
Protective security requirements assessment
The Protective Security Requirements (PSR) is a framework developed by the New Zealand Government to guide organisations in managing physical, personnel, information and governance security. It’s essential for any organisation handling government information - including private sector providers - to align with PSR standards. A formal assessment shows your government clients that your security posture meets their expectations.
Our PSR Maturity Assessment starts with a structured gap analysis across one or all PSR domains. We identify your current strengths and risks across governance, physical, information and personnel security.
We then work with you to build a prioritised programme that strengthens security maturity. This includes tailored advice, implementation support and establishing clear governance and reporting frameworks. It’s especially valuable for organisations needing to uplift security across the board, with a focus on long-term resilience and defensible reporting.
The PSR Maturity Assessment will begin with a gap assessment to understand your current strengths and weaknesses across the areas of security governance, physical security, personnel security and information security. We can assess against one or all of these domains.
Following this we will work with you to develop a work programme to support you to achieve your desired state and provide ongoing advice and guidance to help your teams implement the programme. As part of this we will also help you to establish appropriate governance and reporting of the programme. This is recommended for all organisations looking to uplift their security across the board to better protect their people, information and assets.
- Identify gaps across the PSR domains
- Build a tailored roadmap to improve PSR maturity
- Get guidance to support implementation and ongoing reporting
PSR Four Core Policy Areas
The Four Pillars of Protection
These four policy areas help identify, manage, and reduce risk. They serve as a practical framework for protecting people, information, and assets.
Security Governance
GOV 1 — Establish and maintain the right governance
GOV 2 — Take a risk-based approach
GOV 3 — Prepare for business continuity
GOV 4 — Build security awareness
GOV 5 — Manage risks when working with others
GOV 6 — Manage security incidents
GOV 7 — Be able to respond to increased threat levels
GOV 8 — Assess your capability
Information Security
INFOSEC 1 — Understand what you need to protect
INFOSEC 2 — Design your information security
INFOSEC 3 — Validate your security measures
INFOSEC 4 — Keep your security up to date
Personnel Security
PERSEC 1 — Recruit the right person
PERSEC 2 — Ensure their ongoing suitability
PERSEC 3 — Manage their departure
PERSEC 4 — Manage national security clearances
Physical Security
PHYSEC 1 — Understand what you need to protect
PHYSEC 2 — Design your physical security
PHYSEC 3 — Validate your security measures
PHYSEC 4 — Keep your security up to date
High level approach
Why work with us
Frequently asked questions
Am I obligated to follow the PSR?
If you are a government organisation (including Crown entities), the PSR is either mandated or encouraged. If you are a private sector organisation (especially if you handle government information or provide services to agencies) then it is also encouraged. The principles are sound and Bastion recommends anyone providing services to government organisations to consider adopting them
Will following the PSR keep me safe?
At a high level, if you maintain good maturity against each of the PSR requirements then you will be a lot safer than those who don't. It's all about minimising risk.
Can you help me improve in all the areas, or just information security?
We can help across all areas of the PSR. We have deep experience and expertise in all areas of the PSR.
Talk to an expert
Shortland Street,
Auckland 1010 New Zealand
Brandon Street
Wellington 6011 New Zealand
120 Spencer Street
Melbourne 3000 Australia