New Zealand Information Security Manual (NZISM)
Certification and Accreditation

New Zealand Information Security Manual (NZISM) NZISM-2: Certification and Accreditation (C&A) for Government Systems

Conduct Certification and Accreditation (C&A) per NZISM Chapter 4 covering: system categorisation per classification level + security control selection + security control implementation + Security Risk Management Plan + Certification by independent IRAP-equivalent assessor + Accreditation decision by Accreditation Authority (Agency Chief Executive or delegate) + Authority to Operate (ATO) issuance + ongoing assurance + reaccreditation every 3 years or upon material change. Use Information Security Manual baseline + agency-specific controls.

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.