Frameworks
What is the NZISM?
The New Zealand Information Security Manual (NZISM) is the NZ government’s manual of information security controls, maintained by the National Cyber Security Centre (NCSC). It’s mandatory for government agencies and widely used by others as a trusted local benchmark.
The New Zealand Information Security Manual (NZISM) is the NZ government’s manual of information security controls, maintained by the National Cyber Security Centre (NCSC). It’s mandatory for government agencies and widely used by others as a trusted local benchmark.
The essentials
Who it applies to
- Government agencies must comply with the NZISM.
- Government suppliers are often expected to align with relevant parts of it.
- Private organisations can use it as a credible, locally relevant security benchmark.
- It’s maintained by the NCSC and updated regularly.
- It sits alongside the Protective Security Requirements (PSR).
Using it in practice
How we apply it
For most private organisations, full NZISM compliance isn’t required — but aligning to the parts that fit your risk is valuable, especially if you supply government. We map your controls to the NZISM (alongside NIST CSF and ISO 27001) so your security is recognisable and defensible.
FAQ
Common questions
Is the NZISM mandatory for private companies?
No. It's mandatory for government agencies. Private organisations use it as a voluntary benchmark — valuable especially if you work with or supply the public sector.
Who maintains the NZISM?
The National Cyber Security Centre (NCSC) maintains and regularly updates the NZISM.
Should our business follow NZISM, NIST or ISO 27001?
They overlap heavily. For NZ organisations we often align to the NZISM for local relevance, use NIST CSF 2.0 to structure the programme, and pursue ISO 27001 where formal certification is needed.
Related pages
Let’s talk
Every good plan starts with a conversation, and there’s no obligation in having one.