New Zealand Information Security Manual (NZISM)
The New Zealand Information Security Manual (NZISM) provides information security guidance for New Zealand Government agencies. Maintained by the Government Communications Security Bureau (GCSB) via the National Cyber Security Centre (NCSC). The NZISM specifies mandatory and recommended security controls covering governance, physical security, personnel, ICT equipment, software, networking, cryptography, and cloud computing. Applicable to all NZ government agencies processing RESTRICTED, CONFIDENTIAL, SECRET, and TOP SECRET information.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (8)
Access and Comms Security
| Code | Title |
|---|---|
| NZISM-4 | Access Control, Authentication, and Communications Security |
Certification and Accreditation
| Code | Title |
|---|---|
| NZISM-2 | Certification and Accreditation (C&A) for Government Systems |
Governance and Classification
| Code | Title |
|---|---|
| NZISM-1 | NZISM Governance, Documentation, and Classification System |
Media + Cloud + Outsourcing
| Code | Title |
|---|---|
| NZISM-7 | Media Handling, Outsourcing, Cloud Services, and Remote Access |
Operations and Resilience
| Code | Title |
|---|---|
| NZISM-6 | Event Logging, Monitoring, Incident Response, and Business Continuity |
Personnel + Physical + Crypto
| Code | Title |
|---|---|
| NZISM-3 | Personnel Security, Physical Security, and Cryptography |
Risk and Vulnerability
| Code | Title |
|---|---|
| NZISM-8 | Security Risk Management, Vulnerability Management, and Incident Reporting |
Technical Security Controls
| Code | Title |
|---|---|
| NZISM-5 | Network Security, System Hardening, and Application Security |
Your Compliance Coverage
If you comply with New Zealand Information Security Manual (NZISM), you already cover:
OWASP DevSecOps Maturity Model (DSOMM)
50%
4 controls mapped
Compare →NIST SP 800-146
50%
4 controls mapped
Compare →NIST SP 800-145
50%
4 controls mapped
Compare →+ 172 more: NIST SP 800-144 (50%), ISO 27018 (50%)
See all 175 mapped frameworks ↓Maps to 175 other frameworks
Frequently Asked Questions
What is New Zealand Information Security Manual (NZISM)?
New Zealand Information Security Manual (NZISM) is a compliance framework from New Zealand (GCSB/NCSC) with 8 domains and 8 controls. The New Zealand Information Security Manual (NZISM) provides information security guidance for New Zealand Government agencies. Maintained by the Government Communications Security Bureau (GCSB) via the National Cyber Security Centre (NCSC). The NZISM specifies mandatory and recommended security controls covering governance, physical security, personnel, ICT equipment, software, networking, cryptography, and cloud computing. Applicable to all NZ government agencies processing RESTRICTED, CONFIDENTIAL, SECRET, and TOP SECRET information. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does New Zealand Information Security Manual (NZISM) have?
New Zealand Information Security Manual (NZISM) has 8 controls organised across 8 domains. The largest domains are Access and Comms Security (1 controls), Certification and Accreditation (1 controls), Governance and Classification (1 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does New Zealand Information Security Manual (NZISM) map to?
New Zealand Information Security Manual (NZISM) maps to 175 other compliance frameworks. The top mapping partners are OWASP DevSecOps Maturity Model (DSOMM) (50% coverage), NIST SP 800-146 (50% coverage), NIST SP 800-145 (50% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with New Zealand Information Security Manual (NZISM) compliance?
Start your New Zealand Information Security Manual (NZISM) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about New Zealand Information Security Manual (NZISM) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 8 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 700 frameworks.
Get Started Free →Free forever — no credit card required