nzism

Provides NZISM compliance guidance, gap analysis, and certification workflows for NZ government systems.

869|179|Updated Mar 16, 2026
One-click install
npx skills add https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill nzism
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: nzism
Source: https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/tree/main/plugins/nzism/skills/nzism
Command: npx skills add https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill nzism

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

New Zealand government agencies and their suppliers must comply with the NZISM, the mandatory security framework published by GCSB/NCSC NZ, but interpreting its controls, classification requirements, and Certification & Accreditation process is complex and error-prone.

Core Features & Use Cases

  • Gap Analysis: Produces control-by-control compliance tables with status, evidence needed, and gap notes scoped to the system's classification level.
  • Certification & Accreditation Guidance: Walks through the full C&A pathway including SSP, SRMP, control validation, POA&M, and Accreditation Authority sign-off.
  • Policy & Document Generation: Drafts NZISM-aligned security policies, incident response plans, and supplier due-diligence checklists with verified control ID citations.
  • Use Case: An agency CISO scoping a new RESTRICTED system hosted in an Australian cloud region can get the full offshore hosting risk pathway, applicable controls, and approval chain in one answer.

Quick Start

Ask the assistant to perform an NZISM gap analysis for a RESTRICTED-classified system and list the controls requiring remediation before accreditation.

Frequently Asked Questions about nzism

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I perform an NZISM gap analysis for a government system?

Confirm the agency type, system classification level, and current security posture, then assess each applicable NZISM control as Implemented, Partial, Not Implemented, or N/A with evidence needed and gap notes. Higher classifications inherit all controls from lower levels.

What is the NZISM Certification and Accreditation process?

C&A requires a System Security Plan and Security Risk Management Plan, independent control validation, certification sign-off, a POA&M for findings, and formal accreditation by the Accreditation Authority granting Authorisation to Operate. It is mandatory for systems handling Restricted information and above.

Can NZ government data be hosted offshore or in public cloud?

Offshore hosting is a risk-based decision, not a prohibition. It requires a documented cloud risk assessment, jurisdiction and sovereignty analysis, classification-appropriate controls such as encryption with agency-controlled keys, and formal risk acceptance by the Accreditation Authority.

What security controls apply to RESTRICTED systems under NZISM?

RESTRICTED systems need all baseline controls plus encryption at rest and in transit, MFA for remote access, privileged account separation, 12-month log retention, supplier security assessments, and formal Certification and Accreditation before go-live.

Who must NZ government agencies report security incidents to?

Significant cyber incidents go to the NCSC within GCSB, criminal acts to NZ Police, and notifiable privacy breaches involving serious harm to the Office of the Privacy Commissioner under the Privacy Act 2020.