Framework Support

Assess Against the Frameworks That Matter

NZISM, NIST SP 800-53, ISO/IEC 27002, PSR, Privacy Act IPPs, and your own catalogues, with FISMA-aligned certification and accreditation workflows. One assessment methodology, one project record, every framework.

NZISM v3.9

New Zealand Information Security Manual

NZISM is the primary catalogue for New Zealand government security assessments, and it is AIS's home ground. Auditors can look up controls by ID (for example 16.1.27.C.01), search by topic, and filter by chapter or compliance level. Assessments, control validation, and the resulting C&A and ATO documentation all reference the NZISM baseline appropriate to the system's classification.

  • Control lookup by ID, topic, chapter, and compliance level
  • Risk assessments and control validation plans built against the NZISM baseline
  • C&A memo and ATO memo outputs consistent with NZ government expectations

FISMA-Aligned Workflows

Certification & Accreditation lifecycle

New Zealand's Certification & Accreditation process follows a FISMA-style assurance lifecycle: categorise the system, assess risk, validate controls against a catalogue, and issue a formal authorisation decision. AIS supports this lifecycle end to end, from security risk assessment through control validation to C&A and Authority to Operate documentation, all produced from one project record. AIS supports FISMA-aligned assurance workflows; it does not guarantee compliance, certification, or approval outcomes, which remain with authorised personnel.

  • System context and classification through to authorisation decision support
  • Control validation with recorded evidence behind every rating
  • Formal C&A, ATO and Emergency Accreditation memo outputs

NIST SP 800-53

Security and Privacy Controls

For organisations that assess against NIST SP 800-53, AIS provides the full catalogue for lookup, interpretation, and assessment. Controls can be searched by family and identifier (for example AC-2), and assessments follow the same evidence-led validation workflow used for every supported framework.

  • Full control catalogue with family and identifier search
  • Evidence-led validation and integrity checks before export
  • Useful for agencies mapping NZISM obligations to NIST equivalents

ISO/IEC 27002

Information Security Controls

AIS supports assessments against ISO/IEC 27002 controls (for example 5.15), making it suitable for enterprises and consultancies whose clients operate ISO 27001-based ISMS programmes. The same single project record produces assessment reports and findings tracking for ISO-based engagements.

  • Control lookup and interpretation guidance in Security Chat
  • Consistent assessment methodology across ISO and government frameworks
  • Findings Registry tracks remediation across all engagements

PSR Policy Framework

New Zealand Protective Security Requirements

AIS includes the PSR Policy Framework for assessments that extend beyond information security into governance, personnel, and physical security domains, as required for New Zealand public-sector protective security reporting.

  • PSR policies available alongside NZISM in the same assessment
  • Supports whole-of-organisation protective security reviews

Privacy Act IPPs

Information Privacy Principles

The 13 Information Privacy Principles of the New Zealand Privacy Act 2020 are available as an assessable catalogue, so privacy considerations can be evaluated inside the same project record as the security assessment.

  • IPPs assessable alongside security controls
  • One record covers both security and privacy findings

Custom Control Catalogues

Your policies, standards and baselines

Organisations can load their own control catalogues, internal policies, sector baselines, or tailored subsets, and run assessments against them with the full AIS workflow: AI-assisted risk development, evidence-led validation, integrity checks, and every report type. Per-audit catalogue selection lets different engagements use different baselines without affecting platform defaults.

  • Load internal policies and sector-specific baselines
  • Per-audit control database selection, locked at project creation
  • Same reporting pipeline as built-in frameworks

See Your Framework Inside AIS

A 30-minute walkthrough using the catalogue your team assesses against.