← SecureAZ Blog

Compliance · 6 min read · Published 24 April 2026 · Reviewed 17 August 2026

NZISM Control 3.2.18: Security Awareness Training Requirements for NZ Agencies

NZISM Control 3.2.18.C.01 makes the CISO accountable for security awareness training in NZ government agencies. Here's what the control requires and how to evidence compliance.

The NZ Information Security Manual (NZISM) is the authoritative standard for information security in New Zealand government agencies. It's published by the Government Communications Security Bureau and is mandatory for all agencies covered by the Public Service Act.

Control 3.2.18.C.01 is one of its most directly actionable requirements for CISOs and security managers: it places explicit accountability for security awareness and training at the CISO level. Understanding what this control requires — and how to evidence it — is essential for any NZ government security leader.

What Control 3.2.18.C.01 Requires

The control states that the CISO is responsible for overseeing the development and operation of information security awareness and training programs within the agency.

Three words in that sentence carry the most weight:

Overseeing — this isn't a delegatable control. The CISO must have direct visibility of the programme's operation, not just a policy that says training exists.

Development — the programme must be developed, not just procured. The CISO is responsible for ensuring content is appropriate for the agency's threat environment and classification requirements.

Operation — the programme must be running continuously, not activated for audits. Completion records, simulation results, and refresh schedules must exist and be current.

The NZISM places this control in the Security Awareness and Training section (3.2.18), which covers the full lifecycle: establishing the programme, delivering initial and ongoing training, and measuring effectiveness.

The Broader NZISM Awareness Framework

Control 3.2.18.C.01 doesn't sit in isolation. The surrounding controls establish a complete framework:

  • Agencies must establish and maintain a security awareness programme (3.2.18.C.02)
  • All personnel with access to agency systems must complete security awareness training (3.2.18.C.03)
  • Training must be provided at induction and at regular intervals thereafter
  • Training must be updated when the threat environment changes

Together, these controls mean a single onboarding training event is not NZISM compliant. The standard requires a living programme with regular delivery, records of completion, and a mechanism for updating content in response to evolving threats.

Evidence Requirements for NZISM Audits

NZISM assessments — whether conducted internally, by the NCSC, or by an appointed auditor — look for specific evidence against each control. For 3.2.18.C.01, auditors will ask:

  • Who is the accountable CISO and what is their documented role in the training programme?
  • What is the training programme design and schedule?
  • What are the completion rates for the current period?
  • How is training content reviewed and updated?
  • Are there phishing simulation records?
  • How are new staff trained before system access?

The absence of completion records is a finding, even if training was delivered. The NZISM requires documented evidence, not verbal assurance. Your training platform must be able to export reports that directly address these questions.

Connecting to the NCSC Approved Supplier Requirement

For government agencies, working with an NCSC-approved supplier provides direct assurance that the training programme meets NZISM requirements. Approved suppliers have demonstrated content alignment with NZ government threat priorities and security classification requirements.

This matters specifically for CISO accountability under 3.2.18.C.01 — the CISO must be able to demonstrate that the supplier they've selected meets the standard. Approved supplier status is the most direct way to evidence this.

The Classification Context

NZISM operates alongside the New Zealand Government Security Classification System. Agencies handling RESTRICTED or above information have heightened training obligations — staff must understand classification markings, handling requirements, and the consequences of mishandling classified material.

Awareness training for agencies in this category must cover:

  • Classification marking identification and application
  • Handling requirements for RESTRICTED and SENSITIVE information
  • Reporting obligations when classified material is mishandled
  • Clean desk and screen lock policies

Generic commercial security awareness training typically doesn't cover this material. NZ government-specific content that addresses classification requirements is a NZISM compliance requirement, not an optional extra.

Implementation Pathway for CISOs

For a CISO at a NZ government agency looking to build or strengthen their 3.2.18.C.01 compliance position:

  1. Document the programme — create a written security awareness training plan that covers scope, content, frequency, and accountability
  2. Select an approved platform — use an NCSC-approved supplier to ensure content alignment
  3. Enrol all personnel — every staff member with system access, not just IT staff
  4. Run induction training — before or on day one for new staff
  5. Set refresh schedule — quarterly is recommended for agencies with higher classification obligations
  6. Run phishing simulations — quarterly and after any relevant threat advisory from CERT NZ or the NCSC
  7. Export and retain records — monthly completion reports retained for audit purposes

SecureAZ holds NCSC NZ approved supplier status, provides NZISM-aligned training content, and produces the completion records and compliance documentation that CISOs need to evidence Control 3.2.18.C.01. Contact us for a government procurement pathway.

External references: