New Zealand Information Security Manual (NZISM)
Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Access and Comms Security
Implement access control and authentication per NZISM Chapter 9 including: identity and access management + role-based access control (RBAC) + multi-factor authentication for privileged and remote access + privileged access management with session recording + just-in-time access + account lifecycle management. Apply communications security per NZISM Chapter 8 covering encrypted communications + secure messaging + email security + IPSec + TLS 1.3 + S/MIME + PGP. Use Realme NZ Government identity for citizen-facing services + NZBN for business identity.
- IAM solution deployment
- MFA configuration
- PAM with session recording
- TLS/IPSec deployment
- Realme integration
- Annual access reviews
- MFA gaps
- No PAM
- Weak TLS configurations
- Missing Realme integration
Certification and Accreditation
Conduct Certification and Accreditation (C&A) per NZISM Chapter 4 covering: system categorisation per classification level + security control selection + security control implementation + Security Risk Management Plan + Certification by independent IRAP-equivalent assessor + Accreditation decision by Accreditation Authority (Agency Chief Executive or delegate) + Authority to Operate (ATO) issuance + ongoing assurance + reaccreditation every 3 years or upon material change. Use Information Security Manual baseline + agency-specific controls.
- System categorisation
- Certification Report by independent assessor
- Accreditation Decision
- ATO documentation
- 3-year reaccreditation schedule
- Ongoing assurance evidence
- No certification
- ATO expired
- No reaccreditation
- Missing ongoing assurance
Governance and Classification
Comply with the New Zealand Information Security Manual (NZISM) administered by the Government Communications Security Bureau (GCSB) National Cyber Security Centre (NCSC) under the Government Chief Information Security Officer (GCISO) function. Apply the New Zealand Government Security Classification System: UNCLASSIFIED + IN-CONFIDENCE + SENSITIVE + RESTRICTED + CONFIDENTIAL + SECRET + TOP SECRET (per Cabinet Office Circular CO (18) 5). Maintain Information Security Documentation including Security Risk Management Plan (SRMP) + System Security Plan (SSP) + Incident Response Plan + Audit and Compliance Programme. Govern under the Protective Security Requirements (PSR) overseen by NZ Security Intelligence Service (NZSIS).
- Classification scheme implementation
- SRMP per system
- SSP per system
- PSR compliance attestation
- GCSB/NCSC liaison record
- GCISO reporting
- No classification implementation
- Missing SRMP/SSP
- No PSR alignment
- No GCISO reporting
Media + Cloud + Outsourcing
Apply NZISM Chapter 16 Media Handling and Destruction including classification-appropriate destruction (degaussing for classified magnetic media + shredding for paper + physical destruction for non-magnetic). Manage outsourcing and third-party service providers per NZISM Chapter 17 including due diligence + contractual security clauses + offshoring restrictions for SECRET and above. Use cloud services per NZISM Chapter 18 + NZ Government Cloud Computing Risk Discussion Paper + ALL-OF-GOVERNMENT Cloud Computing arrangement preferred suppliers (AWS + Microsoft Azure + Google Cloud + Datacom + Catalyst NZ + Spark + Revera). Enable remote access and teleworking per NZISM Chapter 19.
- Media destruction certificates
- Vendor due diligence
- Cloud risk assessment
- ALL-OF-GOVERNMENT supplier evidence
- Remote access policy
- Offshoring restrictions for classified data
- No media destruction
- Inadequate vendor diligence
- Non-approved cloud
- No offshoring restrictions
Operations and Resilience
Operate event logging and monitoring per NZISM Chapter 13 covering security event logging + log retention (3-year minimum for SECRET + 7-year for TOP SECRET) + SIEM aggregation + 24x7 SOC monitoring. Maintain Incident Response Plan per NZISM Chapter 14 including detection + containment + eradication + recovery + lessons learned + NCSC notification within agreed timeframes + CERT NZ coordination. Maintain Business Continuity and Disaster Recovery per NZISM Chapter 15 including BCP + DRP + annual testing + RTO/RPO targets.
- SIEM deployment
- Log retention per classification
- Incident Response Plan
- NCSC notification capability
- CERT NZ liaison
- Annual BCP/DRP exercise
- RTO/RPO targets
- Inadequate log retention
- No SOC
- Missing NCSC liaison
- No annual BCP/DRP exercise
Personnel + Physical + Crypto
Apply NZISM Chapters 6 (Personnel Security) + 7 (Physical Security) + Communications Security Chapters covering: personnel security clearances per NZSIS investigation (CONFIDENTIAL + SECRET + TOP SECRET) + clearance reviews every 5 years + need-to-know principle + physical security zoning (Zone 1-5 per PSR) + secure storage + entry controls + Cryptographic Material Handling per GCSB Approved Products List (APL) + cryptographic algorithms per NZISM Crypto Standard (RSA-3072 + ECDSA P-384 + AES-256 + SHA-384 minimum baseline) + Public Key Infrastructure under GCSB Certificate Authority.
- Personnel clearance register
- 5-year reinvestigation schedule
- Physical security zone documentation
- APL-approved product inventory
- Cryptographic algorithm compliance
- GCSB PKI integration
- Stale clearances
- No zone documentation
- Non-APL products
- Outdated crypto algorithms
Risk and Vulnerability
Apply security risk management per NZISM Chapter 20 + ISO 31000 + NZ ISO/AS 31000:2018 covering risk identification + assessment + treatment + monitoring + governance reporting. Conduct vulnerability management and penetration testing per NZISM Chapter 21 including continuous scanning + risk-based patch management (Critical 14 days + High 30 days for SECRET+) + annual penetration test + Red Team exercises + vulnerability disclosure programme via CERT NZ. Report security incidents to NCSC + CERT NZ + Office of the Privacy Commissioner where personal information involved.
- SRMP with treatment decisions
- Vulnerability scan reports
- Patch management metrics
- Annual pen test report
- Red Team exercise reports
- NCSC incident reports
- CERT NZ coordination
- No SRMP
- Patches exceed SLA
- No annual pen test
- Missing NCSC/CERT NZ reports
Technical Security Controls
Apply NZISM Chapters 10 (Network Security) + 11 (System Hardening) + 12 (Software Security and Application Development) covering: network segmentation with cross-domain solutions where applicable + perimeter defence + intrusion detection/prevention + system hardening per NZISM baselines for Windows + Linux + macOS + mobile + cloud + secure software development lifecycle (SDLC) per OWASP SAMM + threat modelling + secure coding + dependency scanning + container security + API security per OWASP API Top 10.
- Network architecture diagrams
- Hardening baselines per OS
- SDLC documentation
- SAST/DAST/SCA scan reports
- OWASP Top 10 compliance
- Container security configuration
- Flat networks
- Missing hardening
- Inadequate secure SDLC
- No SAST/DAST
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the New Zealand Information Security Manual (NZISM) framework page.