What Canada CCCS Protected B Cloud Security Profile - ITSP.50.105 Government Cloud Authorization and Security Control Assessment requires
The Government of Canada Security Control Profile for Cloud-Based IT Services (GC Cloud Security Control Profile), also referenced as ITSP.50.105 and published by the Canadian Centre for Cyber Security (CCCS), establishes the minimum security controls that Government of Canada (GC) departments and agencies must verify are implemented when procuring or deploying cloud-based IT services to process, store, or transmit Protected B information; Protected B is the Government of Canada's second-highest information sensitivity classification covering information that, if disclosed, could cause serious injury to an individual, organisation, or government; the Profile defines 327 controls derived from NIST SP 800-53 Rev 5 tailored to the GC context across 20 control families; cloud service providers (CSPs) seeking to host GC Protected B workloads must undergo a Security Assessment and Authorization (SA&A) process managed by the Treasury Board of Canada Secretariat (TBS) and CCCS; CSPs must demonstrate compliance with the GC Cloud Security Control Profile via a third-party Security Assessment Report (SAR) and must be listed on the GC Cloud Brokering Service (CBaaS) Qualified Vendor List before GC departments can contractually engage them for Protected B workloads; the Framework is aligned with the Government of Canada's Cloud Adoption Strategy (TBS Directive on Service and Digital, Appendix G), FedRAMP Moderate baseline (reciprocity exists for some controls), and the CSA Cloud Controls Matrix (CCM) v4.
Pillar: Cloud & SaaS · Authority: Canadian Centre for Cyber Security (CCCS); Treasury Board of Canada Secretariat (TBS); Shared Services Canada (SSC) · Version: 1.0.0 · Last updated:
Primary source: https://www.tbs-sct.canada.ca/pol/doc-eng.aspx?id=32601
SHA-256 integrity: aefcd964e6582de9195421ee1750b1350e8297baa3fd1a16f73e828ad9e0b418
Primary Citations — 5 traced to source
- {"title":"Government of Canada Security Control Profile for Cloud-Based IT Services (GC Cloud Security Control Profile / ITSP.50.105) - Canadian Centre for Cyber Security","url":"https://www.cyber.gc.ca/en/guidance/government-canada-security-control-profile-cloud-based-it-services","section":"327 controls across 20 NIST SP 800-53 Rev 5 control families; 113 CSP-owned controls requiring documentation in the CSP Security Assessment Report; Protected B definition and information classification criteria; Annual continuous monitoring obligations (CA-6, CA-7)"}
- {"title":"TBS Directive on Service and Digital - Appendix G: Standard on Enterprise Information Technology Service Common Configurations - Government of Canada","url":"https://www.tbs-sct.canada.ca/pol/doc-eng.aspx?id=32601","section":"Appendix G (mandatory requirements for cloud adoption including CBaaS Qualified Vendor List, Protected B cloud deployment requirements, Canadian data residency requirements), Section 4.4 (data residency obligations), Section 4.5 (Security Assessment and Authorization requirements)"}
+ 3 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
- Discovery (free): /api/v1/nodes/canada-protected-b-cloud-security-profile-cccs-itsp-50-105.json — 6-field metadata
- Vault (full node): /api/v1/vault/nodes/canada-protected-b-cloud-security-profile-cccs-itsp-50-105.json — full 13-key payload, $0.01 USDC (L402/Skyfire/Direct Base)
- Canonical URL: https://bidda.com/intelligence/canada-protected-b-cloud-security-profile-cccs-itsp-50-105
- Back to registry: Browse all 10,085 compliance nodes