Skip to content
Skymeba Cybersecurity Solutions

Turning ITSG-33 practice into ITSP.10.033 evidence.

Assessment-ready documentation, control profiles, and practitioner training for Government of Canada security assessment & authorization — and the private-sector GRC programs that inherit from them.

ITSP.10.033Successor to ITSG-33
Medium profileProtected B / M / M
3 starter templatesSoS + TRA + SSP
Print & webSame design system
The Practitioner's Library

A guide and three matching starter templates.

The Practitioner's Guide walks through the migration from ITSG-33 to ITSP.10.033. The three starter templates give you assessment-ready shells — SoS, TRA, and SSP — styled to match, so an assessor can pick up any of them and read the same document family.

Practitioner's Guide

From ITSG-33 to ITSP.10.033

Twelve chapters covering the mandate, categorization, control selection, tailoring, assessment, authorization, and continuous monitoring — with M365 and AI worked examples.

Read the guide
Starter template

Statement of Sensitivity

System identification, business context, information-type CIA analysis, aggregate categorization, injury statements, and the downstream artifact map.

Open the SoS template
Starter template

Threat & Risk Assessment

Scope, asset register, ITSG-33 threat agents, STRIDE-style scenarios, vulnerabilities mapped to controls, a 3×3 risk matrix, and a residual-risk statement.

Open the TRA template
Starter template

System Security Plan

Boundary, in-scope inventory, inherited services, family-by-family control implementation, POA&M, continuous-monitoring plan, and appendices.

Open the SSP template
Services

Four practices, one delivery style.

Skymeba serves federal delivery teams, integrators, and SMB / enterprise clients who need the same evidence-backed discipline the Government of Canada expects — whether the destination is an ATO, an ISO 27001 certification, or an internal audit.

01

Security assessment & authorization

SSP, TRA, SoS, and SRTM authorship and review for ITSP.10.033 medium-impact systems. Assessor-ready traceability from injury statement to control evidence.

02

GRC advisory

ISO 27001 and ISO 42001 lead-implementer engagements. Control framework mapping, risk register uplift, and management-system integration for hybrid Government of Canada / private-sector estates.

03

AI security & governance

ISO/IEC 42001 lead-implementer engagements, NIST AI RMF baselines, model-risk documentation, and AI-project SA&A worked examples aligned to ITSP.10.033.

04

Training & enablement

Role-based awareness programs, ISO 27001 and ISO 42001 practitioner workshops, secure-development sessions, and academic curricula — every module designed for independent self-study.

05

Remote by default

Deliverables produced on the same design system you see here — readable in print, on screen, and inside your evidence store. Timezone-flexible for AMER, EMEA, and APAC.

06

Straight talk

Every statistic sourced. Every recommendation tied to a control or a decision. No performative deliverables, no shelfware.

See the consulting services About Skymeba
Download the library

The practitioner's guide and three matching starter templates.

Grab the full ITSG-33 → ITSP.10.033 practitioner's guide, or pull any of the three starter PDFs individually. Read on-site first if you prefer.