Security Architecture

ITSP.10.033 vs NIST SP 800-53 Rev. 5

What actually differs between the Canadian catalogue and its American parent — and what it costs you to cross the border

Security ArchitectureGovernment of CanadaRisk & Compliance

If you design, build or assess secure systems in North America, NIST SP 800-53 is probably your default reference. For work touching the Government of Canada, the broader public sector or regulated Canadian enterprise, the Canadian Centre for Cyber Security maintains its own: ITSP.10.033, Security and privacy controls and assurance activities catalogue.1

ITSP.10.033 is not a competing standard. It is Canada's tailored adaptation of NIST SP 800-53 Rev. 5, and it says so.16 But the differences that remain sit at exactly the level that changes an architecture review — how controls are structured, how assurance is expressed, and what evidence an assessor expects to see.

Executive Comparison#

DimensionNIST SP 800-53 Rev. 5CCCS ITSP.10.033
Issuing authorityNIST (United States)Canadian Centre for Cyber Security
Governance scopeUS federal (FISMA), FedRAMP, global enterpriseGovernment of Canada, Crown corporations, Canadian critical sectors
Control families2020 — identical mapping
Catalogue items1,000+ base controls and enhancements1,000+ — NIST baseline plus Canadian extensions
Assurance modelSplit: SP 800-53 for controls, SP 800-53A for assessment proceduresUnified: controls and assurance activities in one catalogue
National extensionsNone400-seriesSA-400, IA-04(400)
Guidance layersUS law, OMB memoranda, executive ordersDual-layered: general discussion plus GC discussion
EffectiveRev. 5 (2020), updated31 March 2026, superseding ITSG-33 Annex 3A

Shared DNA: The 20 Control Families#

Both catalogues use the same taxonomy, and both fully absorb the modernized disciplines Rev. 5 introduced — Supply Chain Risk Management (SR) and privacy engineering under Personal Information and Transparency (PT).

The shared twenty-family taxonomy Twenty control families, identical in NIST SP 800-53 Revision 5 and ITSP.10.033, grouped for reading. Identity and access: AC access control, IA identification and authentication, PS personnel security, AT awareness and training. Operations and defence: AU audit and accountability, IR incident response, RA risk assessment, SI system and information integrity, CA assessment and monitoring, MA maintenance, MP media protection, PE physical and environmental protection. Architecture and governance: SC system and communications protection, CM configuration management, SR supply chain risk management, PT personal information and transparency, CP contingency planning, PL planning, PM program management, SA system and services acquisition. THE SHARED 20-FAMILY TAXONOMY — IDENTICAL IN BOTH CATALOGUES Same identifiers, same names. A control reference reads the same in either. Identity & Access 4 AC Access Control IA Identification & Auth. PS Personnel Security AT Awareness & Training Operations & Defence 8 AU Audit & Accountability IR Incident Response RA Risk Assessment SI System & Information Integrity CA Assessment & Monitoring MA Maintenance MP Media Protection PE Physical & Environmental Architecture & Governance 8 SC System & Comms Protection CM Configuration Management SR Supply Chain Risk Management PT Personal Info & Transparency CP Contingency Planning PL Planning PM Program Management SA System & Services Acquisition
Figure 1: The twenty families, grouped for reading. The grouping is editorial; the identifiers and names are identical in both catalogues.

Scroll the diagram sideways to see every profile →

For anyone migrating from ITSG-33, this is the quiet headline. The old Annex 3A catalogue predated Rev. 5, so PM, PT and SR are new arrivals in the Canadian catalogue — and a control library built against the legacy annex has three families it has never scoped.1

The Four Structural Differences#

1. Assurance activities live in the same catalogue#

In the NIST ecosystem, control requirements live in SP 800-53 and the procedures for assessing them — examine, interview, test — live in a separate publication, SP 800-53A.7

ITSP.10.033 organizes controls and assurance activities into the same twenty families, in the same catalogue, with the same entry structure. An assurance activity is defined as:

[A] description of tasks, such as engineering tasks, documentation content requirements, and assessment tasks, to be completed as part of a project that increases the confidence that controls are appropriately implemented.

ITSP.10.033

That is the successor to what ITSG-33 called security assurance requirements, and it is the reason the catalogue's full title names both halves.3

Which publication carries which layer, NIST versus CCCS Three layers compared across two ecosystems. What to implement: NIST uses SP 800-53 Revision 5; CCCS uses ITSP.10.033. What to do to keep a control effective, meaning engineering, documentation and assessment tasks: NIST has no separate concept and folds this into the controls, while CCCS carries assurance activities in ITSP.10.033 itself, in the same twenty families. How an assessor tests a control, meaning examine, interview and test procedures: NIST publishes SP 800-53A Revision 5, while CCCS has not yet published an equivalent. ITSP.10.033 unifies controls and assurance activities in one catalogue but does not replace SP 800-53A; it states that it creates a foundation for developing assessment methods and procedures. WHICH PUBLICATION CARRIES WHICH LAYER NIST UNITED STATES CCCS CANADA What to implement The safeguard itself SP 800-53 Rev. 5 ITSP.10.033 What to do to keep it effective Engineering, documentation and assessment tasks No separate concept — folded into the controls ITSP.10.033 — same catalogue, same 20 families How an assessor tests it Examine · interview · test procedures SP 800-53A Rev. 5 Not yet published ITSP.10.033 unifies controls and assurance activities in one catalogue. It does not replace SP 800-53A — it states that it "creates a foundation for developing assessment methods and procedures".
Figure 2: Three layers, two ecosystems. The unified catalogue is real; the missing assessment-procedure layer is the part that catches teams out.

Scroll the diagram sideways to see every profile →

2. The semantic shift: controls versus activities#

NIST puts every operational obligation under the single word control. ITSP.10.033 draws a deliberate line, and states it plainly: "We refer to assurance-related 'controls' as activities, rather than controls."1

ControlsAssurance activities
What it isA safeguard that prevents, detects or mitigates riskEngineering, documentation and assessment tasks
AnswersIs the risk addressed?Do we have confidence it is, and that it stays that way?
Example shapeAutomated account lockout after failed attemptsThe review cadence, the design documentation, the test that proves the lockout fires

Adopt the vocabulary in your findings. An assessor writing "control not met" against an assurance activity is describing the wrong kind of thing, and it shows.

3. Canadian extensions: the 400-series#

Legacy ITSG-33 numbered Canadian enhancements from 100 — AC-2(101) and the like. As NIST expanded its own catalogue, collisions became inevitable.

ITSP.10.033 moves every Canadian-specific enhancement into the 400+ range, SA-400 and IA-04(400) among them, explicitly to avoid colliding with NIST numbering.1

4. Dual-layered guidance#

NIST discussion sections are framed around US federal regulation. ITSP.10.033 splits its discussion in two:

  • General discussion — technology-agnostic implementation advice, useful to any enterprise or municipality.
  • GC discussion — "specifically directed to a GC audience as it addresses requirements derived from laws, policies, directives, and standards that GC departments and agencies need to comply with."2

In practice the GC discussion is where a control stops being advisory and starts pointing at the Policy on Government Security, the Directive on Service and Digital and the Privacy Act.

Anatomy of a Catalogue Entry#

Knowing the entry structure tells you where to look when a control is ambiguous. Every ITSP.10.033 entry carries:2

SectionWhat it gives you
Identifier and namee.g. CP-09 System backup
Control or activity statementThe requirement, split into lettered parts — A., B., C.
Discussion (optional)Implementation guidance, split into general and GC layers
Related controls and activitiesWhat else in the catalogue supports or depends on this
Enhancements (optional)Additional capability, numbered (01), (02)… and 400+ for Canadian additions
ReferencesThe laws, policies, directives and standards behind it

The lettered parts matter for assessment: a control with statements A through D has four things to evidence, and "partially met" without saying which letter is not a finding anybody can act on.

Crossing the Border#

If your platform already meets NIST SP 800-53 Rev. 5 Moderate or FedRAMP Moderate, the technical foundation largely transfers. What remains is not re-engineering — it is evidence and sovereignty.

  1. Start from a NIST Rev. 5 or FedRAMP Moderate baselineThe control engineering is substantially the same
  2. Re-map evidence to assurance activitiesSame safeguard, different proof obligations
  3. Filter for 400-series enhancementsThe Canadian delta, isolated in one pass
  4. Re-read the GC discussion on every in-scope controlWhere advisory becomes mandatory
  5. Verify cryptography against CCCS-approved algorithmsITSP.40.111 governs, not FIPS alone
  6. Write the assessment procedures yourselfThere is no Canadian SP 800-53A

Conclusion#

ITSP.10.033 is best read as NIST SP 800-53 Rev. 5 with three deliberate Canadian edits: assurance folded in beside the controls, sovereign requirements isolated at 400, and every control given a second layer of guidance that ties it to Canadian law.

Building to NIST Rev. 5 delivers the foundation. Achieving ITSP.10.033 compliance is largely an exercise in aligning operational evidence with CCCS assurance criteria and sovereign policy extensions — plus, for now, writing the assessment procedures that the catalogue has not yet published.

Frequently Asked Questions#

Is ITSP.10.033 a different standard from NIST SP 800-53?#

No. It is an adapted version of NIST SP 800-53 Rev. 5, reflecting Canadian business and legislative requirements. The twenty control families and their identifiers are identical, so AC-2 means the same thing in both. The differences are in packaging, national extensions and guidance layers.

Does ITSP.10.033 replace NIST SP 800-53A?#

No. ITSP.10.033 contains assurance activities — tasks you perform to increase confidence a control is correctly implemented. It does not contain assessment procedures in the SP 800-53A sense. The catalogue states it "creates a foundation for developing assessment methods and procedures", which means departments still define their own.

What is the 400-series?#

Canadian-specific controls and enhancements, numbered from 400 upward — SA-400, IA-04(400) — to avoid collision with NIST numbering as the US catalogue expanded. Legacy ITSG-33 used a 100-series for the same purpose. Any 400-series identifier signals a requirement with no NIST equivalent.

What is the difference between a control and an assurance activity?#

A control is a safeguard that prevents, detects or mitigates risk. An assurance activity is the engineering, documentation or assessment work that gives confidence the control is properly implemented and stays that way. ITSP.10.033 makes the distinction explicit, stating that it refers to assurance-related items as activities rather than controls.

If we already hold FedRAMP Moderate, what is left to do for Canada?#

The control engineering largely transfers. What remains is re-mapping evidence onto assurance activities, assessing against the 400-series enhancements, re-reading the GC discussion on in-scope controls, verifying cryptography against CCCS-approved algorithms rather than FIPS alone, and writing your own assessment procedures.

What changed for teams coming from ITSG-33?#

ITSP.10.033 superseded ITSG-33 Annex 3A on 31 March 2026. Beyond the renumbering to 400, the catalogue adds the PM, PT and SR families that Rev. 5 introduced — so a control library built against the legacy annex has three families it has never scoped. ITSG-33's other annexes were not withdrawn.

References#

  1. ITSP.10.033 — Security and privacy controls and assurance activities catalogue Canadian Centre for Cyber Security · https://www.cyber.gc.ca/en/guidance/cyber-security-privacy-risk-management/itsp10033
  2. ITSP.10.033 — Concepts and structure Canadian Centre for Cyber Security · https://www.cyber.gc.ca/en/guidance/cyber-security-privacy-risk-management/itsp10033/concepts-structure
  3. ITSP.10.033 — The controls and assurance activities families Canadian Centre for Cyber Security · https://www.cyber.gc.ca/en/guidance/cyber-security-privacy-risk-management/itsp10033/controls-assurance-activities-families
  4. ITSG-33 Annex 3A — Security control catalogue (superseded) Canadian Centre for Cyber Security · https://www.cyber.gc.ca/en/guidance/annex-3a-security-control-catalogue-itsg-33
  5. ITSP.40.111 — Cryptographic algorithms for unclassified, Protected A and Protected B information Canadian Centre for Cyber Security · https://www.cyber.gc.ca/en/guidance/cryptographic-algorithms-unclassified-protected-and-protected-b-information-itsp40111
  6. NIST SP 800-53 Rev. 5 — Security and Privacy Controls for Information Systems and Organizations National Institute of Standards and Technology · https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final
  7. NIST SP 800-53A Rev. 5 — Assessing Security and Privacy Controls in Information Systems and Organizations National Institute of Standards and Technology · https://csrc.nist.gov/pubs/sp/800/53/a/r5/final
  8. Policy on Government Security Treasury Board of Canada Secretariat · https://www.tbs-sct.canada.ca/pol/doc-eng.aspx?id=16578
On this page

Zeeshan Mahmood

Security Assessment, Architecture & AI

Zeeshan is a security advisor and senior IT security risk analyst who works at the seam between assessment and design. He runs the full authorization lifecycle — security categorization, threat and risk assessment, control profile selection, and the evidence behind an authority to operate — and designs the solution, cloud and security architecture that has to survive it, from landing zones and network segmentation to Zero Trust and cross-domain solutions. His current focus includes AI security and the assessment of AI-enabled systems. He holds CISSP, CCSP, CISM, CKS and Azure Solutions Architect Expert, and leads assurance methodology at CtrlFort.

Run this framework against your own control library.

CtrlFort Assess maps cloud control profiles, ITSG-33 baselines and certification regimes to one shared evidence base — so a control you evidence once satisfies every obligation it maps to.