C3SA FIELD GUIDE

ITSG-33 / PBMM READINESS GUIDE

ITSG-33 is the Canadian Centre for Cyber Security's IT security risk management guidance for Government of Canada systems. PBMM is a common security control profile for systems handling Protected B information with medium integrity and availability needs. This guide covers the preparation that makes assessment go smoothly.

THE GUIDE

SIX STEPS TO ASSESSMENT READINESS.

Most assessment delays come from unclear scope, undocumented inheritance and missing evidence. All three can be fixed before the assessor arrives.

01

Define system scope and security boundary

Assessment starts with a clear boundary: which components, data flows, users, interconnections and providers are part of the system being authorized.

Questions to ask

  • What is inside the boundary, and what connects to it?
  • Which data at which classification does the system handle?
  • Is the boundary documented in an architecture diagram?
02

Establish control applicability and ownership

Tailor the control profile to the system and assign an owner to each applicable control, so nothing falls between teams.

Questions to ask

  • Which controls in the profile apply to this system?
  • Who owns each control?
  • Are tailoring decisions documented and justified?
03

Map inherited, shared and system-specific controls

Many controls are inherited from a cloud provider, a departmental service or a common platform. Document exactly what is inherited and what remains your responsibility.

Questions to ask

  • Which controls do we inherit, and from whom?
  • Is there evidence the provider actually implements them?
  • Where is responsibility shared, and how is it split?
04

Build evidence before assessment

Assessors need evidence that controls are implemented and operating: configurations, procedures, logs and test results mapped to each requirement, typically in a security requirements traceability matrix (SRTM).

Questions to ask

  • Can we show evidence for every applicable control?
  • Is our SRTM complete and current?
  • Is evidence dated and attributable?
05

Prioritize gaps by mission and risk

Not every gap is equal. Rank gaps by their effect on the system's mission and on the confidentiality, integrity and availability of Protected B information.

Questions to ask

  • Which gaps create the most risk to the mission?
  • Which can be closed quickly?
  • Which require architectural change?
06

Create an implementation roadmap

Turn gaps into a sequenced plan with owners, effort, dependencies and dates, so the authorizing official can see a credible path to acceptable risk.

Questions to ask

  • Does every gap have an owner and a target date?
  • Which items must be closed before authorization?
  • How will residual risk be communicated?

Last reviewed September 24, 2026. This guide is general information, not legal advice. Print or save this page to use it as a workshop handout or pre-engagement checklist.

NEXT STEP

MOVE FROM CHECKLIST TO EVIDENCE.

C3SA can help validate the current state, identify material gaps, define the target state and support implementation, testing and readiness.

UNDER ATTACK? CYBERFIRE →