New Zealand Information Security Manual (NZISM): cited answers and gap reviews
The NZISM is the GCSB's information security manual for New Zealand government agencies. Compliance Colleague covers control guidance, classification, certification and accreditation, and supplier security.
What it covers
- NZISM controls and agency obligations
- Classification from Unclassified to Top Secret
- Certification and Accreditation
- Security risk management
- Third-party supplier security
Questions you can ask
- “What does the NZISM require for a RESTRICTED system?”
- “What does Certification and Accreditation involve?”
- “Which NZISM controls apply to our cloud supplier?”
Every answer cites the NZISM requirement, article or control it rests on, so you can check it in seconds.
What you can upload for review
- An agency security policy checked against the NZISM
- A system architecture diagram checked for classification boundaries
- A supplier security assessment checked for gaps
Files: PDF, Word, Excel or CSV, Visio (.vsdx), draw.io, or an image such as a screenshot. Choose a full review, a prioritized fix list (each gap with its fix and the evidence an assessor will expect) or a short summary, and download the result as Word or PDF.
Crosswalk NZISM to other standards
With NZISM in your plan you can compare it against any standard in the library and see where they align and exactly where they don’t. Common pairings:
What it’s built from
Compliance Colleague carries the official text and checks its answers against it: New Zealand Information Security Manual (NZISM) (Government Communications Security Bureau (GCSB) / NCSC NZ).
Re-checked every month for new versions, deadlines and penalty changes. Full list on the sources page.
More Australia & New Zealand standards
Australian Privacy Act · Australian ISM
Research aid, not legal or audit advice, and not an audit opinion or certification. Verify findings against the official text before relying on them.