Security Risk Assessment Report Template for New Zealand
Generate a bespoke document
What is a Security Risk Assessment Report?
The Security Risk Assessment Report is a critical document used to evaluate and document an organization's security posture within the New Zealand regulatory environment. It is typically required when organizations need to assess their security risks, comply with regulatory requirements, or enhance their security framework. The report combines technical analysis, compliance assessment, and practical recommendations, addressing requirements set forth by New Zealand legislation including the Privacy Act 2020, Health and Safety at Work Act 2015, and the Protective Security Requirements framework. It serves as both a compliance document and a strategic planning tool, helping organizations identify and address security vulnerabilities while maintaining alignment with local regulatory requirements.
About the Security Risk Assessment Report
A Security Risk Assessment Report is a comprehensive evaluation document that systematically identifies, analyzes, and addresses security vulnerabilities within your organization. This critical document helps you understand your current security posture, comply with New Zealand regulatory requirements, and develop strategies to mitigate identified risks across physical, digital, and operational domains.
When do you need this document?
You need a Security Risk Assessment Report when conducting annual security reviews, responding to security incidents, or preparing for regulatory audits. Organizations typically require this assessment when implementing new systems or technologies, undergoing significant organizational changes, or seeking certification compliance. Government agencies and critical infrastructure providers must conduct regular assessments to meet Protective Security Requirements. Private organizations often need these reports when engaging with government contracts, handling sensitive data, or responding to cybersecurity insurance requirements. Financial institutions, healthcare providers, and technology companies regularly use these assessments to demonstrate due diligence and regulatory compliance.
Key legal considerations
Your Security Risk Assessment Report must address data protection requirements under the Privacy Act 2020, including how personal information is collected, stored, and protected from unauthorized access. The assessment should evaluate physical security measures required by the Health and Safety at Work Act 2015, ensuring workplace safety and visitor protection protocols are adequate. Consider potential criminal liability under the Crimes Act 1961, particularly regarding unauthorized system access and data breaches. Document your organization's compliance with applicable industry standards and international frameworks like ISO 27001. Include clear accountability measures, incident response procedures, and regular review schedules. Ensure the assessment covers both technical vulnerabilities and human factors that could compromise security.
Legal requirements in New Zealand
Under New Zealand law, your Security Risk Assessment Report must comply with the Privacy Act 2020's mandatory breach notification requirements and demonstrate appropriate safeguards for personal information. Government agencies must align with the Protective Security Requirements framework, addressing personnel, physical, and information security domains. The Intelligence and Security Act 2017 may apply if your organization handles national security information or operates critical infrastructure. Your assessment must consider the Health and Safety at Work Act 2015 requirements for workplace security and emergency procedures. Financial sector organizations must meet additional Reserve Bank of New Zealand guidelines for operational resilience. Document compliance with relevant industry-specific regulations and international standards that apply to your sector. Include regular review cycles and update procedures to ensure ongoing compliance with evolving regulatory requirements.
GOVERNING LAW
Applicable law
This Security Risk Assessment Report is drafted to comply with New Zealand law. Key legislation includes:
Health and Safety at Work Act 2015: Addresses physical security risks and workplace safety requirements, including security measures to protect workers and visitors.
Crimes Act 1961: Relevant sections dealing with computer systems, unauthorized access, and cybercrime that need to be considered in security risk assessments.
Intelligence and Security Act 2017: Particularly relevant for organizations dealing with national security or critical infrastructure, defining security requirements and reporting obligations.
Protective Security Requirements (PSR): Government mandated security requirements that set standards for security governance, personnel security, physical security, and information security.
Public Records Act 2005: Relevant for security assessments involving public sector information and record-keeping security requirements.
Telecommunications (Interception Capability and Security) Act 2013: Important for security assessments involving telecommunications infrastructure and network security.
Financial Markets Conduct Act 2013: Relevant for security risk assessments in financial institutions, particularly regarding information security and market integrity.
Explore 208,390+ legal templates
Explore 208,390+ legal templates
Genie's Security Promise
Genie is the safest place to draft. Here's how we prioritise your privacy and security.
Your data is private:
We do not train on your data; Genie's AI improves independently
All data stored on Genie is private to your organisation
Your documents are protected:
Your documents are protected by ultra-secure 256-bit encryption
We are ISO27001 certified, so your data is secure
Organizational security:
You retain IP ownership of your documents and their information
You have full control over your data and who gets to see it