Security controls — the SA&A control catalogue (ITSG-33 / NIST 800-53) used in Security assessments, pack-seeded and tenant-extensible
Last updated: July 24, 2026 by Steve
Security Controls
The Security controls catalogue is the library of security controls your Security (SA&A) assessments draw on — the ITSG-33 / NIST 800-53 control set that a System Security Plan (SSP) is built from. It is pre-seeded by configuration packs and extensible, so your assessors select and implement controls from a catalogue that matches your control profile rather than typing them out each time.
This catalogue feeds Security assessments specifically (the SA&A / Authority-to-Operate workflow). It is separate from the exemptions used when redacting documents.

Where to Find It
Open Settings from the app toolbar and choose Security controls in the Privacy configuration group. This group is visible only to users who hold the relevant privacy configure permission.
A Control
Each catalogue entry describes one control:
| Field | What it holds |
|---|---|
| Catalog code | The catalogue the control belongs to (for example, ITSG-33 or NIST 800-53). |
| Family | The control family (for example, AC — Access Control, AU — Audit & Accountability). |
| Control code | The control's identifier within the catalogue (for example, AC-2). |
| Title | The control's name. |
| Control text | The control statement itself. |
| Profiles | The control profiles the control belongs to (for example, PBMM) — profile membership is what drives which controls a Security assessment spawns. |
| Enhancement | Marks a control enhancement (a sub-control) rather than a base control. |
| Enabled | Only enabled controls are offered when building an assessment. |
Profiles Drive the SSP
A Security assessment is categorized (for example, to the PBMM profile), and that categorization determines which controls are pulled from this catalogue into the assessment's System Security Plan. Maintaining accurate profile membership here is what makes the SSP spawn the right control set automatically. See Assessment types and Assessment templates for how the Security engine is configured, and the GC Security Controls Reference for the ITSG-33 mapping.
Seeded by Configuration Packs, Extensible by You
The shipped catalogue is pack-seeded (its provenance is recorded on each control), and you can add your own controls or enhancements for frameworks the packs don't cover. When the optional AI Assist component is deployed, a control's guidance text can also ground assessment answer suggestions — but the catalogue is useful on its own, with or without AI.
Managing Controls
- Add — Click Add control, choose the catalogue and family, enter the control code, title, and control text, set profile membership, and save.
- Edit — Open a control to update its text or profile membership.
- Enable / disable — Disable a control to remove it from assessment selection without deleting it.