New Zealand Information Security Manual (NZISM)
Governance and Classification

New Zealand Information Security Manual (NZISM) NZISM-1: NZISM Governance, Documentation, and Classification System

Comply with the New Zealand Information Security Manual (NZISM) administered by the Government Communications Security Bureau (GCSB) National Cyber Security Centre (NCSC) under the Government Chief Information Security Officer (GCISO) function. Apply the New Zealand Government Security Classification System: UNCLASSIFIED + IN-CONFIDENCE + SENSITIVE + RESTRICTED + CONFIDENTIAL + SECRET + TOP SECRET (per Cabinet Office Circular CO (18) 5). Maintain Information Security Documentation including Security Risk Management Plan (SRMP) + System Security Plan (SSP) + Incident Response Plan + Audit and Compliance Programme. Govern under the Protective Security Requirements (PSR) overseen by NZ Security Intelligence Service (NZSIS).

What else in your programme already covers this

This control maps to 237 controls across 97 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 27005 · 6 controls

ISO 31000 · 6 controls

ISO/IEC 23894:2023 · 6 controls

NIST SP 800-30 · 6 controls

  • NISTSP30-1 Risk Management Strategy and Risk Assessment Programme Establishment
  • NISTSP30-2 Three-Tier Risk Assessment Scoping (Organisation, Mission/Business, Information System)
  • NISTSP30-3 Threat Source and Threat Event Identification
  • NISTSP30-4 Vulnerability and Predisposing Condition Identification
  • NISTSP30-6 Risk Determination, Uncertainty, and Sensitivity Analysis
  • NISTSP30-8 Risk Assessment Maintenance, Continuous Monitoring, and Integration with the RMF

NIST SP 800-53 Rev 5 · 6 controls

  • NIST-CSF-GV.RM-03 Cybersecurity risk management activities and outcomes are included in enterprise risk management processes
  • NIST-CSF-GV.RM-04 Strategic direction that describes appropriate risk response options is established and communicated
  • NIST-CSF-GV.RM-07 Strategic opportunities (i.e., positive risks) are characterized and are included in organizational cybersecurity risk discussions
  • NIST-CSF-GV.SC-01 A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders
  • NIST-CSF-ID.RA-09 The authenticity and integrity of hardware and software are assessed prior to acquisition and use
  • CPS230-11 Identification, Assessment and Management of Operational Risk
  • CPS230-16 Internal Audit Review of the Business Continuity Plan
  • CPS230-37 Service Provider Management Policy
  • CPS230-46 Ongoing Risk Management of Each Material Arrangement
  • 3.11 Encrypt Sensitive Data at Rest
  • 3.16 System and Services Acquisition
  • 3.17 Supply Chain Risk Management
  • 3.2.1 Account data storage is kept to a minimum through implementation of data retention and disposal policies, procedures, and processes that include at least the following: • Coverage for all locations of stored account data.

NIST SP 800-37 · 4 controls

  • NISTSP37-1 RMF Prepare Step: Organisation-Level and System-Level Preparation
  • NISTSP37-2 RMF Categorize Step: Information and System Categorisation
  • NISTSP37-3 RMF Select Step: Security and Privacy Control Selection
  • NISTSP37-7 RMF Monitor Step: Continuous Monitoring and Ongoing Authorisation

API 1164 · 3 controls

BSI IT-Grundschutz · 3 controls

  • BSI-13 Risk assessment procedures
  • BSI-15 Security categorization
  • BSI-17 Continuous monitoring strategy
  • FFIEC-03 Risk appetite and tolerance for IT risk
  • FFIEC-18 Ongoing monitoring and assessment
  • FFIEC-20 Exit strategy and transition planning

IEC 62443 · 3 controls

ISO 27019 · 3 controls

ISO/IEC 27003:2017 · 3 controls

ISO/IEC 29134:2023 · 3 controls

  • NISTPF-1 Identify-P - Business Environment, Data Processing Inventory, Ecosystem, and Risk Assessment
  • NISTPF-2 Govern-P - Governance Policies, Risk Management Strategy, Awareness Training, and Monitoring
  • NISTPF-8 Protect-P Information Protection Processes (PR.PO-P)

NIST SP 1800-32 · 3 controls

NIST SP 800-39 · 3 controls

  • NISTSP39-3 Risk Assessing: Organisation, Mission, and System Level Assessments
  • NISTSP39-4 Risk Responding: Identify, Evaluate, Decide, Implement
  • NISTSP39-5 Risk Monitoring: Effectiveness, Changes, Compliance, and Reassessment Triggers
  • CRM-1 AML/CFT Compliance
  • CRM-3 Risk Management Framework
  • CRM-4 Business Risk Assessment

APRA CPS 234 · 2 controls

  • CPS234-16 Assessment of Related Party and Third Party Capability
  • CPS234-20 Information Asset Classification
  • ICP-16 Enterprise Risk Management for Solvency Purposes
  • ICP-8 Risk Management and Internal Controls

ISO 13485 · 2 controls

ISO 27799 · 2 controls

ISO/IEC 27014:2020 · 2 controls

NIST SP 800-66 · 2 controls

  • NISTSP66-1 Security Management Process: Risk Analysis and Risk Management for ePHI
  • NISTSP66-2 Workforce Security, Information Access Management, and Awareness Training
  • NISTSP82-1 OT Security Program Governance, Policy, Roles, and Safety-Security Integration
  • NISTSP82-2 OT Risk Assessment and Threat/Vulnerability Identification
  • NRFCS-1 Retail Cybersecurity Governance, Policy, and Regulatory Change Management
  • NRFCS-2 Risk Assessment, Customer Data Inventory, Classification, and Retail Threat Model
  • OCCHS-3 Risk Appetite Statement, Risk Limits, Concentration Risk, and Limit Breach Protocols
  • OCCHS-7 Risk Data Aggregation, Reporting, Talent, Compensation, and Strategic Planning
  • ASTWO-1 Audit Planning, Scaling, Risk Assessment, and Integration
  • ASTWO-3 Entity-Level Controls and Period-End Financial Reporting Process
  • 2.4.4 Hazard Analysis and Risk Assessment
  • 2.7.2 Food Fraud Plan

South Korea ISMS-P · 2 controls

  • CH-FADP-21 Data protection impact assessments
  • FADP-7 Data Protection Impact Assessment (Articles 9-10)
  • ASD37-37 Personnel management (Very Good)
  • 4.3.1 Risk Assessment and Impact Analysis

Bahrain PDPL · 1 control

  • BB-DPA-20 Sections 50-60 - Registration and Responsibilities

GDPR · 1 control

ISO 22000 · 1 control

ISO 22320:2018 · 1 control

ISO 27017 · 1 control

ISO 27018 · 1 control

ISO 45001 · 1 control

ISO/IEC 27011:2024 · 1 control

ISO/IEC 27031:2011 · 1 control

ISO/IEC 29147:2018 · 1 control

  • 29147-5.11 Researcher Safe Harbour and Legal Posture
  • NIS2I-2 Policy, Risk Management, and Roles + Responsibilities

NIST SP 800-122 · 1 control

  • NISTSP122-8 Continuous Monitoring, Training, and Privacy Programme Governance

NIST SP 800-144 · 1 control

  • NISTSP144-1 Cloud Governance, Risk Assessment, and Provider Trust Evaluation

NIST SP 800-145 · 1 control

  • NISTSP145-7 Cloud Procurement Standards Aligned to NIST SP 800-145 Definition

NIST SP 800-146 · 1 control

  • NISTSP146-1 Cloud Adoption Strategy, Workload Suitability, and Decision Framework

NIST SP 800-190 · 1 control

  • NGNDPR-5 Security of Personal Data, Breach Notification, and DPIA under NDPR Section 2.6-Security
  • NGOB-1 Open Banking Registry Participation, Tiered Categorisation, and KYP
  • DSOMM-1 Culture, Organization, Education, and Governance
  • NORWAY-4 DPIA, Privacy by Design, Records of Processing
  • AUPRV-6 Sensitive Information, PIA, Privacy by Design, Children
  • PSPF24-1 Security Culture, Governance, Risk Management
  • AIGF-1.1 Risk Management and Internal Controls

South Korea PIPA · 1 control

Turkey KVKK · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 237 it maps to, and the evidence behind each claim, over MCP and REST.