nzism

Provides NZISM compliance guidance, gap analysis, and certification workflows for NZ government systems.

Updated Jul 29, 2026
One-click install
npx skills add https://github.com/FR-LYO-CYS-AURA/GRC-Consultant --skill nzism-fr-lyo-cys-aura
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: nzism
Source: https://github.com/FR-LYO-CYS-AURA/GRC-Consultant/tree/main/extracted-skills/nzism
Command: npx skills add https://github.com/FR-LYO-CYS-AURA/GRC-Consultant --skill nzism-fr-lyo-cys-aura

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve? NZ government agencies and their suppliers must comply with the NZISM, the mandatory information security framework published by GCSB/NCSC NZ, but interpreting its controls, classification requirements, and Certification & Accreditation process is complex and time-consuming. ## Core Features & Use Cases - Gap Analysis: Produces control-by-control tables with implementation status, evidence needed, and gap notes scoped to the system's classification level. - Certification & Accreditation Guidance: Walks through the full C&A pathway including SSP, SRMP, control validation, POA&M, and Accreditation Authority sign-off. - Policy Generation: Drafts NZISM-aligned documents such as Information Security Policies, Incident Response Plans, and Access Control Policies with verified control ID citations. - Use Case: A CISO at an NZ agency needs to assess whether a new SaaS platform can host RESTRICTED data. The skill produces a classification-scoped control checklist, a cloud risk assessment pathway, and a supplier due-diligence checklist covering ISO 27001, SOC 2 Type II, and IRAP evidence. ## Quick Start Ask the skill to perform an NZISM gap analysis for a system handling RESTRICTED data at your agency.

Frequently Asked Questions about nzism

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I perform an NZISM gap analysis for a government system?

Confirm the agency type, system classification level, and current security posture, then assess each applicable NZISM control as Implemented, Partial, Not Implemented, or N/A with evidence needed and gap notes. The skill generates the full control table scoped to your classification level.

What is the NZISM Certification and Accreditation process?

C&A requires a System Security Plan, Security Risk Management Plan, independent control validation, certification sign-off, a POA&M for findings, and formal accreditation by the Accreditation Authority. It is mandatory for systems handling Restricted information and above.

Can NZ government data be hosted offshore or in public cloud?

Offshore hosting is a risk-based decision, not a prohibition. It requires a documented cloud risk assessment, jurisdiction and sovereignty analysis, classification-appropriate controls such as encryption and agency-controlled keys, and formal risk acceptance by the Accreditation Authority.

What NZISM controls apply to RESTRICTED systems?

Restricted systems inherit all baseline controls plus encryption at rest, TLS 1.2+ in transit, MFA for remote access, 12-month log retention, supplier security assessments, and mandatory Certification and Accreditation before go-live.

Who must security incidents be reported to in New Zealand?

Cyber incidents are reported to the NCSC within GCSB, criminal acts to NZ Police, and notifiable privacy breaches meeting the serious-harm threshold to the Office of the Privacy Commissioner under the Privacy Act 2020.