CybersecurityStandard

NZISM

New Zealand Information Security Manual

The New Zealand Information Security Manual (NZISM) is the New Zealand Government’s information security framework that provides baseline security controls, processes, and guidance to help organizations protect information systems and manage cybersecurity risks effectively.

Overview

The New Zealand Information Security Manual (NZISM) is the New Zealand Government’s authoritative framework for information assurance and information systems security, developed and maintained by the Government Communications Security Bureau (GCSB). The NZISM provides a comprehensive set of mandatory baseline controls, security processes, and recommended practices designed to protect government information, systems, and services from security threats. It supports a risk-based approach to information security by establishing requirements for areas such as asset management, identity and access management, authentication, logging, incident management, supply chain security, and risk management. The NZISM forms an integral part of New Zealand’s Protective Security Requirements (PSR) framework and promotes a consistent approach to safeguarding the confidentiality, integrity, and availability of information across government agencies. While primarily intended for government organizations, it is also widely used by Crown entities, local government bodies, contractors, and private sector organizations seeking to align with New Zealand government security standards.

Related in Cybersecurity

CybersecurityStandard

NDIS Practice Standards and Quality Indicators v4

The NDIS Practice Standards and Quality Indicators v4 is Australia's quality and compliance framework for registered NDIS providers, defining the standards and quality indicators required to deliver safe, person-centred, and high-quality disability supports and services.

NDIS Quality and Safeguards Commission • Australia • v4

View details
CybersecurityStandard

NDIS SIL Module — NDIS Supported Independent Living Module

The NDIS Supported Independent Living (SIL) Module is a supplementary NDIS Practice Standards module that sets quality and safety requirements for providers delivering Supported Independent Living services, ensuring participants receive person-centred supports that promote independence, choice, inclusion, and wellbeing.

NDIS Quality and Safeguards Commission • Australia

View details
CybersecurityStandard

CCC-2: 2024 — Cloud Cybersecurity Controls

The Cloud Cybersecurity Controls (CCC – 2: 2024) define minimum cybersecurity requirements for cloud computing services used by Cloud Service Providers (CSPs) and Cloud Service Tenants (CSTs) in Saudi Arabia. The controls aim to enhance national cybersecurity goals and mitigate cyber risks.

National Cybersecurity Authority (NCA) • Saudi Arabia • v2: 2024

View details
CybersecurityStandard

OTCC-1:2022 — Operational Technology Cybersecurity Controls

The Operational Technology Cybersecurity Controls (OTCC-1:2022), developed by Saudi Arabia’s National Cybersecurity Authority (NCA), establish minimum cybersecurity requirements for Operational Technology (OT) and Industrial Control Systems (ICS) environments. The framework aims to protect critical infrastructure from cyber threats and enhance operational resilience, safety, and security. OTCC consists of 4 domains, 23 subdomains, 47 controls, and 122 sub-controls, with requirements categorized across three control levels (L1, L2, and L3) based on facility criticality and risk.

National Cybersecurity Authority (NCA) • Saudi Arabia • v2022

View details

Ready to manage these frameworks?

6clicks maps regulations to controls, evidence and risks — automatically.

Book your strategy call