Skip to content
Atlas
GET IN TOUCH

INDUSTRIESI12Government & Public Sector

Evidence for the
questions you will be asked.

IT for councils, Crown entities, and the businesses that supply them. In this sector the requirements are written down, which is genuinely helpful, and the standard of proof is higher than almost anywhere else.

The four sentences we hear most in your sector.

  • 01
    The tender asks where our data is held and we are not certain.

    A question that is easy to answer badly and difficult to answer with evidence, which is exactly what the tender is testing.

  • 02
    We are told we need to align to NZISM. Nobody has said what that means for us.

    Alignment is proportionate to what you handle. The first useful step is establishing which controls actually apply rather than treating the whole manual as mandatory.

  • 03
    Our supplier assurance questionnaire took three weeks.

    Because the evidence was assembled from scratch. Built once and kept current, the same questionnaire takes a day.

  • 04
    We hold information about members of the public.

    Which carries both legal obligations and a higher public expectation, and the second one is often the harder standard.

The systems you actually run.

Not a list of logos. These are the platforms we support, migrate, and get called about in this sector. If yours is missing, it usually means we have not worked with it, and we will say so rather than nod along.

Bring one group of systems forward
  • Security frameworks

    Published, specific, and testable, which makes this sector easier to work in than most once you know which parts apply.

    • NZISM
    • Protective Security Requirements
    • NCSC guidance
    • ISO 27001
    • NIST Cybersecurity Framework
  • Sovereignty and hosting

    Where the data sits, and the documentation that proves it, which is what a procurement process actually asks for.

    • New Zealand sovereign cloud
    • Onshore data centres
    • Residency evidence packs
    • Jurisdictional access records
  • Identity and access

    The control set every assurance process examines first, and the one with the clearest evidence requirements.

    • Microsoft Entra ID
    • Conditional access
    • Privileged access management
    • RealMe integration
    • Audit log retention
  • Records and information management

    Public records obligations make retention and disposal a statutory matter rather than a preference.

    • Public Records Act obligations
    • Retention and disposal schedules
    • SharePoint and records systems
    • Official information request support

Four things we do for government & public sector specifically.

  1. 01

    Working out which controls apply

    NZISM and the Protective Security Requirements are proportionate to what you handle. We establish the actual scope before anyone starts implementing, because working to the whole manual when only part applies is an expensive way to be no safer.

  2. 02

    A sovereignty position you can evidence

    Named facilities, their certifications, where backups and replicas sit, and who holds administrative access from which jurisdiction. Documented rather than asserted, because assertion does not survive a procurement process.

  3. 03

    Assurance answered from a standing pack

    Supplier assurance and security questionnaires answered from evidence you already hold and keep current, rather than researched fresh each time by the people who can least afford the week.

  4. 04

    Access and records that satisfy scrutiny

    Access by role with retained logs, and retention and disposal applied automatically against a schedule rather than by habit. Both are examined, and both are commonly found wanting.

The obligations that shape the work.

We make the systems match your obligations. We are not your lawyer or your compliance adviser, and where a question turns on interpretation we will tell you to take advice rather than guess on your behalf.

  • NZISM

    The New Zealand Information Security Manual sets the government standard for information security. Which controls apply depends on the classification of the information you handle.

  • Protective Security Requirements

    Cover governance, personnel, physical, and information security across government. Suppliers are frequently asked to demonstrate alignment as a condition of contract.

  • Privacy Act 2020

    Applies in full, and public sector organisations face a higher expectation than the minimum because of the nature of the information they hold and the trust attached to it.

  • Public Records Act 2005

    Public offices and local authorities must create and maintain records and dispose of them only under authority. That makes retention a statutory control rather than a policy preference.

Quoted against scope, with procurement-ready documentation

Quoted against the actual scope rather than a per-seat rate, because the control set that applies to you drives most of the cost and it varies widely. We provide the documentation a procurement or assurance process asks for as part of the engagement rather than as an extra. We will tell you where a requirement someone has quoted at you does not in fact apply, which is not an unusual finding.

Questions from your sector

01What does it mean to align to NZISM?

NZISM is the New Zealand Information Security Manual, and it sets government information security controls. Alignment is proportionate: which controls apply depends on the classification of the information you handle, so an organisation touching publicly available information and one handling classified material are held to very different standards. The first and most valuable piece of work is establishing your actual scope, because a great deal of money gets spent implementing controls that were never required.

02Does our data have to be hosted in New Zealand to supply government?

Not automatically, and the answer depends on the agency, the information, and the contract. Government cloud policy and agency-specific requirements both come into it, and the strictest requirement is often a clause in the contract rather than a general rule. What matters in every case is being able to evidence where data is held, where it is replicated, and who can reach it. Where onshore hosting genuinely is required, we deliver that through sovereign cloud.

03We are a private company supplying a government agency. Do these requirements apply to us?

Through your contract, usually yes. Agencies flow their security and privacy obligations down to suppliers, so you can find yourself required to demonstrate alignment to standards you have never read. The practical approach is to find out what your contracts already commit you to before an assurance questionnaire asks you to evidence it, which is a considerably less stressful order to do it in.

04How long does it take to get assurance-ready?

The assessment is a matter of weeks. How long the remediation takes depends entirely on where you are starting, and we will give you a ranked plan rather than a single number so you can see what buys the most assurance soonest. Organisations with a tender deadline usually want to know what can be genuinely closed before it and what has to be declared as in progress, and we will be straight with you about that distinction.

05What is the difference between NZISM and ISO 27001?

NZISM is the New Zealand government standard and is prescriptive about controls. ISO 27001 is an international standard describing a management system, and it is certifiable by an external auditor. They overlap substantially. Which one you need is decided by who is asking: agencies generally ask about NZISM and the Protective Security Requirements, while commercial customers generally ask about ISO 27001. Doing the work once against a mapped control set is much cheaper than running two programmes.

06Can you support a council or Crown entity directly?

Yes, and we are used to the procurement process that comes with it. We can also work alongside an existing internal team or incumbent provider on a defined scope, which is frequently how this sector prefers to engage, with responsibilities written down at the outset.

Start with the scope question.

Which controls actually apply to you, and which ones somebody has assumed. Getting that right first saves more money than anything else in this sector.

← All industries