HomeFrameworksNational Cyber & Cloud SchemesCCCS ITSG-33

Framework  National Cyber & Cloud Schemes

CCCS ITSG-33

ITSG-33, "IT Security Risk Management: A Lifecycle Approach", is the Canadian Centre for Cyber Security's (part of the Communications Security Establishment) guidance for how Government of Canada departments manage IT security risk.

It is Canada's counterpart to the NIST risk management series: Annex 1 describes departmental-level activities (defining security control profiles, roles, and continuous monitoring), Annex 2 describes the information system security implementation process across a project lifecycle, Annex 3A is the security control catalog (derived from NIST SP 800-53 and grouped into management, operational, and technical families), and Annexes 4 and 5 give security control profiles for common protected-B, medium-integrity, medium-availability environments and glossary material.

Departments use it to satisfy the Treasury Board Policy on Government Security and Directive on Security Management, and CCCS's cloud security guidance uses the ITSG-33 profiles to assess cloud service providers for government use.

ITSG-33 does not create a certificate. Systems are authorized by departmental officials after a security assessment, and cloud providers receive a CCCS assessment against the relevant profile that departments rely on.

In writing, a department or supplier needs a security categorization (statement of sensitivity), a selected control profile with tailoring rationale, a system security plan or equivalent describing each control's implementation, assessment evidence, a plan for residual risks, and continuous monitoring reports.

AI-compiled
Share
Sponsored
CCCS
help
Consultants  Assessors  Quotes
Matched3 quotesread by a human
The Shortlist is Yoursfrom this directory
Comply the Modern WayFind help with CCCS ITSG-33
01
Verified listings first
Unverified ones follow, labeled
02
Published prices where they exist
“Quote only” where we confirmed it, “Not published” where we have not
03
Up to three quotes, one form
Firms don’t see you until you choose
House ad. This slot is open to firms listed for this page. Get help Advertise here

Who has to comply

Government of Canada departments and agencies subject to Treasury Board security policy. Cloud and IT service providers to the federal government meet it indirectly: CCCS assesses cloud services against ITSG-33 profiles under its Cloud Service Provider IT Security Assessment Program, and departments write the profiles into contracts.

What the assessor asks to see

Statement of sensitivity and security categorization; selected control profile and tailoring rationale; security requirements traceability matrix; system security plan or control implementation descriptions; architecture and data flow; assessment plan and results; vulnerability assessment and penetration test reports; residual risk and plan of action; authorization letter; continuous monitoring reports; for cloud providers, third-party audit reports (SOC 2, ISO/IEC 27001) mapped to ITSG-33 controls.

Assessors

Who assesses CCCS ITSG-33

Departmental security assessors (internal or contracted) for departmental systems, with authorization by the departmental authority; CCCS assessors for cloud service providers under the CSP IT Security Assessment Program. No private certification exists. assessments are governmental.

No firm has claimed a CCCS ITSG-33 assessor listing yet. Claim yours →

Consultants

Who helps with CCCS ITSG-33

Canadian security consultancies and the federal practices of global firms build control profiles, security assessment and authorization (SA&A) packages, and cloud provider evidence sets. Engagements run several months for a first authorization package.

Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.

No firm has claimed a CCCS ITSG-33 consultant listing yet. Claim yours →

Software

Tools for CCCS ITSG-33

Tools that name this framework in their own material.

No firm has claimed a CCCS ITSG-33 tool listing yet. Claim yours →

Related reading

  1. CCCS assessmentDescribes how the Canadian Centre for Cyber Security assesses a provider against the Medium cloud control profile drawn from ITSG-33.Amazon Web Services
  2. Canadian Centre for Cybersecurity Medium (CCCS Medium)Explains the Protected B, medium integrity, medium availability profile and how responsibility splits between provider and department.Microsoft

Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.

Need a hand implementing it?

Find a Consultant for CCCS ITSG-33

Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.

Not sure where to start?

Get Help with CCCS ITSG-33

Tell us what you are trying to put in place. We will point you to the right tool, a consultant who can implement it, or both.

About this data

Pages on this site are compiled with AI from two or more linked sources, rewritten in our words, and reviewed by people in stages. Each record shows its stage and date. Nothing here is legal, audit or tax advice, and policyandcompliance.com accepts no responsibility for errors or for decisions made on it. Read the source, then decide.
How we compile and verify →

Think something is wrong?

corrections@policyandcompliance.com
Tell us the page and what you found. We check it against the source and fix it.
Corrections log →

Want to advertise here?

ads@policyandcompliance.com
A primary ad and a secondary placement, flat fee. Buying one changes nothing else on the page.