Se rendre au contenu

Sécurité et conformité

Lynx Compliance - ITSG-33 / PBMM

Government of Canada ITSG-33 with the PBMM profile and the thirteen cloud guardrails, overlaying NIST SP 800-53 so the shared control catalogue is referenced rather than duplicated.

lynx_compliance_itsg33 · v19.0.1.0.0 · Complément Bêta

Ce que cela résout

Lynx Compliance - ITSG-33 / PBMM

ITSG-33 is how the Government of Canada does IT security risk management, and PBMM - Protected B, Medium Integrity, Medium Availability - is the profile most departmental systems and most suppliers to departments end up against. Selling to the GC generally means producing evidence in this shape.

The Annex 3A control catalogue is closely modelled on NIST SP 800-53 and uses the same family identifiers. Re-seeding it would duplicate the 296 controls already shipped by lynx_compliance_nist_80053 and force every control to be assessed twice, so this pack does not do that. It ships what is genuinely Canadian and genuinely absent from 800-53:

  • the departmental and system-level risk management activities from Annexes 1 and 2, which are process obligations rather than controls;

  • the PBMM profile as tailoring decisions, including the Protected B handling requirements;

  • the thirteen GC cloud guardrails, which are the concrete checks a department is held to when standing up a cloud environment;

  • authorisation and continuous monitoring.

Everything that is simply an 800-53 control is referenced by code, so a supplier holding an 800-53 profile carries it straight over.

Key Features

  • 41 controls across five functions - departmental risk management, system lifecycle, PBMM profile, cloud guardrails, and authorisation.

  • The thirteen cloud guardrails by their official numbering - GC-GR-01 through GC-GR-13, so a department can cite them the way its reviewers do.

  • Data location treated as enforcement, not policy - guardrail 05 is assessed against region restrictions pulled from the cloud connector, including backups, logs and support data.

  • Protected B handling across the lifecycle - labelling, screening-based access, approved cryptography and sanitisation, rather than a single "handle appropriately" control.

  • Overlay, not a duplicate - no control code collides with the 800-53 pack, so nothing is assessed twice.

  • Inheritance treated sceptically - a control claimed as inherited from a provider has its own control requiring the claim be verified.

Integrates With

  • lynx_compliance_nist_80053 - the shared control catalogue this overlays; install both for the crosswalk to work.

  • lynx_compliance - CSF 2.0 profiles cross-reference through the shared 800-53 mappings.

  • lynx_compliance_connector_patrii - Canadian region enforcement is exactly what guardrail 05 asks a cloud connector to evidence.

Essayer Lynx Compliance - ITSG-33 / PBMM de votre équipe.

Essai gratuit, sans carte de crédit. Parlez à l'équipe des ventes quand vous êtes prêt.