New Zealand Information Security Manual (NZISM)
Access and Comms Security

New Zealand Information Security Manual (NZISM) NZISM-4: Access Control, Authentication, and Communications Security

Implement access control and authentication per NZISM Chapter 9 including: identity and access management + role-based access control (RBAC) + multi-factor authentication for privileged and remote access + privileged access management with session recording + just-in-time access + account lifecycle management. Apply communications security per NZISM Chapter 8 covering encrypted communications + secure messaging + email security + IPSec + TLS 1.3 + S/MIME + PGP. Use Realme NZ Government identity for citizen-facing services + NZBN for business identity.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.