NZISM — New Zealand Information Security Manual
The New Zealand Government's primary information security standard, maintained by the GCSB and National Cyber Security Centre. A prescriptive manual covering 20+ chapters from network security and access control to cryptography and gateway architecture.
See where NodeZero appliesWhat is the NZISM?
The New Zealand Information Security Manual is the New Zealand Government's primary information security standard, maintained by the Government Communications Security Bureau (GCSB) and the National Cyber Security Centre (NCSC). The NZISM provides mandatory security requirements and recommended controls across 20+ chapters covering everything from governance and personnel security to enterprise systems, network security, cryptography, and gateway architecture. Compliance is required for New Zealand Government agencies and is increasingly referenced by organisations in the wider public sector and critical infrastructure.
Unlike frameworks that operate at a high level of abstraction, the NZISM is prescriptive -- it specifies password length requirements, mandates network segmentation between zones of different classification levels, defines gateway architectures, and sets patching timeframes. This specificity makes it well-suited to technical validation: either systems meet the requirements or they don't. For agencies undergoing NZISM assessments, the challenge is proving that technical controls are implemented correctly across every system in scope, not just documented in policy.
Where NodeZero applies
NodeZero tests the technical chapters of the NZISM where autonomous pentesting has direct relevance: Enterprise systems security (OS hardening, EOL detection, EDR effectiveness), Network security (segmentation, lateral movement, firewall rules), Access control and passwords (credential audit, MFA, privilege escalation, cloud IAM, AD attack graphs), Gateway security (boundary controls), Software security (web app OWASP Top 10, patching, rapid response to newly disclosed vulnerabilities, scanner integration), and Cryptography (cipher strength and protocol exposure). For chapters covering governance, personnel security, physical security, and media handling, we clearly map the boundaries so your assessment addresses the full NZISM scope.
This mapping reflects our best-effort analysis of where NodeZero's autonomous pentesting produces relevant technical evidence against each requirement. It is intended to help you focus security effort on the controls NodeZero can test — not to serve as a compliance certification. You remain responsible for your own compliance assessment, for validating applicability to your environment, and for evidencing the requirements NodeZero does not directly test.
Showing coverage grouped by compliance category.
System hardening and patching (Chapters 12 and 14)
Tests OS hardening, service configuration, and exploitable weaknesses.
Internal pentestingCore
Returns proof-of-exploit evidence on which hardening gaps actually create attack paths — not a theoretical configuration review.
AD Password AuditCore
Directly hunts for default credentials across AD, service accounts, and network devices — one of the most common NZISM failure modes.
Endpoint Security EffectivenessCore
Per-host and per-vendor EDR block/allow data mapped to MITRE ATT&CK — concrete effectiveness metrics you can put in front of an NZISM assessor.
Network security and gateways (Chapters 18–19)
Tests firewall rules, network segmentation, and lateral movement, plus decoy-based validation of intrusion detection.
Segmentation testingCore
Enumerates IPs, ports, services, and applications to validate that zone boundaries actually hold.
Internal pentestingCore
Proves end-to-end attack paths that cross network boundaries — direct evidence of whether prevention rulesets actually contain an attacker.
NodeZero TripwiresPro & Elite
Decoy AD accounts baited for Kerberoasting and AS-REP roasting, paired with DC Kerberos logging and real-time SIEM/SOAR alerting, prove whether an in-network attack is actually detected — the detection half of 18.4.1 that internal pentesting's prevention/segmentation evidence above cannot cover on its own.
Authentication, access controls and cloud (Chapters 16 and 20)
Strong coverage. Tests credential strength, MFA enforcement, and privilege escalation.
AD Password AuditCore
First AI to solve GOAD in 14 minutes (Horizon3-reported); it is not uncommon for NodeZero to crack more than 50% of the passwords it tests on a first audit — direct evidence of whether the 16-character password policy actually holds.
Phishing Impact TestingCore
Takes credentials captured by your phishing tool and proves how far a phished login can actually reach — showing whether MFA and access controls contain a stolen credential or let it pivot to data and admin.
BloodHound (integrated)Core
AD attack-graph visualisation makes the over-privileged relationships NZISM expects agencies to rein in visible and actionable.
Cloud pentestingCore
Extends access-control validation into cloud environments — where NZISM scope increasingly lands for NZ government entities.
Gateway security (Chapter 19)
Tests gateway boundaries between networks of different trust levels.
Segmentation testingCore
Validates filtering and inspection effectiveness at network gateways — proves whether cross-zone exploit chains are actually contained.
External pentestingCore
Gateways are the first thing a real attacker touches; external pentesting generates traffic you can correlate with gateway logs.
Software security (Chapter 14)
Tests for exploitable application vulnerabilities, missing patches, and exposure to newly disclosed exploits.
Web application pentestingPriced separately
Tests applications for exploitable weaknesses — injection, broken access control and business-logic flaws — in pre-production as well as production, which is the review-or-test-before-production this control asks for. The control is a SHOULD across all classifications.
Internal pentestingCore
Returns proof-of-exploit evidence on which missing patches actually create attack paths.
Rapid ResponsePro & Elite
Rapid Response tests are delivered often within hours of disclosure, and in some cases ahead of the public patch.
Vulnerability Risk IntelligenceElite only
Overlays attacker-first validation on existing vulnerability scans — decision-grade prioritisation tied to real exploitability.
Cryptography (Chapter 17)
Partial coverage. Tests for weak cipher suites and unencrypted data in transit.
External pentestingCore
Probes public-facing services for unencrypted channels, deprecated TLS, weak ciphers, and downgradeable protocols — the exact failures Chapter 17 guards against.
See every control mapped to NodeZero
The full control-by-control coverage map — every NZISMrequirement matched to the NodeZero capability that produces evidence for it, with maturity-level grouping and source citations. We'll email you the link and a downloadable copy.
Who does this apply to?
The NZISM is mandatory for New Zealand Government agencies, including all departments, ministries, and Crown entities that handle government information. The framework is maintained by the GCSB's National Cyber Security Centre and is the primary reference for how government information systems must be secured. Agencies are expected to comply with the mandatory requirements and consider the recommended controls based on their risk profile.
Beyond central government, the NZISM is increasingly referenced by local government, district health boards, Crown Research Institutes, state-owned enterprises, and organisations in the wider public sector. Entities that provide IT services to the New Zealand Government -- including cloud providers, managed service providers, and systems integrators -- are typically required to demonstrate NZISM alignment as a condition of their contracts.
If your organisation handles New Zealand Government information, provides services to government agencies, or operates critical infrastructure in New Zealand, the NZISM is the security standard you are expected to meet. The framework is publicly available and updated regularly to reflect evolving threats and technology changes.
Close the gaps before your next assessment
See how NodeZero generates audit-ready evidence for your compliance obligations. We'll walk you through where NodeZero applies for your specific framework.