ITSG-33 · Canada IT Security Risk Management · Evidence & Implementation Kit
Get your system authorized under ITSG-33, without building the risk-management lifecycle yourself.
Every ITSG-33 element handed to you as an adopt-ready control, from the two-level risk-management process and the management, operational and technical control classes to the PROTECTED B profile and security assessment and authorization, with the evidence an assessor examines.
Authorization-ready in a weekend, not a quarter.
Here is the honest situation. Canadian federal departments and their suppliers manage IT security risk under ITSG-33: a two-level lifecycle, departmental and system, a control catalogue of management, operational and technical controls closely aligned to NIST 800-53, security control profiles like PROTECTED B / Medium / Medium, and a security assessment and authorization process that ends in an authority to operate. Building that process, selecting and implementing the profile, and assembling the assessment evidence, is weeks of work, and a system with an incomplete SA&A package is exactly where the authority to operate stalls.
This Kit removes that build. It is every ITSG-33 element written as an adopt-ready control you personalize in a weekend, with the evidence an assessor examines.
What you get, the moment you buy
34
Elements as adopt-ready controls. Every ITSG-33 element, from the two-level risk-management lifecycle through the management, operational and technical control classes and the profiles, written so you personalize and apply it. SA&A is built in.
34
Evidence-they-examine checklists. For each control, exactly what an assessor examines, plus where authorization stalls, so you close the gap before the SA&A.
1
ITSG-33 Control Matrix, pre-built. Every element in a working spreadsheet, ready to record status and evidence location across the departmental and system levels.
1
Gap & Readiness Assessment. Score each element and the workbook returns your authorization readiness as a single percentage, and exactly what to fix next.
Grounded in ITSG-33, with the two-level risk-management lifecycle, the management, operational and technical control classes, the PROTECTED B profile and security assessment and authorization called out. Editable Word and Excel files.
The authority to operate is what the process is for
Everything in ITSG-33 points at one outcome: an authorizing official granting the authority to operate on the residual risk. This Kit builds the SA&A package, the assessment report, the residual-risk view and the continuous monitoring, so the authority to operate is defensible, not delayed.
What one control looks like
This is the security assessment and authorization step, where the authority to operate is granted. All 34 are built to this depth.
ITSG-10 Assess security controls SA&A
Implement this control
[Department] shall assess the implemented security controls for each information system using a documented assessment plan, testing and examining controls to determine whether they are implemented correctly, operating as intended, and producing the desired outcome, and shall record findings, weaknesses, and recommended remediation in a security assessment report.
Practitioner note.
The assessment produces the objective evidence an authorizer relies on to grant authority to operate.
Evidence an assessor examines
- Security assessment plan defining scope and methods
- Security assessment report with per-control findings
- Test results, examination notes, and interview records
- Weakness list feeding the remediation plan
Common finding they raise: Assessments are sometimes limited to documentation review without technical testing, overstating actual control effectiveness.
Why this is not another template pack
- The evidence is the point. A control you cannot evidence stalls the authorization. This tells you exactly what an assessor examines and where authorization stalls, for every element.
- The lifecycle and profiles built in. The two-level process and the PROTECTED B baseline are written into the controls, the framework a Canadian assessor expects.
- Built on a mapped compliance corpus, not one person's opinion, from a graph of thousands of controls across standards.
- It compounds. ITSG-33 aligns closely with NIST 800-53, so this work maps onto a broader security program if you run one.
Who buys this
Canadian federal departments and the vendors serving them, the security and authorization leads who own ITSG-33, and consultants preparing a system for authority to operate. Whether it is a first authorization or a reauthorization, you save weeks and walk in with the controls and SA&A evidence ready.
By the end of the weekend you will have
✓ An adopt-ready control for all 34 elements
✓ A completed ITSG-33 control matrix
✓ The evidence an assessor examines
✓ Your PROTECTED B profile and SA&A anchored
✓ An authorization-readiness percentage and a fix list
✓ The common authorization stalls designed out
Common questions
Is it really editable? Yes. Word and Excel files you own and adapt. No portal, no subscription.
How does it relate to NIST 800-53? ITSG-33's control catalogue is closely aligned to NIST 800-53, so the controls and evidence carry across if you also work to 800-53.
Does it cover the authority to operate? Yes. Security assessment and authorization, ending in the authority to operate on residual risk, is a core control group.
What is PROTECTED B? A common ITSG-33 security control profile (PROTECTED B / Medium Integrity / Medium Availability). The Kit builds it as a baseline with governed tailoring.
What if it is not for me? A 30-day money-back guarantee.
Do not build the risk-management lifecycle from a blank page.
Every ITSG-33 element is fast to adopt with the Kit. It is instant, and it is guaranteed.
Add it to your cart and be authorization-ready this weekend.
Instant digital download · 30-day money-back guarantee · The Art of Service Pty Ltd, GPO Box 2673, Brisbane QLD 4001 · support@theartofservice.com