What Canada CCCS Protected B Cloud Security Profile - ITSP.50.105 Government Cloud Authorization and Security Control Assessment requires
The Government of Canada Security Control Profile for Cloud-Based IT Services (GC Cloud Security Control Profile), also referenced as ITSP.50.105 and published by the Canadian Centre for Cyber Security (CCCS), establishes the minimum security controls that Government of Canada (GC) departments and agencies must verify are implemented when procuring or deploying cloud-based IT services to process, store, or transmit Protected B information; Protected B is the Government of Canada's second-highest information sensitivity classification covering information that, if disclosed, could cause serious injury to an individual, organisation, or government; the Profile defines 327 controls derived from NIST SP 800-53 Rev 5 tailored to the GC context across 20 control families; cloud service providers (CSPs) seeking to host GC Protected B workloads must undergo a Security Assessment and Authorization (SA&A) process managed by the Treasury Board of Canada Secretariat (TBS) and CCCS; CSPs must demonstrate compliance with the GC Cloud Security Control Profile via a third-party Security Assessment Report (SAR) and must be listed on the GC Cloud Brokering Service (CBaaS) Qualified Vendor List before GC departments can contractually engage them for Protected B workloads; the Framework is aligned with the Government of Canada's Cloud Adoption Strategy (TBS Directive on Service and Digital, Appendix G), FedRAMP Moderate baseline (reciprocity exists for some controls), and the CSA Cloud Controls Matrix (CCM) v4.
Pillar: Cloud & SaaS · Authority: Canadian Centre for Cyber Security (CCCS); Treasury Board of Canada Secretariat (TBS); Shared Services Canada (SSC) · Version: 1.0.0 · Last updated:
Primary source: https://www.tbs-sct.canada.ca/pol/doc-eng.aspx?id=32601
SHA-256 integrity: cef2c6d18d1f0567a2d73e538d9d6b499ff286580f4a4898b8ec4daa140a43e5
Primary Citations — 5 traced to source
- 327 controls across 20 NIST SP 800-53 Rev 5 control families; 113 CSP-owned controls requiring documentation in the CSP Security Assessment Report; Protected B definition and information classification criteria; Annual continuous monitoring obligations (CA-6, CA-7) — Government of Canada Security Control Profile for Cloud-Based IT Services (GC Cloud Security Control Profile / ITSP.50.105) - Canadian Centre for Cyber Security
- Appendix G (mandatory requirements for cloud adoption including CBaaS Qualified Vendor List, Protected B cloud deployment requirements, Canadian data residency requirements), Section 4.4 (data residency obligations), Section 4.5 (Security Assessment and Authorization requirements) — TBS Directive on Service and Digital - Appendix G: Standard on Enterprise Information Technology Service Common Configurations - Government of Canada
+ 3 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
- Discovery (free): /api/v1/nodes/canada-protected-b-cloud-security-profile-cccs-itsp-50-105.json — 6-field metadata
- Vault (full node): /api/v1/vault/nodes/canada-protected-b-cloud-security-profile-cccs-itsp-50-105.json — full 13-key payload, $0.01 USDC (L402/Skyfire/Direct Base)
- Canonical URL: https://bidda.com/intelligence/canada-protected-b-cloud-security-profile-cccs-itsp-50-105
- Back to registry: Browse all 10,099 compliance nodes