← Back to Resources
Free Checklist Checklist ITSG-33

ITSG-33 Annex 3 Control Quick Reference

Security control categories mapped to Government of Canada data classification levels (Protected A/B).

ITSG-33 Annex 3 Control Quick Reference

IRON FORT SOLUTIONS · 2026

Instant email delivery — no waiting
Written by compliance professionals
Updated for 2026 regulatory changes
No credit card required

Get Free Access

Enter your work email and we'll send the download link immediately.

Your info is never sold or shared. Unsubscribe anytime.

Checklist · ITSG-33 · Read in full

Security control categories mapped to Government of Canada data classification levels (Protected A/B).

This reference maps the ITSG-33 Annex 3 control families to GC data classification levels and identifies key controls in each family. Use it during SA&A; initiation to scope your control set.

AC — Access Control

Control IDControl NameProtected A Protected B
AC-2Account ManagementAB
AC-3Access EnforcementAB
AC-6Least PrivilegeAB
AC-17Remote AccessAB

AU — Audit and Accountability

Control IDControl NameProtected A Protected B
AU-2Auditable EventsAB
AU-6Audit Review & ReportingAB
AU-9Protection of Audit InformationAB
AU-11Audit Record RetentionAB

IA — Identification and Authentication

Control IDControl NameProtected A Protected B
IA-2User Identification & AuthAB
IA-2(1)Multi-factor AuthenticationB
IA-5Authenticator ManagementAB

IA-8 Non-Org User Identification A B

SC — System and Communications Protection

Control IDControl NameProtected A Protected B
SC-8Transmission IntegrityAB
SC-8(1)Cryptographic Protection in TransitAB
SC-28Protection of Info at RestB
SC-28(1)Cryptographic Protection at RestB

IR — Incident Response

Control IDControl NameProtected A Protected B
IR-1IR Policy & ProceduresAB
IR-4Incident HandlingAB
IR-5Incident MonitoringAB
IR-6Incident ReportingAB

CM — Configuration Management

Control IDControl NameProtected A Protected B
CM-2Baseline ConfigurationAB
CM-6Configuration SettingsAB
CM-7Least FunctionalityAB
CM-8Information System Component InventoryAB

RA — Risk Assessment

Control IDControl NameProtected A Protected B
RA-2Security CategorizationAB
RA-3Risk AssessmentAB
RA-5Vulnerability ScanningAB
RA-5(1)Update Tool CapabilityAB

SA — System and Services Acquisition

Control IDControl NameProtected A Protected B
SA-9External Information System ServicesAB
SA-10Developer Config MgmtB
SA-11Developer Security TestingB
SA-12Supply Chain ProtectionB

■■ Iron Fort maps your controls to the exact ITSG-33 Annex 3 profile for your classification level. Book a free SA&A; readiness assessment at goironfort.com/demo

Want the formatted PDF?

You've just read the whole thing. If you'd like the designed, printable version to share with your team or attach to an audit file, we'll email it over.

Email Me the PDF →