arckit-ca-itsg-33

Generate ITSG-33 Statements of Applicability with security categorization and control profiles.

Updated Jul 24, 2026
One-click install
npx skills add https://github.com/tractorjuice/arckit-kimi --skill arckit-ca-itsg-33
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: arckit-ca-itsg-33
Source: https://github.com/tractorjuice/arckit-kimi/tree/main/skills/arckit-ca-itsg-33
Command: npx skills add https://github.com/tractorjuice/arckit-kimi --skill arckit-ca-itsg-33

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill addresses the high-effort, error-prone process of generating ITSG-33 Statements of Applicability for federal information systems, ensuring compliance with TBS standards.

Core Features & Use Cases

  • Automated Categorization: Calculates system-level security categorization based on C/I/A injury scoring.
  • Control Profile Selection: Maps systems to CSE-published profiles like PBMM or Secret-High with automated tailoring justification.
  • Compliance Reporting: Generates comprehensive documentation including CMVP validation checks, supply chain risk assessments, and continuous monitoring plans.

Quick Start

Invoke the arckit-ca-itsg-33 skill to generate a new Statement of Applicability for the current project directory.

Frequently Asked Questions about arckit-ca-itsg-33

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I generate an ITSG-33 Statement of Applicability for a Canadian federal information system?

You can generate an ITSG-33 Statement of Applicability by invoking the skill in your project directory to automatically evaluate security categorization, map control profiles, and produce TBS-compliant documentation with risk-based tailoring justifications.

What is security categorization based on when assessing ITSG-33 compliance?

Security categorization for ITSG-33 compliance is calculated based on confidentiality, integrity, and availability injury scoring to determine the appropriate system-level security profile for federal information systems.

How do I map a system to a CSE control profile like PBMM with automated tailoring justification?

The skill maps your system to CSE-published profiles such as PBMM or Secret-High by evaluating your security categorization and automatically generating the required risk-based tailoring justifications for compliance.

Can I automate cryptographic module validation and supply chain risk assessments for TBS compliance?

Yes, the skill facilitates the assessment of CMVP cryptographic module validation checks and supply chain security risk assessments, integrating them into your continuous monitoring plans and compliance reporting artifacts.

Do I need any specific dependencies or setup before automating Canadian federal security compliance documentation?

No external dependencies are required to automate Canadian federal security compliance; you simply invoke the skill within your current project directory to begin generating the required ITSG-33 documentation.