ISO Guide 73:2019 Risk Management – Vocabulary – ISO Guidelines for use in Standards NIST SP 800-30 rev. 1 https://www.iso.org/standar d/44651.html Guide for conducting Risk NIST Assessments https://nvlpubs.nist.gov/nistpubs/ Legacy/SP/nistspecialpublication80030r1.pdf Security Management HB 167:2006 Security Risk Management Standards NZ https://www.standards.govt.nz Parliamentary Counsel Office https://www.legislation.govt.nz/ Security And Intelligence Legislation Intelligence and Security Act 2017 Telecommunications (Interception Parliamentary Counsel Capability and Security) Act 2013 (as amended) https://www.legislation.govt.nz/ Office Rationale & Controls 1.1.64. Non-compliance 1.1.64.R.01. Rationale Controls for classified systems and information within this manual with a “MUST” or “MUST NOT” compliance requirementcannot be effectively individually risk managed by agencies without jeopardising their own, multi-agency or All-of-Government information assurance. 1.1.64.R.02. Rationale Controls within this manual with a “SHOULD” and “SHOULD NOT” requirement may be risk managed by agencies. As the individual control security risk for non-compliance is not as high as those controls with a ‘MUST’ or ‘MUST NOT’ requirement, the Accreditation Authority can consider the justification for the acceptance of risks, consider any mitigations then acknowledge and accept any residual risks. 1.1.64.R.03. Rationale Deviations from the procedures and controls in the NZISM may represent risks in themselves. It is important that governance and assurance is supported by evidence, especially where deviations from the procedures and controls in the NZISM are accepted. In this case a formal approval or signoff by the Accreditation Authority is essential. Ultimately, the Agency Head remains accountable for the ICT risks and information security of their agency. 1.1.64.C.01. ControlSystem Classification(s): All Classifications; Compliance: MUST [CID:127] System owners seeking a dispensation for non-compliance with any baseline controls in this manual MUST be granted a dispensation by their Accreditation Authority. Where High Assurance Cryptographic Systems (HACS) are implemented, the Accreditation Authority will be the Director-General GCSB or a formal delegate. 1.1.65. Justification for non-compliance 1.1.65.R.01. Rationale Without sufficient justification and consideration of security risks by the system owner when seeking a dispensation, the agency head or their authorised delegate will lack the appropriate range of information to the make an informed decision on whether to accept the security risk and grant the dispensation or not. 1.1.65.C.01. ControlSystem Classification(s): All Classifications; Compliance: MUST [CID:131] System owners seeking a dispensation for non-compliance with baseline controls MUST complete an agency risk assessment which documents: the reason(s) for not being able to comply with this manual; the effect on any of their own, multi-agency or All-of-Government system; the alternative mitigation measure(s) to be implemented; The strength and applicability of the alternative mitigations; an assessment of the residual security risk(s); and a date by which to review the decision. 1.1.66. Consultation on non-compliance 1.1.66.R.01. Rationale When an agency stores information on their systems that belongs to a foreign government they have an obligation to inform and seek agreement from that third party when they do not apply all appropriate controls in this manual. These third parties will place reliance on the application of controls from the NZISM. If the agency fails to implement all appropriate controls, the third party will be unaware that their information may have been placed at a heightened risk of compromise. As such, the third party is denied the opportunity to consider their own additional risk mitigation measures for their information in light of the agency’s desire to risk manage controls from this manual. 1.1.66.R.02. Rationale Most New Zealand Government agencies will store or processes information on their systems that originates from another New Zealand Government Agency. The use of the NZ Government Security Classification System, and implementation of its attendant handling instructions, provides assurance to the originating agency that the information is adequately safeguarded. 1.1.66.R.03. 8 Rationale Version_3.5__January-2022

Select target paragraph3