Skip to content

Evidence request lists

New Zealand Information Security Manual (NZISM)

Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Access and Comms Security

NZISM-4
Access Control, Authentication, and Communications Security

Implement access control and authentication per NZISM Chapter 9 including: identity and access management + role-based access control (RBAC) + multi-factor authentication for privileged and remote access + privileged access management with session recording + just-in-time access + account lifecycle management. Apply communications security per NZISM Chapter 8 covering encrypted communications + secure messaging + email security + IPSec + TLS 1.3 + S/MIME + PGP. Use Realme NZ Government identity for citizen-facing services + NZBN for business identity.

Artefacts an auditor will ask for
  • IAM solution deployment
  • MFA configuration
  • PAM with session recording
  • TLS/IPSec deployment
  • Realme integration
  • Annual access reviews
Where this commonly fails
  • MFA gaps
  • No PAM
  • Weak TLS configurations
  • Missing Realme integration

Certification and Accreditation

NZISM-2
Certification and Accreditation (C&A) for Government Systems

Conduct Certification and Accreditation (C&A) per NZISM Chapter 4 covering: system categorisation per classification level + security control selection + security control implementation + Security Risk Management Plan + Certification by independent IRAP-equivalent assessor + Accreditation decision by Accreditation Authority (Agency Chief Executive or delegate) + Authority to Operate (ATO) issuance + ongoing assurance + reaccreditation every 3 years or upon material change. Use Information Security Manual baseline + agency-specific controls.

Artefacts an auditor will ask for
  • System categorisation
  • Certification Report by independent assessor
  • Accreditation Decision
  • ATO documentation
  • 3-year reaccreditation schedule
  • Ongoing assurance evidence
Where this commonly fails
  • No certification
  • ATO expired
  • No reaccreditation
  • Missing ongoing assurance

Governance and Classification

NZISM-1
NZISM Governance, Documentation, and Classification System

Comply with the New Zealand Information Security Manual (NZISM) administered by the Government Communications Security Bureau (GCSB) National Cyber Security Centre (NCSC) under the Government Chief Information Security Officer (GCISO) function. Apply the New Zealand Government Security Classification System: UNCLASSIFIED + IN-CONFIDENCE + SENSITIVE + RESTRICTED + CONFIDENTIAL + SECRET + TOP SECRET (per Cabinet Office Circular CO (18) 5). Maintain Information Security Documentation including Security Risk Management Plan (SRMP) + System Security Plan (SSP) + Incident Response Plan + Audit and Compliance Programme. Govern under the Protective Security Requirements (PSR) overseen by NZ Security Intelligence Service (NZSIS).

Artefacts an auditor will ask for
  • Classification scheme implementation
  • SRMP per system
  • SSP per system
  • PSR compliance attestation
  • GCSB/NCSC liaison record
  • GCISO reporting
Where this commonly fails
  • No classification implementation
  • Missing SRMP/SSP
  • No PSR alignment
  • No GCISO reporting

Media + Cloud + Outsourcing

NZISM-7
Media Handling, Outsourcing, Cloud Services, and Remote Access

Apply NZISM Chapter 16 Media Handling and Destruction including classification-appropriate destruction (degaussing for classified magnetic media + shredding for paper + physical destruction for non-magnetic). Manage outsourcing and third-party service providers per NZISM Chapter 17 including due diligence + contractual security clauses + offshoring restrictions for SECRET and above. Use cloud services per NZISM Chapter 18 + NZ Government Cloud Computing Risk Discussion Paper + ALL-OF-GOVERNMENT Cloud Computing arrangement preferred suppliers (AWS + Microsoft Azure + Google Cloud + Datacom + Catalyst NZ + Spark + Revera). Enable remote access and teleworking per NZISM Chapter 19.

Artefacts an auditor will ask for
  • Media destruction certificates
  • Vendor due diligence
  • Cloud risk assessment
  • ALL-OF-GOVERNMENT supplier evidence
  • Remote access policy
  • Offshoring restrictions for classified data
Where this commonly fails
  • No media destruction
  • Inadequate vendor diligence
  • Non-approved cloud
  • No offshoring restrictions

Operations and Resilience

NZISM-6
Event Logging, Monitoring, Incident Response, and Business Continuity

Operate event logging and monitoring per NZISM Chapter 13 covering security event logging + log retention (3-year minimum for SECRET + 7-year for TOP SECRET) + SIEM aggregation + 24x7 SOC monitoring. Maintain Incident Response Plan per NZISM Chapter 14 including detection + containment + eradication + recovery + lessons learned + NCSC notification within agreed timeframes + CERT NZ coordination. Maintain Business Continuity and Disaster Recovery per NZISM Chapter 15 including BCP + DRP + annual testing + RTO/RPO targets.

Artefacts an auditor will ask for
  • SIEM deployment
  • Log retention per classification
  • Incident Response Plan
  • NCSC notification capability
  • CERT NZ liaison
  • Annual BCP/DRP exercise
  • RTO/RPO targets
Where this commonly fails
  • Inadequate log retention
  • No SOC
  • Missing NCSC liaison
  • No annual BCP/DRP exercise

Personnel + Physical + Crypto

NZISM-3
Personnel Security, Physical Security, and Cryptography

Apply NZISM Chapters 6 (Personnel Security) + 7 (Physical Security) + Communications Security Chapters covering: personnel security clearances per NZSIS investigation (CONFIDENTIAL + SECRET + TOP SECRET) + clearance reviews every 5 years + need-to-know principle + physical security zoning (Zone 1-5 per PSR) + secure storage + entry controls + Cryptographic Material Handling per GCSB Approved Products List (APL) + cryptographic algorithms per NZISM Crypto Standard (RSA-3072 + ECDSA P-384 + AES-256 + SHA-384 minimum baseline) + Public Key Infrastructure under GCSB Certificate Authority.

Artefacts an auditor will ask for
  • Personnel clearance register
  • 5-year reinvestigation schedule
  • Physical security zone documentation
  • APL-approved product inventory
  • Cryptographic algorithm compliance
  • GCSB PKI integration
Where this commonly fails
  • Stale clearances
  • No zone documentation
  • Non-APL products
  • Outdated crypto algorithms

Risk and Vulnerability

NZISM-8
Security Risk Management, Vulnerability Management, and Incident Reporting

Apply security risk management per NZISM Chapter 20 + ISO 31000 + NZ ISO/AS 31000:2018 covering risk identification + assessment + treatment + monitoring + governance reporting. Conduct vulnerability management and penetration testing per NZISM Chapter 21 including continuous scanning + risk-based patch management (Critical 14 days + High 30 days for SECRET+) + annual penetration test + Red Team exercises + vulnerability disclosure programme via CERT NZ. Report security incidents to NCSC + CERT NZ + Office of the Privacy Commissioner where personal information involved.

Artefacts an auditor will ask for
  • SRMP with treatment decisions
  • Vulnerability scan reports
  • Patch management metrics
  • Annual pen test report
  • Red Team exercise reports
  • NCSC incident reports
  • CERT NZ coordination
Where this commonly fails
  • No SRMP
  • Patches exceed SLA
  • No annual pen test
  • Missing NCSC/CERT NZ reports

Technical Security Controls

NZISM-5
Network Security, System Hardening, and Application Security

Apply NZISM Chapters 10 (Network Security) + 11 (System Hardening) + 12 (Software Security and Application Development) covering: network segmentation with cross-domain solutions where applicable + perimeter defence + intrusion detection/prevention + system hardening per NZISM baselines for Windows + Linux + macOS + mobile + cloud + secure software development lifecycle (SDLC) per OWASP SAMM + threat modelling + secure coding + dependency scanning + container security + API security per OWASP API Top 10.

Artefacts an auditor will ask for
  • Network architecture diagrams
  • Hardening baselines per OS
  • SDLC documentation
  • SAST/DAST/SCA scan reports
  • OWASP Top 10 compliance
  • Container security configuration
Where this commonly fails
  • Flat networks
  • Missing hardening
  • Inadequate secure SDLC
  • No SAST/DAST
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the New Zealand Information Security Manual (NZISM) framework page.