Skip to main content
Image coming soon

New Zealand NZISM Evidence & Implementation Kit

$249.00
Adding to cart… The item has been added
New Zealand NZISM · Information Security Manual · Evidence & Implementation Kit
Meet the NZISM, without decoding the manual yourself.
Every control area handed to you as an adopt-ready control, from governance and certification through access, cryptography and gateways to monitoring and incident response, with the evidence an assessor examines.
NZISM-ready in a weekend, not a quarter.

Here is the honest situation. The New Zealand Information Security Manual, issued by the GCSB, is the government's baseline of controls for protecting information systems. It runs from governance, risk management and system certification and accreditation through information classification, personnel and physical security, access control and approved cryptography, network and gateway security, system hardening, monitoring and incident response, to continuity. An agency or supplier that runs systems but cannot show certified and accredited systems, approved cryptography or its incident reporting is exactly where organizations fall short.

This Kit removes the guesswork. It is the NZISM control areas written as adopt-ready controls you personalize in a weekend, with the evidence an assessor examines.

What you get, the moment you buy

18
Control areas as adopt-ready controls. Every area, from governance and certification through access and cryptography to monitoring and response, written so you personalize and apply it.
18
Evidence-they-examine checklists. For each control, exactly what an assessor examines, plus where organizations fall short, so you close the gap first.
1
NZISM Control Matrix, pre-built. Every area in a working spreadsheet, ready to record status, owner and evidence location.
1
Gap & Readiness Assessment. Score each area and the workbook returns your readiness as a single percentage, and exactly what to fix next.

Grounded in the New Zealand Information Security Manual, with governance and risk, certification and accreditation, information classification, personnel and physical security, access control, approved cryptography, network and gateway security, system hardening, monitoring and incident response called out. Editable Word and Excel files.

Certification and accreditation authorize a system to operate
Under the NZISM, a system is certified against the applicable controls and then accredited to operate at its classification, and that authorization is periodically reviewed. A system running without it, or with cryptography that is not approved, will not survive an assessment. This Kit builds certification, accreditation and the control areas with the evidence an assessor asks for.

What one control looks like

This is confirming scope and applicability, where the NZISM begins. All 18 are built to this depth.

NZISM-1 Confirm scope and applicability GOVERNANCE
Put this control in place

Determine and document how the New Zealand Information Security Manual applies to [your organization name]'s information systems, identifying the in-scope systems and the classification of the information they hold, so scope is clear and the organization can evidence its applicability assessment.

Framework note.

The New Zealand Information Security Manual (NZISM) is the government's manual of baseline controls for protecting information systems, issued by the GCSB.

Evidence an assessor examines
  • An applicability assessment against the NZISM
  • In-scope systems identified
  • Records of the classification
Common finding they raise: An organization does not scope its systems against the NZISM.

Why this is not another template pack

  • The evidence is the point. A control you cannot evidence is a gap in an accreditation. This tells you what an assessor examines and where organizations fall short, for every area.
  • Certification, cryptography and gateways built in. Certification and accreditation, approved cryptography and secure gateways are written into the controls, the substance the NZISM requires.
  • Built on a mapped compliance corpus, not one person's opinion, from a graph of thousands of controls across standards.
  • It compounds. The NZISM aligns with ISO 27001 and the PSR, so this work feeds your wider security assurance.

Who buys this

New Zealand government agencies and their suppliers, and their security, IT and risk leads. Whether it is a first alignment or an accreditation-readiness pass, you save weeks and walk in with the control areas structured.

By the end of the weekend you will have
✓  An adopt-ready control for all 18 areas
✓  A completed NZISM control matrix
✓  The evidence an assessor examines
✓  Your certification, access and cryptography in place
✓  A readiness percentage and a fix list
✓  The gateway, monitoring and response gaps closed

Common questions

Is it really editable? Yes. Word and Excel files you own and adapt. No portal, no subscription.

Is this an official GCSB tool? No. It is an independent implementation toolkit grounded in the published NZISM structure, to get your controls and evidence in order fast.

Does it cover certification and accreditation? Yes. Certifying systems against the controls and accrediting them to operate is built as a control.

Does it help me self-assess? Yes. The Gap and Readiness assessment scores you against the control areas and ranks the fixes.

What if it is not for me? A 30-day money-back guarantee.

Do not run systems without controls you can show.
Every NZISM control area is fast to adopt with the Kit. It is instant, and it is guaranteed.
Add it to your cart and be NZISM-ready this weekend.

Instant digital download · 30-day money-back guarantee · The Art of Service Pty Ltd, GPO Box 2673, Brisbane QLD 4001 · support@theartofservice.com