home / frameworks / itsg-33

// Canadian government guidance

ITSG-33 IT security risk management: A lifecycle approach

The Cyber Centre's lifecycle approach to IT security risk management for federal systems, with a control catalogue based on NIST SP 800-53. Its catalogue, Protected B profile, and departmental annex were replaced in 2026 by the ITSP.10.033 and ITSP.10.036 series.

Canada (federal)

Overview

ITSG-33, IT security risk management: A lifecycle approach, has guided how federal departments manage IT security risk since it took effect on November 1, 2012. It's a suite of publications. An overview sits on top of Annex 1 on departmental risk management activities, Annex 2 on information system risk management, Annex 3A with the security control catalogue, Annex 4A with control profiles, and Annex 5 with a glossary. The catalogue, dated December 30, 2014, is consistent with NIST SP 800-53 Revision 4 and sorts 17 control families into management, technical, and operational classes. The profiles, including the widely used Profile 1 for Protected B, medium integrity, and medium availability, give departments a starting point to tailor.

That structure is being replaced in stages. On March 31, 2026, the Cyber Centre released ITSP.10.033, Security and privacy controls and assurance activities catalogue, which supersedes Annex 3A. It aligns with NIST SP 800-53 Revision 5, has 20 families, and adds program management, personal information handling and transparency, and supply chain risk management. ITSP.10.033-01, a suggested medium impact profile effective April 2, 2026, replaces Annex 4A Profile 1. ITSP.10.036, effective September 14, 2026, replaces Annex 1 with a 6-step organizational cycle that now covers privacy as well as security.

For suppliers, the practical effect is a new control numbering and a broader scope. Contracts, statements of work, and assessment packages that still cite ITSG-33 controls will move to ITSP.10.033 over time. Annex 2 and the overview remain. The Medium cloud control profile used for Protected B cloud services was built on ITSG-33, and its home publication, ITSP.50.103 from May 2020, still refers to that framework.

Who it applies to in Canada

Government of Canada departments and agencies managing IT security risk, and the suppliers, integrators, and cloud providers whose systems handle federal information.

It's the federal government's own risk management framework and control catalogue. Suppliers meet it through contract security requirements, security assessment and authorization of systems they build or host, and the cloud profiles derived from it.

Controls at a glance

ITSG-33 sets risk management activities at departmental and system levels, a control catalogue in families, and profiles, and its successors keep that split.

Departmental activities (Annex 1, now ITSP.10.036)

  • Define organizational security and privacy needs
  • Develop control and activity profiles
  • Allocate controls to systems and services
  • Monitor and assess control performance
  • Maintain authorization
  • Update profiles as threats and needs change

Information system activities (Annex 2)

  • Engage security stakeholders and set concept and planning
  • Analyze requirements and tailor controls
  • Build controls into high-level and detailed design
  • Develop, integrate, and test security
  • Install, assess residual risk, and authorize
  • Operate, maintain, and monitor securely
  • Dispose of IT assets securely

Annex 2 describes 11 phases of the information system security implementation process.

Technical families (ITSP.10.033)

  • Access control (AC)
  • Audit and accountability (AU)
  • Identification and authentication (IA)
  • System and communications protection (SC)

Operational families (ITSP.10.033)

  • Awareness and training (AT)
  • Configuration management (CM)
  • Contingency planning (CP)
  • Incident response (IR)
  • Maintenance (MA)
  • Media protection (MP)
  • Physical and environmental protection (PE)
  • Personnel security (PS)
  • System and information integrity (SI)

Management families (ITSP.10.033)

  • Assessment, authorization, and monitoring (CA)
  • Planning (PL)
  • Program management (PM), new
  • Personal information handling and transparency (PT), new
  • Risk assessment (RA)
  • System and services acquisition (SA)
  • Supply chain risk management (SR), new

ITSP.10.033 lists 20 families; the grouping by class follows the ITSG-33 convention.

Profiles (Annex 4A, now ITSP.10.033-01)

  • Protected B, medium integrity, medium availability baseline
  • Protected A and Secret profiles in ITSG-33
  • Medium impact profile replaces Profile 1
  • Profiles are starting points to tailor

Certification and assessment

A department assesses a system's controls against its tailored profile and an authorizer accepts the residual risk. Suppliers show conformance through system security plans, assessment evidence, and contract security clauses.

Dates to know

2012-11-01
ITSG-33 takes effect
2014-12-30
Annex 3A security control catalogue takes effect
2026-03-31
ITSP.10.033 catalogue supersedes Annex 3A
2026-04-02
ITSP.10.033-01 medium impact profile replaces Annex 4A Profile 1
2026-09-14
ITSP.10.036 supersedes Annex 1

Resources

Official texts and free tools for ITSG-33. Links open the publisher’s site.

Need help? Browse the directory or read the guides.

References

  1. IT security risk management: A lifecycle approach (ITSG-33), Canadian Centre for Cyber Security
  2. ITSP.10.033 foreword, overview, and introduction, Canadian Centre for Cyber Security
  3. ITSP.10.033 controls and assurance activities families, Canadian Centre for Cyber Security
  4. ITSP.10.036 Organizational cyber security and privacy risk management activities, Canadian Centre for Cyber Security
  5. Annex 3A, Security control catalogue (ITSG-33), Canadian Centre for Cyber Security