IT Security Risk Management: A Lifecycle Approach (ITSG-33)

With today’s dynamic threat environment and Government of Canada (GC) fiscal constraints, information technology (IT) security can no longer be an afterthought, but rather needs to be a vital component in both your departmental and IT project plans. With that in mind, the ITSG-33 publication has been developed to help government departments ensure security is considered right from the start. By following the principles within this publication, you not only help ensure predictability and cost-effectiveness, you also help ensure that there are no hidden surprises preventing you from obtaining authority to operate and maintaining continued authorization.

Data and Resources

Additional Info

Field Value
Last Updated April 17, 2026, 20:18 (UTC)
Created April 17, 2026, 20:18 (UTC)
contact_email opengov-gouvouvert@cse-cst.gc.ca
criticality_level ["government"]
geographic_scope []
open_canada_collection publication
open_canada_date_published 2012-11-01 00:00:00
open_canada_keywords {"fr": ["gestion des risques"], "en": ["risk management"]}
open_canada_subject ["information_and_communications", "science_and_technology"]
sensitivity_level unrestricted
title_fr La gestion des risques liés à la sécurité des TI : Une méthode axée sur le cycle de vie (ITSG-33)
update_frequency not_planned