Security Assessment

SA&A Terminology Explained: Controls, Findings, Risks, SARs, POA&Ms and ATOs

The vocabulary of security assessment — what each term means, what it does not, and where Canadian and American usage part ways

Security AssessmentGovernment of CanadaRisk & Compliance

An assessor writes "finding". The system owner reads "risk". The executive reads "problem we must fix now". Three people, one word, and a meeting spent disagreeing about vocabulary instead of about the system.

Precision here is not pedantry. It is what lets a finding survive challenge, a risk reach the right owner, and an authorization mean what it says.

Every term in SA&A names a different thing, owned by a different person. Blur two of them and you have moved a decision without noticing.

The Control Layer#

TermMeansDoes not mean
ControlA safeguard that prevents, detects or mitigates riskA policy that describes one
Control enhancementAn added capability on top of a base control, numbered (01), (02)…A separate control
Assurance activityA task that increases confidence a control is properly implementedA control
Control statementThe requirement, split into lettered parts A., B., C.One requirement

The last row matters more than it looks. A control with four lettered parts is four things to evidence, and "partially met" without a letter is not a finding anybody can act on.2

The third row is a deliberate change in the current Canadian catalogue:

We refer to assurance-related "controls" as activities, rather than controls.

ITSP.10.033

An assurance activity — an engineering task, a documentation requirement, an assessment task — is something you do to gain confidence.1 A control is something the system has. Writing "control not met" against an assurance activity describes the wrong kind of thing.

The Assessment Layer#

The assessment chain Five linked steps, each with an owner. Evidence, what was observed, and observation, what it seems to mean, both belong to the assessor. Finding, a judgment against a requirement, also belongs to the assessor. Risk, what it means for the organization, belongs to the system owner. Decision, what we will accept, belongs to the authorizer. Most disputes come from skipping a link, such as an observation reported as a finding or a finding reported as a risk. THE ASSESSMENT CHAIN — EACH STEP HAS AN OWNER Evidence What was observed ASSESSOR Observation What it seems to mean ASSESSOR Finding Judgment against a requirement ASSESSOR Risk What it means for the organization SYSTEM OWNER Decision What we will accept AUTHORIZER Most disputes come from skipping a link — an observation reported as a finding, or a finding reported as a risk.
Figure 1: The chain from evidence to decision, and who owns each link. Most disputes come from skipping one.

Scroll sideways to see the full diagram →

TermMeans
EvidenceAn artifact: a configuration export, a log extract, a record, a demonstration
ObservationWhat the assessor noticed, before judging it against anything
FindingA judgment that a control, or part of one, does not meet its requirement
WeaknessThe specific deficiency a finding describes
Assessment procedureHow an assessor checks a control — examine, interview, test

The chain runs evidence → observation → finding. An observation is not yet a finding; it becomes one only when measured against a requirement. Reporting observations as findings is the fastest way to lose a system owner's trust.

On assessment procedures: NIST publishes them in SP 800-53A.4 Canada does not have a centrally published equivalent — ITSP.10.033 says it lays a foundation for developing them — so departments define their own.

The Risk Layer#

TermMeans
ThreatSomething that could exploit a weakness
VulnerabilityThe weakness itself, as exploitable
Inherent riskRisk before any control is credited
Residual riskRisk that remains after controls are credited
Risk statementThe risk in words: what is wrong, what it exposes, what could follow, for whom

A finding lives in the assessment layer; a risk lives here. Converting one into the other is a skill in its own right, and we cover it in Step 5. The scoring — how dangerous, how exposed, what remains — is in our residual risk model.

The Document Layer#

  1. System security plan (SSP)What the system is and how its controls are meant to work
  2. Security assessment report (SAR)What the assessor found, and what risk remains
  3. Plan of action and milestones (POA&M)What will be fixed, by whom, by when
  4. Authorization packageAll of the above, assembled for the decision

SSP describes intent. SAR describes reality. POA&M describes commitment. The package carries them to the person who decides.

The Decision Layer#

TermMeans
AuthorizationA decision by a senior official to operate a system, accepting its residual risk
AuthorizerThe person who makes it — and carries it
Risk acceptanceAgreeing to carry one specific risk. Narrower than authorization
ConditionsObligations attached to an authorization, each with an owner and a date

Authorization is a decision, not a document. You can accept one risk without authorizing a system, and you can authorize a system while several risks remain formally accepted.

Canadian and American Usage#

This is the section that earns the post. Most glossaries online are RMF- and FedRAMP-flavoured — FedRAMP being the US federal cloud authorization program — and they quietly mislead a Canadian reader.

ConceptITSG-33 / GC usageNIST RMF / FedRAMP usage
The decisionAuthorizationAuthorization, ATO
The deciderAuthorizer, senior officialAuthorizing Official (AO)
Control catalogueITSP.10.033SP 800-53 Rev. 5
Assessment proceduresDefined by each departmentSP 800-53A Rev. 5
Assurance obligationsAssurance activities, in the catalogueFolded into controls
Time-boxed approvalNo standard instrumentIATO, P-ATO
Baseline selectionControl profileBaseline plus overlays

The American decision is defined with unusual directness:

Official management decision given by a senior Federal official or officials to authorize operation of an information system and to explicitly accept the risk to agency operations … based on the implementation of an agreed-upon set of security and privacy controls.

CNSSI 4009-2022, via the NIST glossary

Read ATO as the RMF name for what ITSG-33 calls authorization.3 The idea is identical. The word is not — and a Canadian who learns "IATO" from an American blog will not find it in their departmental template. The catalogue-level differences are in ITSP.10.033 vs NIST SP 800-53.

Where CtrlFort Fits#

Vocabulary drifts when it lives in people's heads. Three assessors, three templates, three meanings of "partially met" — and by the third assessment nobody can compare results across systems.

CtrlFort Assess holds the vocabulary in the structure. A control, a finding, a risk and a decision are different objects with different fields, so a finding cannot be filed as a risk by accident and an assurance activity cannot be graded like a control. The chain in Figure 1 is how the platform is built, not a diagram of good intentions.

That is why this glossary is also the map of what CtrlFort tracks: each layer is a linked object, every result points back to the evidence it rests on, and the assessment intelligence architecture keeps the terms meaning the same thing on the hundredth assessment as on the first.

Final Thoughts#

Get the words right and most of the arguments in an assessment disappear, because they were never about the system. They were about which layer a sentence belonged to.

Previous: What Is Security Assessment and Authorization? · Next: Assessments Don't Reduce Risk. Decisions Do.

Frequently Asked Questions#

What is the difference between a finding and a risk?#

A finding says a control does not meet its requirement. A risk says what that could cost the organization, to whom, and how badly. The first is the assessor's judgment about a safeguard; the second is a statement an owner can decide about. One finding can produce several risks, and several findings can collapse into one.

Do Canadian departments issue ATOs?#

They issue authorizations. ATO is NIST RMF and FedRAMP vocabulary for the same decision, and it has crept into Canadian usage informally. Use it if your department does — but know that ITSG-33 does not, and that the interim IATO has no standard Canadian equivalent.5

Is a POA&M the same as a risk register?#

No. A POA&M tracks one assessment's remediation commitments. A risk register holds every risk the organization is managing, from every source, for the life of the system. Teams often run both and duplicate; our risk register post draws the line.

Who writes the SAR?#

The assessor. It records what they found and what risk remains, addressed to the authorizer. The system owner contributes control responses and the POA&M; they do not write the assessment of their own system.

References#

  1. ITSP.10.033 — Security and privacy controls and assurance activities catalogue Canadian Centre for Cyber Security · https://www.cyber.gc.ca/en/guidance/cyber-security-privacy-risk-management/itsp10033
  2. ITSP.10.033 — Concepts and structure Canadian Centre for Cyber Security · https://www.cyber.gc.ca/en/guidance/cyber-security-privacy-risk-management/itsp10033/concepts-structure
  3. Authorization to Operate — glossary entry, citing CNSSI 4009-2022 National Institute of Standards and Technology · https://csrc.nist.gov/glossary/term/authorization_to_operate
  4. NIST SP 800-53A Rev. 5 — Assessing Security and Privacy Controls in Information Systems and Organizations National Institute of Standards and Technology · https://csrc.nist.gov/pubs/sp/800/53/a/r5/final
  5. ITSG-33 Annex 2 — Information System Security Risk Management Activities Canadian Centre for Cyber Security · https://www.cyber.gc.ca/en/guidance/annex-2-information-system-security-risk-management-activities-itsg-33
On this page

Zeeshan Mahmood

Security Assessment, Architecture & AI

Zeeshan is a security advisor and senior IT security risk analyst who works at the seam between assessment and design. He runs the full authorization lifecycle — security categorization, threat and risk assessment, control profile selection, and the evidence behind an authority to operate — and designs the solution, cloud and security architecture that has to survive it, from landing zones and network segmentation to Zero Trust and cross-domain solutions. His current focus includes AI security and the assessment of AI-enabled systems. He holds CISSP, CCSP, CISM, CKS and Azure Solutions Architect Expert, and leads assurance methodology at CtrlFort.

Run this framework against your own control library.

CtrlFort Assess maps cloud control profiles, ITSG-33 baselines and certification regimes to one shared evidence base — so a control you evidence once satisfies every obligation it maps to.