ISO Guide 73:2019
Risk Management – Vocabulary –
ISO
Guidelines for use in Standards
NIST SP 800-30 rev. 1
https://www.iso.org/standar
d/44651.html
Guide for conducting Risk
NIST
Assessments
https://nvlpubs.nist.gov/nistpubs/
Legacy/SP/nistspecialpublication80030r1.pdf
Security Management
HB 167:2006
Security Risk Management
Standards NZ
https://www.standards.govt.nz
Parliamentary Counsel Office
https://www.legislation.govt.nz/
Security And Intelligence Legislation
Intelligence and Security Act 2017
Telecommunications (Interception
Parliamentary Counsel
Capability and Security) Act 2013 (as
amended)
https://www.legislation.govt.nz/
Office
Rationale & Controls
1.1.64.
Non-compliance
1.1.64.R.01.
Rationale
Controls for classified systems and information within this manual with a “MUST” or “MUST NOT” compliance requirementcannot be
effectively individually risk managed by agencies without jeopardising their own, multi-agency or All-of-Government information assurance.
1.1.64.R.02.
Rationale
Controls within this manual with a “SHOULD” and “SHOULD NOT” requirement may be risk managed by agencies. As the individual control
security risk for non-compliance is not as high as those controls with a ‘MUST’ or ‘MUST NOT’ requirement, the Accreditation Authority can
consider the justification for the acceptance of risks, consider any mitigations then acknowledge and accept any residual risks.
1.1.64.R.03.
Rationale
Deviations from the procedures and controls in the NZISM may represent risks in themselves. It is important that governance and assurance is
supported by evidence, especially where deviations from the procedures and controls in the NZISM are accepted. In this case a formal
approval or signoff by the Accreditation Authority is essential. Ultimately, the Agency Head remains accountable for the ICT risks and
information security of their agency.
1.1.64.C.01.
ControlSystem Classification(s): All Classifications; Compliance: MUST
[CID:127]
System owners seeking a dispensation for non-compliance with any baseline controls in this manual MUST be granted a dispensation by their
Accreditation Authority. Where High Assurance Cryptographic Systems (HACS) are implemented, the Accreditation Authority will be the
Director-General GCSB or a formal delegate.
1.1.65.
Justification for non-compliance
1.1.65.R.01.
Rationale
Without sufficient justification and consideration of security risks by the system owner when seeking a dispensation, the agency head or their
authorised delegate will lack the appropriate range of information to the make an informed decision on whether to accept the security risk and
grant the dispensation or not.
1.1.65.C.01.
ControlSystem Classification(s): All Classifications; Compliance: MUST
[CID:131]
System owners seeking a dispensation for non-compliance with baseline controls MUST complete an agency risk assessment which documents:
the reason(s) for not being able to comply with this manual;
the effect on any of their own, multi-agency or All-of-Government system;
the alternative mitigation measure(s) to be implemented;
The strength and applicability of the alternative mitigations;
an assessment of the residual security risk(s); and
a date by which to review the decision.
1.1.66.
Consultation on non-compliance
1.1.66.R.01.
Rationale
When an agency stores information on their systems that belongs to a foreign government they have an obligation to inform and seek
agreement from that third party when they do not apply all appropriate controls in this manual. These third parties will place reliance on the
application of controls from the NZISM. If the agency fails to implement all appropriate controls, the third party will be unaware that their
information may have been placed at a heightened risk of compromise. As such, the third party is denied the opportunity to consider their own
additional risk mitigation measures for their information in light of the agency’s desire to risk manage controls from this manual.
1.1.66.R.02.
Rationale
Most New Zealand Government agencies will store or processes information on their systems that originates from another New Zealand
Government Agency. The use of the NZ Government Security Classification System, and implementation of its attendant handling instructions,
provides assurance to the originating agency that the information is adequately safeguarded.
1.1.66.R.03.
8
Rationale
Version_3.5__January-2022