New Zealand Information Security Manual (NZISM)
Chapter 23: Public Cloud Security – New Zealand Information Security Manual (NZISM)

New Zealand Information Security Manual (NZISM) 23.1.54.C.02: 23.1.54.C.02 Separate domain when multiple identity systems control access

Where an agency's public cloud instance is accessed through several identity systems subject to different security policies, that instance must be treated as a separate security domain from services whose access control is managed only by the agency's own identity system.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Other controls in Chapter 23: Public Cloud Security – New Zealand Information Security Manual (NZISM)

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.