Government agencies don't operate in isolation. Cloud providers, managed service providers, software vendors, consultants, and contractors all routinely access government systems and information. Under NZISM, agencies are responsible for ensuring these suppliers meet appropriate security standards — even though the agency doesn't directly control their security posture.
This is one of the most practically complex areas of NZISM compliance. It requires a structured approach to supplier assessment, contracting, and ongoing assurance.
What NZISM Requires
NZISM's supply chain and outsourcing requirements cover:
Security requirements in contracts — agencies must include security requirements in contracts with suppliers who handle official information or access government systems. These requirements should reference NZISM where applicable and specify what controls the supplier is required to maintain.
Supplier assessment before engagement — before engaging a supplier, the agency should assess their security posture. This includes reviewing the supplier's own compliance certifications (ISO 27001, etc.), requesting evidence of relevant controls, and assessing the risk they represent.
Ongoing assurance — supplier security is not a one-time assessment. Agencies need processes for monitoring supplier security posture, including periodic re-assessments and review of any security incidents affecting the supplier.
Exit and transition planning — contracts with suppliers should include provisions for secure data return or destruction when the engagement ends.
The New Zealand Government Procurement guidance reinforces these requirements from a procurement perspective.
Cloud Services and the NZISM Cloud Framework
Cloud computing creates specific challenges for NZISM compliance. When an agency uses a cloud service to host, process, or transmit government information, the cloud provider becomes a supplier requiring assessment.
The GCSB has published specific guidance on cloud computing under NZISM, including approved cloud security configurations and requirements for different classification levels. Key considerations:
- Data residency — where is data stored? For sensitive information, storage in New Zealand or specific jurisdictions may be required.
- Shared responsibility — cloud services operate on a shared responsibility model. Agencies remain responsible for controls they operate (access management, application configuration) even when the infrastructure is the provider's responsibility.
- Transparency and auditability — can the agency audit the provider's security controls? For higher-classification information, direct audit rights may be required.
Major cloud providers including Microsoft, Amazon Web Services, and Google Cloud have obtained certifications relevant to NZISM requirements. The New Zealand government cloud guidance provides a framework for assessing cloud service suitability.
Structuring Supplier Assessments
A risk-based approach to supplier assessment tiers suppliers by the risk they represent:
Tier 1 — High risk: Suppliers with access to RESTRICTED or above information, or with administrative access to critical systems. Require: ISO 27001 certification or equivalent, detailed security questionnaire, reference checks, contractual security requirements, annual re-assessment.
Tier 2 — Medium risk: Suppliers with access to SENSITIVE or IN-CONFIDENCE information, or with limited system access. Require: security questionnaire, review of certifications, contractual requirements, biennial re-assessment.
Tier 3 — Low risk: Suppliers providing services with no access to government information. Standard procurement security requirements, periodic review.
What a Vendor Security Questionnaire Should Cover
A vendor security questionnaire for government supplier assessment should cover:
- Governance — does the supplier have a documented information security policy? Who is responsible for security? How is security incorporated into their risk management?
- Access control — how is access to government information or systems controlled? How are privileged accounts managed?
- Incident response — does the supplier have an incident response plan? How and when would they notify the agency of a security incident?
- Subcontractors — does the supplier use subcontractors who may have access to government information? What security requirements do they impose on subcontractors?
- Data handling — how is government information stored, transmitted, and disposed of? Where is it located?
- Security testing — does the supplier conduct regular security testing (penetration testing, vulnerability scanning)?
- Certifications — what security certifications does the supplier hold? (ISO 27001, SOC 2, etc.)
AccreditAZ includes a vendor questionnaire module — send security questionnaires to suppliers, track responses, and link supplier risk assessments to your NZISM compliance posture. Learn more.