New Zealand Information Security Manual (NZISM)
The New Zealand Information Security Manual (NZISM) provides information security guidance for New Zealand Government agencies. Maintained by the Government Communications Security Bureau (GCSB) via the National Cyber Security Centre (NCSC). The NZISM specifies mandatory and recommended security controls covering governance, physical security, personnel, ICT equipment, software, networking, cryptography, and cloud computing. Applicable to all NZ government agencies processing RESTRICTED, CONFIDENTIAL, SECRET, and TOP SECRET information.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (2)
Classification and Compliance
Information classification and compliance framework
| Code | Title |
|---|---|
| NZ-NZISM-CC-01 | Classification System |
| NZ-NZISM-CC-02 | Certification and Accreditation |
| NZ-NZISM-CC-03 | Incident Reporting |
Security Controls
Information protection and breach management
| Code | Title |
|---|---|
| CA-ITSG33-SC-01 | Security Control Catalogue |
| CA-ITSG33-SC-02 | Security Profiles |
| CA-ITSG33-SC-03 | Cloud Security |
| KR-CSAP-SC-01 | Information Security Management |
| KR-CSAP-SC-02 | Infrastructure and Network Security |
| KR-CSAP-SC-03 | Virtual Environment Security |
| MARSE-SC-01 | NIST 800-53 Moderate Baseline |
| MARSE-SC-02 | Federal Tax Information Protection |
| MARSE-SC-03 | Identity Verification |
| NRC73-CTL-01 | Access Control for CDAs |
| NRC73-CTL-02 | Network Isolation and Segmentation |
| NRC73-CTL-03 | Configuration Management |
| NRC73-CTL-04 | Monitoring and Incident Response |
| NRC73-CTL-05 | Supply Chain Security for CDAs |
| NRC73-CTL-06 | Training and Awareness |
| NZ-NZISM-SC-01 | Governance and Risk Management |
| NZ-NZISM-SC-02 | ICT Security Controls |
| NZ-NZISM-SC-03 | Cryptography and Cloud |
| PAS1192-5-SC-01 | Technical Controls |
| PAS1192-5-SC-02 | Personnel Security |
| PAS1192-5-SC-03 | Breach Management |
Maps to 650 other frameworks
Frequently Asked Questions
What is New Zealand Information Security Manual (NZISM)?
New Zealand Information Security Manual (NZISM) is a compliance framework from New Zealand (GCSB/NCSC) with 2 domains and 24 controls. The New Zealand Information Security Manual (NZISM) provides information security guidance for New Zealand Government agencies. Maintained by the Government Communications Security Bureau (GCSB) via the National Cyber Security Centre (NCSC). The NZISM specifies mandatory and recommended security controls covering governance, physical security, personnel, ICT equipment, software, networking, cryptography, and cloud computing. Applicable to all NZ government agencies processing RESTRICTED, CONFIDENTIAL, SECRET, and TOP SECRET information. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does New Zealand Information Security Manual (NZISM) have?
New Zealand Information Security Manual (NZISM) has 24 controls organised across 2 domains. The largest domains are Security Controls (21 controls), Classification and Compliance (3 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does New Zealand Information Security Manual (NZISM) map to?
New Zealand Information Security Manual (NZISM) maps to 650 other compliance frameworks. The top mapping partners are CSA CCM v4 (67% coverage), NRC 10 CFR 73.54 — Nuclear Facility Cybersecurity (63% coverage), FAA Cybersecurity Framework for Aviation (63% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with New Zealand Information Security Manual (NZISM) compliance?
Start your New Zealand Information Security Manual (NZISM) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about New Zealand Information Security Manual (NZISM) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 24 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 692 frameworks.
Get Started Free →Free forever — no credit card required