NZISM requires agencies to maintain a risk register as part of their security risk management programme. The Government Communications Security Bureau expects this register to be current, actively maintained, and used to inform security decisions — not just produced for assessment purposes.
In practice, many agencies have a risk register that exists primarily as a document. It was created when the system was first certified, reviewed briefly before the last assessment, and otherwise not touched. This is both a compliance risk and a genuine security risk — because the threats and vulnerabilities facing your systems change continuously.
Here's how to build a risk register that satisfies NZISM requirements and is genuinely useful.
What NZISM Requires
NZISM's risk management chapter requires agencies to:
- Identify and assess information security risks systematically
- Document risks in a format that enables prioritisation and decision-making
- Assign ownership of risks to accountable individuals
- Document treatment decisions for each risk
- Review the risk register regularly and when significant changes occur
- Use the risk register to inform the accreditation process
The PSR self-assessment guidance reinforces these requirements from a governance perspective. The risk register is the primary artefact demonstrating that the agency takes a risk-based approach to security.
The Structure of a Good Risk Register Entry
Each risk in the register should include:
Risk description — what is the risk? Describe it in terms of a threat acting on a vulnerability to produce a consequence. "A malicious insider exploiting excessive access privileges to exfiltrate classified information" is a risk description. "Access control" is not.
Likelihood — how probable is this risk materialising? Use a consistent scale (1–5 or similar) with documented definitions for each level. Reference threat intelligence from the NCSC's Cyber Threat Report where relevant.
Consequence — if the risk materialises, what is the impact? Consider: harm to individuals, operational disruption, reputational damage, legal and regulatory exposure, financial cost. Again, use a consistent scale with documented definitions.
Inherent risk rating — likelihood × consequence, before controls.
Current controls — what controls are currently in place to reduce this risk? Link to the relevant NZISM controls and evidence.
Residual risk rating — likelihood × consequence, after current controls.
Treatment decision — accept, mitigate, transfer, or avoid? For accepted risks, document the rationale and who accepted it. For risks being mitigated, link to the treatment plan.
Owner — who is accountable for this risk? Not a team — a named individual.
Review date — when was this risk last reviewed? When is the next review due?
Keeping the Register Current
The most common failure: the register is accurate at certification time and deteriorates thereafter.
Build a maintenance rhythm:
- Quarterly review — review all risks rated HIGH or CRITICAL. Are the threat landscape and controls still as assessed?
- Annual review — review all risks in the register. Update ratings, treatment decisions, and control references.
- Triggered review — any significant system change, security incident, or relevant threat intelligence (from NCSC alerts or similar) should trigger a review of relevant risks.
The NZISM guidance on security risk management specifies that the risk register must be reviewed as part of any significant change assessment. If you're making major changes to your system, the risk register review is not optional.
Connecting the Risk Register to Accreditation
The risk register is the primary input to the Accreditation Authority's decision. When the AA reviews the accreditation package, they are looking at the residual risk the agency is accepting when it authorises the system to operate.
Residual risks that are rated HIGH or CRITICAL should be explicitly presented to the AA with a recommendation — accept with conditions, or require further mitigation before accreditation. The AA's decision on each significant risk should be documented in the Accreditation Letter.
An assessor reviewing a risk register wants to see: that every significant risk has been identified, that treatment decisions are documented and current, that ownership is clear, and that the register is actually being used to manage the programme. A register with every risk rated LOW and every treatment decision marked "Accept" with no justification will attract questions.
AccreditAZ provides a structured risk register linked directly to your NZISM controls and accreditation documentation — so changes in control status automatically surface as risk register review prompts. Try it free.