5655 (2026). Hon Priyanca Radhakrishnan to the Minister responsible for the GCSB

Written Question
Published date: 13 Mar 2026
5655 (2026). Hon Priyanca Radhakrishnan to the Minister responsible for the GCSB: In which ministries, departments, or agencies, if any, is the Chief Information Security Officer (CISO) a member of the senior leadership team?
Hon Judith Collins: The Director-General of the GCSB holds the Government Chief Information Security Officer (GCISO) role. The GCISO promulgates the New Zealand Information Security Manual (NZISM), which details processes and controls essential for the protection of all New Zealand Government information and systems. The NZISM is intended for use by New Zealand Government departments, agencies and organisations. Crown entities, local government and private sector organisations are also encouraged to use the NZISM. All 40 mandated government agencies have reported that they have a CISO, as have all 7 voluntary reporting agencies. Crown entities are not mandated under the PSR or GCSIO. The PSR specifies that the CISO role should be a senior leader or an equivalent management position. The PSR Assurance Framework has only asked agencies to confirm that they have a designated CISO role; it has not asked agencies to outline the details of this role. It is common that an agency CISO will also have another role within the agency. This reporting year, the PSR has rolled out a new PSR Assurance Framework that asks some more specific questions relating to the CISO role, specifically around conflicts of interest, whether the CISO is a senior leader, and accountability arrangements if the role is outsourced (virtual CISO). PSR-reporting submissions by agencies are due 30 April 2026.