1.1.47. A control with a “SHOULD” or “SHOULD NOT” requirement indicates that use, or non-use, of the control is considered good and recommended practice. Valid reasons for not implementing a control could exist, including: a. A control is not relevant in the agency; b. A system or ICT capability does not exist in the agency; or c. A process or control(s) of equal strength has been substituted. 1.1.48. While some cases may require a simple record of fact, agencies must recognise that non-use of any control, without due consideration, may increase residual risk for the agency. This residual risk needs to be agreed and acknowledged by the Accreditation Authority. In particular an agency should pose the following questions: a. Is the agency willing to accept additional risk? b. Have any implications for All-of-Government systems been considered? c. If, so, what is the justification? 1.1.49. A formal auditable record of this consideration and decision is required as part of the IA governance and assurance processes within an agency. Non-compliance 1.1.50. Non-compliance is a risk to the agency and may also pose risks to other agencies and organisations. Good governance requires these risks are clearly articulated, measures are implemented to manage and reduce the identified risks to acceptable levels, that the Accreditation Authority is fully briefed, acknowledges any residual and additional risk and approves the measures to reduce risk. 1.1.51. In some circumstances, full compliance with this manual may not be possible, for example some legacy systems may not support the configuration of particular controls. In such circumstances, a risk assessment should clearly identify compensating controls to reduce risks to an acceptable level. Acceptance of risk or residual risk, without due consideration is NOT adequate or acceptable. 1.1.52. It is recognised that agencies may not be able to immediately implement all controls described in the manual due to resource, budgetary, capability or other constraints. Good practice risk management processes will acknowledge this and prepare a timeline and process by which the agency can implement all appropriate controls described in this manual. 1.1.53. Simply acknowledging risks and not providing the means to implement controlsdoes not represent effective risk management. 1.1.54. Where multiple controls are not relevant or an agency chooses not to implement multiple controls within this manual the system owner may choose to logically group and consolidate controls when following the processes for non-compliance. Rationale Statements 1.1.55. A short rationale is provided with each group of controls. It is intended that this rationale is read in conjunction with the relevant controls in order to provide context and guidance. Risk management Risk Management Standards 1.1.56. For security risk management to be of true value to an agency it MUST relate to the specific circumstances of an agency and its systems, as well as being based on an industry recognised approach or risk management guidelines. For example, guidelines and standards produced by Standards New Zealand and the International Organization for Standardization (ISO). 1.1.57. The International Organization for Standardization has published an international risk management standard, including principles and guidelines on implementation, outlined in ISO 31000:2018 - Risk Management - Guidelines. Refer to the tables below for additional reference materials. The NZISM and Risk Management 1.1.58. The ISM encapsulates good and recommended best-practice in managing technology risks and mitigating or minimising threat to New Zealand government information systems. 1.1.59. Because there is a broad range of systems across government and the age and technological sophistication of these systems varies widely, there is no single governance, assurance, risk or controls model that will accommodate all agencies information and technology security needs. 1.1.60. The NZISM contains guidance on governance and assurance processes and technological controls based on comprehensive risk and threat assessments, research and environmental monitoring. 1.1.61. The NZISM encourages agencies to take a similar risk-based approach to information security. This approach enables the flexibility to allow agencies to conduct their business and maintain resilience in the face of a changing threat environment, while recognising the essential requirements and guidance provided by the NZISM. References 1.1.62. Key Standards Reference 5 Title Publisher Source NZISM New Zealand Information Security Manual GCSB https://www.nzism.gcsb.govt.nz PSR Protective Security Requirements NZSIS https://www.protectivesecurity.govt. nz Version_3.5__January-2022

Select target paragraph3