What problem does it solve?
New Zealand government agencies and their suppliers must comply with the NZISM, the mandatory security framework published by GCSB/NCSC NZ, but interpreting its controls, classification requirements, and Certification & Accreditation process is complex and error-prone.
Core Features & Use Cases
- Gap Analysis: Produces control-by-control compliance tables with status, evidence needed, and gap notes scoped to the system's classification level.
- Certification & Accreditation Guidance: Walks through the full C&A pathway including SSP, SRMP, control validation, POA&M, and Accreditation Authority sign-off.
- Policy & Document Generation: Drafts NZISM-aligned security policies, incident response plans, and supplier due-diligence checklists with verified control ID citations.
- Use Case: An agency CISO scoping a new RESTRICTED system hosted in an Australian cloud region can get the full offshore hosting risk pathway, applicable controls, and approval chain in one answer.
Quick Start
Ask the assistant to perform an NZISM gap analysis for a RESTRICTED-classified system and list the controls requiring remediation before accreditation.