NZCSS 400
New Zealand Communications
Security Standard No 400 (Document
GCSB
classified CONFIDENTIAL)
CONDFIDENTIAL document available
on application to authorised
personnel
Information classification
Protective Security Requirements
(New Zealand Government Security
NZSIS
http://www.protectivesecurity.govt.n
z
ISO
https://www.iso.org/standard/54534.
html
ISO
https://www.iso.org/standard/75652.
Classification System Handling
Requirements for protectively
marked information and equipment)
Information security management
ISO/IEC 27001:2013
Information technology — Security
techniques — Information security
management systems —
Requirements
ISO/IEC 27002:2022
Information security, cybersecurity,
and privacy protection —
Information security controls
ISO/IEC 270xx series
Other standards and guidelines in
html
ISO
https://www.iso.org/standards.html
IS0
https://www.iso.org/standards.html
ISO
https://www.iso.org/standard/44381.
the ISO/IEC 270xx series, as
appropriate
Key management – commercial grade
ISO/IEC 11770
ISO/IEC 11770 Parts 1-6: Information
Technology – Security Techniques –
Key Management
Management of electronic records that may be used as evidence
ISO/IEC 27037:2012
Information Technology – Security
Techniques - Guidelines for
Identification, Collection, Aquisition
html
and Preservation of Digital Evidence
Personnel security
PSR
Protective Security Requirements
NZSIS
https://www.protectivesecurity.govt.
nz/personnel-security/
Protective Security Requirements
NZSIS
https://www.protectivesecurity.govt.
Physical security
PSR
nz/physical-security/
Privacy requirements
Privacy Act 2020
Office of The Privacy Commissioner
Parliamentary Counsel Office
http://www.privacy.org.nz
https://www.legislation.govt.
nz/
Privacy advice, guidance and tools
GCPO
to help government agencies
improve their privacy capability and
https://www.digital.govt.nz/standards
-and-guidance/privacy-security-andrisk/privacy/
maturity.
Risk management
ISO 31000:2018
Risk Management -- Guidelines
ISO
https://www.iso.org/standard/65694.
html
ISO/IEC 27005:2018
Information technology — Security
ISO
https://www.iso.org/standard/75281.
techniques — Information security
risk management
HB 436:2013
Risk Management Guidelines
html
Standards NZ
https://www.standards.govt.nz
(Companion to withdrawn standard
ISO 31000:2009)
7
Version_3.5__January-2022