Framework National Cyber & Cloud Schemes
CCCS ITSG-33
ITSG-33, "IT Security Risk Management: A Lifecycle Approach", is the Canadian Centre for Cyber Security's (part of the Communications Security Establishment) guidance for how Government of Canada departments manage IT security risk.
It is Canada's counterpart to the NIST risk management series: Annex 1 describes departmental-level activities (defining security control profiles, roles, and continuous monitoring), Annex 2 describes the information system security implementation process across a project lifecycle, Annex 3A is the security control catalog (derived from NIST SP 800-53 and grouped into management, operational, and technical families), and Annexes 4 and 5 give security control profiles for common protected-B, medium-integrity, medium-availability environments and glossary material.
Departments use it to satisfy the Treasury Board Policy on Government Security and Directive on Security Management, and CCCS's cloud security guidance uses the ITSG-33 profiles to assess cloud service providers for government use.
ITSG-33 does not create a certificate. Systems are authorized by departmental officials after a security assessment, and cloud providers receive a CCCS assessment against the relevant profile that departments rely on.
In writing, a department or supplier needs a security categorization (statement of sensitivity), a selected control profile with tailoring rationale, a system security plan or equivalent describing each control's implementation, assessment evidence, a plan for residual risks, and continuous monitoring reports.
help
Who has to comply
Government of Canada departments and agencies subject to Treasury Board security policy. Cloud and IT service providers to the federal government meet it indirectly: CCCS assesses cloud services against ITSG-33 profiles under its Cloud Service Provider IT Security Assessment Program, and departments write the profiles into contracts.
What the assessor asks to see
Statement of sensitivity and security categorization; selected control profile and tailoring rationale; security requirements traceability matrix; system security plan or control implementation descriptions; architecture and data flow; assessment plan and results; vulnerability assessment and penetration test reports; residual risk and plan of action; authorization letter; continuous monitoring reports; for cloud providers, third-party audit reports (SOC 2, ISO/IEC 27001) mapped to ITSG-33 controls.
Assessors
Who assesses CCCS ITSG-33
Departmental security assessors (internal or contracted) for departmental systems, with authorization by the departmental authority; CCCS assessors for cloud service providers under the CSP IT Security Assessment Program. No private certification exists. assessments are governmental.
No firm has claimed a CCCS ITSG-33 assessor listing yet. Claim yours →
Consultants
Who helps with CCCS ITSG-33
Canadian security consultancies and the federal practices of global firms build control profiles, security assessment and authorization (SA&A) packages, and cloud provider evidence sets. Engagements run several months for a first authorization package.
Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.
No firm has claimed a CCCS ITSG-33 consultant listing yet. Claim yours →
Software
Tools for CCCS ITSG-33
Tools that name this framework in their own material.
No firm has claimed a CCCS ITSG-33 tool listing yet. Claim yours →
Related reading
- CCCS assessmentDescribes how the Canadian Centre for Cyber Security assesses a provider against the Medium cloud control profile drawn from ITSG-33.Amazon Web Services
- Canadian Centre for Cybersecurity Medium (CCCS Medium)Explains the Protected B, medium integrity, medium availability profile and how responsibility splits between provider and department.Microsoft
Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.
Need a hand implementing it?
Find a Consultant for CCCS ITSG-33
Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.
Not sure where to start?
Get Help with CCCS ITSG-33
Tell us what you are trying to put in place. We will point you to the right tool, a consultant who can implement it, or both.