nzism

Provides NZISM compliance guidance, gap analysis, and certification workflows for NZ government systems.

Updated Jul 29, 2026
One-click install
npx skills add https://github.com/FR-LYO-CYS-AURA/GRC-Consultant --skill nzism-fr-lyo-cys-aura
Or copy as Structured Prompt for Agent▼
Please help me install this Agent Skill.
Skill: nzism
Source: https://github.com/FR-LYO-CYS-AURA/GRC-Consultant/tree/main/extracted-skills/nzism
Command: npx skills add https://github.com/FR-LYO-CYS-AURA/GRC-Consultant --skill nzism-fr-lyo-cys-aura

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve? NZ government agencies and their suppliers must comply with the NZISM, the mandatory information security framework published by GCSB/NCSC NZ, but interpreting its controls, classification requirements, and Certification & Accreditation process is complex and time-consuming. ## Core Features & Use Cases - Gap Analysis: Produces control-by-control tables with implementation status, evidence needed, and gap notes scoped to the system's classification level. - Certification & Accreditation Guidance: Walks through the full C&A pathway including SSP, SRMP, control validation, POA&M, and Accreditation Authority sign-off. - Policy Generation: Drafts NZISM-aligned documents such as Information Security Policies, Incident Response Plans, and Access Control Policies with verified control ID citations. - Use Case: A CISO at an NZ agency needs to assess whether a new SaaS platform can host RESTRICTED data. The skill produces a classification-scoped control checklist, a cloud risk assessment pathway, and a supplier due-diligence checklist covering ISO 27001, SOC 2 Type II, and IRAP evidence. ## Quick Start Ask the skill to perform an NZISM gap analysis for a system handling RESTRICTED data at your agency.

Frequently Asked Questions about nzism

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I perform an NZISM gap analysis for a government system?▼

Confirm the agency type, system classification level, and current security posture, then assess each applicable NZISM control as Implemented, Partial, Not Implemented, or N/A with evidence needed and gap notes. The skill generates the full control table scoped to your classification level.

What is the NZISM Certification and Accreditation process?▼

C&A requires a System Security Plan, Security Risk Management Plan, independent control validation, certification sign-off, a POA&M for findings, and formal accreditation by the Accreditation Authority. It is mandatory for systems handling Restricted information and above.

Can NZ government data be hosted offshore or in public cloud?▼

Offshore hosting is a risk-based decision, not a prohibition. It requires a documented cloud risk assessment, jurisdiction and sovereignty analysis, classification-appropriate controls such as encryption and agency-controlled keys, and formal risk acceptance by the Accreditation Authority.

What NZISM controls apply to RESTRICTED systems?▼

Restricted systems inherit all baseline controls plus encryption at rest, TLS 1.2+ in transit, MFA for remote access, 12-month log retention, supplier security assessments, and mandatory Certification and Accreditation before go-live.

Who must security incidents be reported to in New Zealand?▼

Cyber incidents are reported to the NCSC within GCSB, criminal acts to NZ Police, and notifiable privacy breaches meeting the serious-harm threshold to the Office of the Privacy Commissioner under the Privacy Act 2020.