From ITSG-33 to ITSP.10.033
Twelve chapters covering the mandate, categorization, control selection, tailoring, assessment, authorization, and continuous monitoring — with M365 and AI worked examples.
Read the guideAssessment-ready documentation, control profiles, and practitioner training for Government of Canada security assessment & authorization — and the private-sector GRC programs that inherit from them.
The Practitioner's Guide walks through the migration from ITSG-33 to ITSP.10.033. The three starter templates give you assessment-ready shells — SoS, TRA, and SSP — styled to match, so an assessor can pick up any of them and read the same document family.
Twelve chapters covering the mandate, categorization, control selection, tailoring, assessment, authorization, and continuous monitoring — with M365 and AI worked examples.
Read the guideSystem identification, business context, information-type CIA analysis, aggregate categorization, injury statements, and the downstream artifact map.
Open the SoS templateScope, asset register, ITSG-33 threat agents, STRIDE-style scenarios, vulnerabilities mapped to controls, a 3×3 risk matrix, and a residual-risk statement.
Open the TRA templateBoundary, in-scope inventory, inherited services, family-by-family control implementation, POA&M, continuous-monitoring plan, and appendices.
Open the SSP templateSkymeba serves federal delivery teams, integrators, and SMB / enterprise clients who need the same evidence-backed discipline the Government of Canada expects — whether the destination is an ATO, an ISO 27001 certification, or an internal audit.
SSP, TRA, SoS, and SRTM authorship and review for ITSP.10.033 medium-impact systems. Assessor-ready traceability from injury statement to control evidence.
ISO 27001 and ISO 42001 lead-implementer engagements. Control framework mapping, risk register uplift, and management-system integration for hybrid Government of Canada / private-sector estates.
ISO/IEC 42001 lead-implementer engagements, NIST AI RMF baselines, model-risk documentation, and AI-project SA&A worked examples aligned to ITSP.10.033.
Role-based awareness programs, ISO 27001 and ISO 42001 practitioner workshops, secure-development sessions, and academic curricula — every module designed for independent self-study.
Deliverables produced on the same design system you see here — readable in print, on screen, and inside your evidence store. Timezone-flexible for AMER, EMEA, and APAC.
Every statistic sourced. Every recommendation tied to a control or a decision. No performative deliverables, no shelfware.
Grab the full ITSG-33 → ITSP.10.033 practitioner's guide, or pull any of the three starter PDFs individually. Read on-site first if you prefer.