family controls from ITSG-33 Annex 3A / the selected profile are implemented
  • assessment results for the family controls
Where this commonly fails
  • family policy missing or stale
  • controls selected but not implemented or assessed
  • profile tailoring undocumented

ITSG-33: Technical Class Controls

ITSG33-AC
Access Control (AC)

ITSG-33 Annex 3A technical family: Access Control.

Artefacts an auditor will ask for
  • the family policy and procedures for Access Control
  • evidence the family controls from ITSG-33 Annex 3A / the selected profile are implemented
  • assessment results for the family controls
Where this commonly fails
  • family policy missing or stale
  • controls selected but not implemented or assessed
  • profile tailoring undocumented
ITSG33-AU
Audit and Accountability (AU)

ITSG-33 Annex 3A technical family: Audit and Accountability.

Artefacts an auditor will ask for
  • the family policy and procedures for Audit and Accountability
  • evidence the family controls from ITSG-33 Annex 3A / the selected profile are implemented
  • assessment results for the family controls
Where this commonly fails
  • family policy missing or stale
  • controls selected but not implemented or assessed
  • profile tailoring undocumented
ITSG33-IA
Identification and Authentication (IA)

ITSG-33 Annex 3A technical family: Identification and Authentication.

Artefacts an auditor will ask for
  • the family policy and procedures for Identification and Authentication
  • evidence the family controls from ITSG-33 Annex 3A / the selected profile are implemented
  • assessment results for the family controls
Where this commonly fails
  • family policy missing or stale
  • controls selected but not implemented or assessed
  • profile tailoring undocumented
ITSG33-SC
System and Communications Protection (SC)

ITSG-33 Annex 3A technical family: System and Communications Protection.

Artefacts an auditor will ask for
  • the family policy and procedures for System and Communications Protection
  • evidence the family controls from ITSG-33 Annex 3A / the selected profile are implemented
  • assessment results for the family controls
Where this commonly fails
  • family policy missing or stale
  • controls selected but not implemented or assessed
  • profile tailoring undocumented

Security Controls

CA-ITSG33-SC-01
Security Control Catalogue

Controls organised into families: access control, audit, certification, configuration management, contingency, identification, incident response, maintenance, media, physical, planning, personnel, risk, and system protection.

Artefacts an auditor will ask for
  • Control selection records
  • Tailoring decisions
  • Baseline mapping
  • Inheritance documentation
Where this commonly fails
  • No tailoring
  • No inheritance
  • No baseline
  • Selection undocumented
CA-ITSG33-SC-02
Security Profiles

Baseline security profiles for Protected A, Protected B, and classified systems. Profiles specify minimum security controls. Tailoring guidance for specific system characteristics and threat environments.

Artefacts an auditor will ask for
  • Security profile documentation
  • Tailoring rationale
  • Profile approval records
  • Cross-reference to baseline
Where this commonly fails
  • No profile
  • Tailoring undocumented
  • No approvals
  • No cross-reference
CA-ITSG33-SC-03
Cloud Security

GC cloud security controls and assessment. CCCS cloud security assessment programme. Approved cloud service providers for GC data. Protected B cloud requirements.

Artefacts an auditor will ask for
  • Cloud risk assessment
  • Provider attestations
  • Shared responsibility matrix
  • Cloud control inheritance
Where this commonly fails
  • No matrix
  • Inheritance unverified
  • No attestations
  • No assessment
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Canada ITSG-33 - IT Security Risk Management framework page.