Cyber Centre publishes ITSP.10.036, replacing ITSG-33 Annex 1 risk management guidance
Canada's Cyber Centre issues ITSP.10.036, a new organizational cyber security and privacy risk management guideline that supersedes ITSG-33 Annex 1.
The Canadian Centre for Cyber Security (Cyber Centre) has published ITSP.10.036, Organizational cyber security and privacy risk management activities, a practitioner series guideline that supersedes Annex 1 of ITSG-33, IT security risk management: A lifecycle approach. The publication takes effect on September 14, 2026, which is also listed as its first release date.
The document is unclassified and is issued under the authority of the Head of the Cyber Centre. It sits within a broader series titled Cyber security and privacy risk management: A lifecycle approach, and covers the risk management activities that happen at the organizational level, as opposed to the system level. The full text is available from the Cyber Centre at cyber.gc.ca.
The most visible change is in the name. The retired annex was called Departmental IT security risk management activities. The replacement is Organizational cyber security and privacy risk management activities. Two shifts are baked into that title: "departmental" became "organizational," and "privacy" now sits alongside cyber security rather than being someone else's problem down the hall. The Cyber Centre's overview describes the publication as a tool to help security and privacy practitioners protect organizations in compliance with applicable legislation, policies, directives and standards.
The overview also states that the publication outlines a risk management framework designed to ensure organizations effectively manage risks and obtain approval from the appropriate authorities on those risks. In plain terms: identify the risk, treat it or accept it, and get the right person to sign for it. That last step is the one most organizations quietly skip, which is why so many risk registers contain entries that have been "pending approval" since the last hardware refresh.
The source material available at the time of writing includes the foreword, effective date and overview. It does not include the full list of activities, the roles named, or any templates, so this report does not describe them. Whether the new publication changes the activity list from the old annex, or how it relates to the system level guidance in ITSG-33, is not confirmed in the material reviewed. The Cyber Centre invites questions and suggested amendments by email at contact@cyber.gc.ca and by phone at (613) 949-7048 or 1-833-CYBER-88.
The publication does not, in the material reviewed, list a mandated audience. Practically speaking, any organization whose security governance documentation cites ITSG-33 Annex 1 now points at a superseded document. That is a documentation problem before it is a security problem, but auditors tend not to appreciate the distinction.
For identity teams, the addition of privacy to the title is the part worth reading twice. Identity systems are where personal data, access decisions and risk acceptance meet. Every standing exception to an MFA policy, every service account with no named owner, every shared administrative credential that "we'll fix next quarter" is a risk that someone in the organization has implicitly accepted. The framework described in the overview exists to make that acceptance explicit and to put a name against it. The good news is that identity teams usually already have the raw material: access review records, exception logs and provisioning audit trails. The less good news is that the raw material is often sitting in six different tools and one spreadsheet named final_v3_REAL.
Security and identity teams working in or with the Canadian public sector should do three things. First, search internal policy, standards and assessment templates for references to ITSG-33 Annex 1 and plan to update them to ITSP.10.036 once the full text has been reviewed. Second, pull the current list of accepted identity risks (MFA exceptions, privileged access exceptions, orphaned service accounts) and confirm each one has a documented approver who still works there. Third, loop in the privacy office now rather than after the first assessment under the new guidance, because the title just made them your co-author. None of this is glamorous, but a risk register that a real human has actually signed is a rare and beautiful thing, and the teams that have one will find this transition close to painless.
Be the first to comment
Members only: sign up if you have something worth saying.
Want to weigh in? Sign in or create a free account.
No comments yet.