home / guides / itsg-33-security-risk-management

Frameworks and controls · Canadian Centre for Cyber Security

ITSG-33 IT security risk management

The Government of Canada lifecycle approach to managing IT security risk, widely referenced in public sector work.

Who this applies to

Federal departments, their suppliers, and organizations that align to Government of Canada security practice.

What to know

  • It sets out a lifecycle for managing IT security risk, from planning and design through operation and disposal.
  • It uses a catalog of security controls and profiles, so requirements can be tailored to the sensitivity of a system.
  • Public sector security assessments and many supplier requirements still point back to it.

What to do

  • Confirm which control profile your contract or department requires.
  • Keep assessment evidence organized by control, because reviewers ask for it that way.