NZCSS 400 New Zealand Communications Security Standard No 400 (Document GCSB classified CONFIDENTIAL) CONDFIDENTIAL document available on application to authorised personnel Information classification Protective Security Requirements (New Zealand Government Security NZSIS http://www.protectivesecurity.govt.n z ISO https://www.iso.org/standard/54534. html ISO https://www.iso.org/standard/75652. Classification System Handling Requirements for protectively marked information and equipment) Information security management ISO/IEC 27001:2013 Information technology — Security techniques — Information security management systems — Requirements ISO/IEC 27002:2022 Information security, cybersecurity, and privacy protection — Information security controls ISO/IEC 270xx series Other standards and guidelines in html ISO https://www.iso.org/standards.html IS0 https://www.iso.org/standards.html ISO https://www.iso.org/standard/44381. the ISO/IEC 270xx series, as appropriate Key management – commercial grade ISO/IEC 11770 ISO/IEC 11770 Parts 1-6: Information Technology – Security Techniques – Key Management Management of electronic records that may be used as evidence ISO/IEC 27037:2012 Information Technology – Security Techniques - Guidelines for Identification, Collection, Aquisition html and Preservation of Digital Evidence Personnel security PSR Protective Security Requirements NZSIS https://www.protectivesecurity.govt. nz/personnel-security/ Protective Security Requirements NZSIS https://www.protectivesecurity.govt. Physical security PSR nz/physical-security/ Privacy requirements Privacy Act 2020 Office of The Privacy Commissioner Parliamentary Counsel Office http://www.privacy.org.nz https://www.legislation.govt. nz/ Privacy advice, guidance and tools GCPO to help government agencies improve their privacy capability and https://www.digital.govt.nz/standards -and-guidance/privacy-security-andrisk/privacy/ maturity. Risk management ISO 31000:2018 Risk Management -- Guidelines ISO https://www.iso.org/standard/65694. html ISO/IEC 27005:2018 Information technology — Security ISO https://www.iso.org/standard/75281. techniques — Information security risk management HB 436:2013 Risk Management Guidelines html Standards NZ https://www.standards.govt.nz (Companion to withdrawn standard ISO 31000:2009) 7 Version_3.5__January-2022

Select target paragraph3