Overview
The New Zealand Information Security Manual (NZISM) is the New Zealand Government’s authoritative framework for information assurance and information systems security, developed and maintained by the Government Communications Security Bureau (GCSB). The NZISM provides a comprehensive set of mandatory baseline controls, security processes, and recommended practices designed to protect government information, systems, and services from security threats. It supports a risk-based approach to information security by establishing requirements for areas such as asset management, identity and access management, authentication, logging, incident management, supply chain security, and risk management. The NZISM forms an integral part of New Zealand’s Protective Security Requirements (PSR) framework and promotes a consistent approach to safeguarding the confidentiality, integrity, and availability of information across government agencies. While primarily intended for government organizations, it is also widely used by Crown entities, local government bodies, contractors, and private sector organizations seeking to align with New Zealand government security standards.