DrochaidHorizon3.ai
NodeZero/Australia & NZ compliance/NZISM
Australia & NZ compliance

NZISM — New Zealand Information Security Manual

The New Zealand Government's primary information security standard, maintained by the GCSB and National Cyber Security Centre. A prescriptive manual covering 20+ chapters from network security and access control to cryptography and gateway architecture.

See where NodeZero applies

What is the NZISM?

The New Zealand Information Security Manual is the New Zealand Government's primary information security standard, maintained by the Government Communications Security Bureau (GCSB) and the National Cyber Security Centre (NCSC). The NZISM provides mandatory security requirements and recommended controls across 20+ chapters covering everything from governance and personnel security to enterprise systems, network security, cryptography, and gateway architecture. Compliance is required for New Zealand Government agencies and is increasingly referenced by organisations in the wider public sector and critical infrastructure.

Unlike frameworks that operate at a high level of abstraction, the NZISM is prescriptive -- it specifies password length requirements, mandates network segmentation between zones of different classification levels, defines gateway architectures, and sets patching timeframes. This specificity makes it well-suited to technical validation: either systems meet the requirements or they don't. For agencies undergoing NZISM assessments, the challenge is proving that technical controls are implemented correctly across every system in scope, not just documented in policy.

GCSB — NZISM

Where NodeZero applies

NodeZero tests the technical chapters of the NZISM where autonomous pentesting has direct relevance: Enterprise systems security (OS hardening, EOL detection, EDR effectiveness), Network security (segmentation, lateral movement, firewall rules), Access control and passwords (credential audit, MFA, privilege escalation, cloud IAM, AD attack graphs), Gateway security (boundary controls), Software security (web app OWASP Top 10, patching, rapid response to newly disclosed vulnerabilities, scanner integration), and Cryptography (cipher strength and protocol exposure). For chapters covering governance, personnel security, physical security, and media handling, we clearly map the boundaries so your assessment addresses the full NZISM scope.

NZISM v3.9 — November 2025

This mapping reflects our best-effort analysis of where NodeZero's autonomous pentesting produces relevant technical evidence against each requirement. It is intended to help you focus security effort on the controls NodeZero can test — not to serve as a compliance certification. You remain responsible for your own compliance assessment, for validating applicability to your environment, and for evidencing the requirements NodeZero does not directly test.

Showing coverage grouped by compliance category.

System hardening and patching (Chapters 12 and 14)

Tests OS hardening, service configuration, and exploitable weaknesses.

Internal pentestingCore

Returns proof-of-exploit evidence on which hardening gaps actually create attack paths — not a theoretical configuration review.

AD Password AuditCore

Directly hunts for default credentials across AD, service accounts, and network devices — one of the most common NZISM failure modes.

Endpoint Security EffectivenessCore

Per-host and per-vendor EDR block/allow data mapped to MITRE ATT&CK — concrete effectiveness metrics you can put in front of an NZISM assessor.

4 controls mapped

Network security and gateways (Chapters 18–19)

Tests firewall rules, network segmentation, and lateral movement, plus decoy-based validation of intrusion detection.

Segmentation testingCore

Enumerates IPs, ports, services, and applications to validate that zone boundaries actually hold.

Internal pentestingCore

Proves end-to-end attack paths that cross network boundaries — direct evidence of whether prevention rulesets actually contain an attacker.

NodeZero TripwiresPro & Elite

Decoy AD accounts baited for Kerberoasting and AS-REP roasting, paired with DC Kerberos logging and real-time SIEM/SOAR alerting, prove whether an in-network attack is actually detected — the detection half of 18.4.1 that internal pentesting's prevention/segmentation evidence above cannot cover on its own.

2 controls mapped

Authentication, access controls and cloud (Chapters 16 and 20)

Strong coverage. Tests credential strength, MFA enforcement, and privilege escalation.

AD Password AuditCore

First AI to solve GOAD in 14 minutes (Horizon3-reported); it is not uncommon for NodeZero to crack more than 50% of the passwords it tests on a first audit — direct evidence of whether the 16-character password policy actually holds.

Phishing Impact TestingCore

Takes credentials captured by your phishing tool and proves how far a phished login can actually reach — showing whether MFA and access controls contain a stolen credential or let it pivot to data and admin.

BloodHound (integrated)Core

AD attack-graph visualisation makes the over-privileged relationships NZISM expects agencies to rein in visible and actionable.

Cloud pentestingCore

Extends access-control validation into cloud environments — where NZISM scope increasingly lands for NZ government entities.

4 controls mapped

Gateway security (Chapter 19)

Tests gateway boundaries between networks of different trust levels.

Segmentation testingCore

Validates filtering and inspection effectiveness at network gateways — proves whether cross-zone exploit chains are actually contained.

External pentestingCore

Gateways are the first thing a real attacker touches; external pentesting generates traffic you can correlate with gateway logs.

2 controls mapped

Software security (Chapter 14)

Tests for exploitable application vulnerabilities, missing patches, and exposure to newly disclosed exploits.

Web application pentestingPriced separately

Tests applications for exploitable weaknesses — injection, broken access control and business-logic flaws — in pre-production as well as production, which is the review-or-test-before-production this control asks for. The control is a SHOULD across all classifications.

Internal pentestingCore

Returns proof-of-exploit evidence on which missing patches actually create attack paths.

Rapid ResponsePro & Elite

Rapid Response tests are delivered often within hours of disclosure, and in some cases ahead of the public patch.

Vulnerability Risk IntelligenceElite only

Overlays attacker-first validation on existing vulnerability scans — decision-grade prioritisation tied to real exploitability.

5 controls mapped

Cryptography (Chapter 17)

Partial coverage. Tests for weak cipher suites and unencrypted data in transit.

External pentestingCore

Probes public-facing services for unencrypted channels, deprecated TLS, weak ciphers, and downgradeable protocols — the exact failures Chapter 17 guards against.

1 control mapped
NZISM kit

See every control mapped to NodeZero

The full control-by-control coverage map — every NZISMrequirement matched to the NodeZero capability that produces evidence for it, with maturity-level grouping and source citations. We'll email you the link and a downloadable copy.

Who does this apply to?

The NZISM is mandatory for New Zealand Government agencies, including all departments, ministries, and Crown entities that handle government information. The framework is maintained by the GCSB's National Cyber Security Centre and is the primary reference for how government information systems must be secured. Agencies are expected to comply with the mandatory requirements and consider the recommended controls based on their risk profile.

Beyond central government, the NZISM is increasingly referenced by local government, district health boards, Crown Research Institutes, state-owned enterprises, and organisations in the wider public sector. Entities that provide IT services to the New Zealand Government -- including cloud providers, managed service providers, and systems integrators -- are typically required to demonstrate NZISM alignment as a condition of their contracts.

If your organisation handles New Zealand Government information, provides services to government agencies, or operates critical infrastructure in New Zealand, the NZISM is the security standard you are expected to meet. The framework is publicly available and updated regularly to reflect evolving threats and technology changes.

Trusted by 7,013 organisations worldwide
Powers the NSA's CAPT program310,332 pentests4.7 Gartner

Close the gaps before your next assessment

See how NodeZero generates audit-ready evidence for your compliance obligations. We'll walk you through where NodeZero applies for your specific framework.