Skip to main content
Home · Standards · ITSG-33 — Canadian Centre for Cyber Security IT Security Risk Management
Standard · ITSG-33

ITSG-33 — Canadian Centre for Cyber Security IT Security Risk Management

IT Security Guidance Publication 33 (ITSG-33) — IT Security Risk Management: A Lifecycle Approach — is the foundational risk-management framework for the Government of Canada, published by the Canadian Centre for Cyber Security (a part of the Communications Security Establishment). Federal departments procuring ITAD services typically reference ITSG-33 in their RFPs. For Maxicom federal-department engagements, ITSG-33 alignment is the operational baseline.

ITSG-33 scope and application

ITSG-33 applies to all federal departments and agencies procuring IT services where cyber risk is in scope. ITAD engagements are in scope. The framework references NIST SP 800-53 controls plus Canadian-government-specific controls; the catalogue is harmonised with U.S. federal practice for cross-border interoperability.

Operator vetting under ITSG-33

ITSG-33 requires personnel security commensurate with the data classification handled. Federal Maxicom engagements use cleared operators (Reliability or Secret clearance per engagement), background-checked, NDA-bound, escort-trained. Per-engagement cleared-operator pool documented.

Federal department engagement profile

Federal departments produce predictable retiring volumes through Public Services and Procurement Canada (PSPC) procurement vehicles. Programme-level engagement model. NDA-bound. Witness destruction standard. On-site or cleared-area destruction protocols.

Treasury Board IT Asset Disposition Policy

Treasury Board of Canada Secretariat issues IT Asset Disposition guidance that complements ITSG-33. Asset categorisation, sanitisation, environmental disposition. Maxicom certificates reference both ITSG-33 and the Treasury Board guidance for federal engagements.

Regulator stack — by region Every Maxicom certificate is admissible against the full stack simultaneously UNIVERSAL NIST SP 800-88 Rev. 1 · IEEE 2883-2022 · DoD 5220.22-M · NAID-grade Protocol 🇮🇳 INDIA INR · IST PRIVACY DPDPA 2023 BFSI RBI IT-Risk SECTOR-SPECIFIC SEBI · IRDAI · CERT-In · CPCB 🇨🇦 CANADA CAD · EST PRIVACY PIPEDA · Quebec Law 25 BFSI OSFI Guideline B-13 SECTOR-SPECIFIC PIPA (AB/BC) · PHIPA · ITSG-33 🇸🇬 SINGAPORE SGD · SGT PRIVACY PDPA Section 24 BFSI MAS TRM SECTOR-SPECIFIC IMDA · NEA Resource Sustainability Act 🇦🇪 UAE AED · GST PRIVACY UAE PDPL Article 21 BFSI Central Bank UAE SECTOR-SPECIFIC TDRA · DIFC DPL · ADGM · NESA
Reviewed by the Maxicom compliance desk. Last updated April 2026.
Operates to NIST 800-88 · PIPEDA · OSFI B-13 · NAID-grade · IEEE 2883-2022
References

Authoritative references

Primary sources for the standards and frameworks referenced on this page. Maxicom maps every engagement to these recognised authorities.

Frequently asked questions

Frequently asked questions

Are your operators cleared for federal Canadian engagements?

Yes — Reliability or Secret clearance per engagement profile. Cleared-operator pool documented; per-engagement assignment.

How does ITSG-33 compose with PIPEDA?

PIPEDA applies to personal information regardless of whether ITSG-33 also applies; ITSG-33 covers the broader cyber risk management. Both compose; Maxicom certificates satisfy both.

What about classified-material destruction?

On-site cleared-area destruction with witness; per-asset certificate; chain-of-custody under cleared protocols. Specific to engagement classification level.

When you are ready

Send the asset list. We will send the number.

A photograph of the rack works. A spreadsheet works better. CAD settlement, against PO.

purchase@maxicom.ca · per engagement SLA