Security control categories mapped to Government of Canada data classification levels (Protected A/B).
This reference maps the ITSG-33 Annex 3 control families to GC data classification levels and identifies key controls in each family. Use it during SA&A; initiation to scope your control set.
AC — Access Control
| Control ID | Control Name | Protected A Protected B | |
| AC-2 | Account Management | A | B |
| AC-3 | Access Enforcement | A | B |
| AC-6 | Least Privilege | A | B |
| AC-17 | Remote Access | A | B |
AU — Audit and Accountability
| Control ID | Control Name | Protected A Protected B | |
| AU-2 | Auditable Events | A | B |
| AU-6 | Audit Review & Reporting | A | B |
| AU-9 | Protection of Audit Information | A | B |
| AU-11 | Audit Record Retention | A | B |
IA — Identification and Authentication
| Control ID | Control Name | Protected A Protected B | |
| IA-2 | User Identification & Auth | A | B |
| IA-2(1) | Multi-factor Authentication | — | B |
| IA-5 | Authenticator Management | A | B |
IA-8 Non-Org User Identification A B
SC — System and Communications Protection
| Control ID | Control Name | Protected A Protected B | |
| SC-8 | Transmission Integrity | A | B |
| SC-8(1) | Cryptographic Protection in Transit | A | B |
| SC-28 | Protection of Info at Rest | — | B |
| SC-28(1) | Cryptographic Protection at Rest | — | B |
IR — Incident Response
| Control ID | Control Name | Protected A Protected B | |
| IR-1 | IR Policy & Procedures | A | B |
| IR-4 | Incident Handling | A | B |
| IR-5 | Incident Monitoring | A | B |
| IR-6 | Incident Reporting | A | B |
CM — Configuration Management
| Control ID | Control Name | Protected A Protected B | |
| CM-2 | Baseline Configuration | A | B |
| CM-6 | Configuration Settings | A | B |
| CM-7 | Least Functionality | A | B |
| CM-8 | Information System Component Inventory | A | B |
RA — Risk Assessment
| Control ID | Control Name | Protected A Protected B | |
| RA-2 | Security Categorization | A | B |
| RA-3 | Risk Assessment | A | B |
| RA-5 | Vulnerability Scanning | A | B |
| RA-5(1) | Update Tool Capability | A | B |
SA — System and Services Acquisition
| Control ID | Control Name | Protected A Protected B | |
| SA-9 | External Information System Services | A | B |
| SA-10 | Developer Config Mgmt | — | B |
| SA-11 | Developer Security Testing | — | B |
| SA-12 | Supply Chain Protection | — | B |
■■ Iron Fort maps your controls to the exact ITSG-33 Annex 3 profile for your classification level. Book a free SA&A; readiness assessment at goironfort.com/demo