What problem does it solve? NZ government agencies and their suppliers must comply with the NZISM, the mandatory information security framework published by GCSB/NCSC NZ, but interpreting its controls, classification requirements, and Certification & Accreditation process is complex and time-consuming. ## Core Features & Use Cases - Gap Analysis: Produces control-by-control tables with implementation status, evidence needed, and gap notes scoped to the system's classification level. - Certification & Accreditation Guidance: Walks through the full C&A pathway including SSP, SRMP, control validation, POA&M, and Accreditation Authority sign-off. - Policy Generation: Drafts NZISM-aligned documents such as Information Security Policies, Incident Response Plans, and Access Control Policies with verified control ID citations. - Use Case: A CISO at an NZ agency needs to assess whether a new SaaS platform can host RESTRICTED data. The skill produces a classification-scoped control checklist, a cloud risk assessment pathway, and a supplier due-diligence checklist covering ISO 27001, SOC 2 Type II, and IRAP evidence. ## Quick Start Ask the skill to perform an NZISM gap analysis for a system handling RESTRICTED data at your agency.