Snowflake says AWS Auckland deployment completed NZISM assessment
Snowflake says an independent NZISM Restricted assessment of its AWS Auckland deployment gives New Zealand agencies reusable evidence, but does not replace their certification, accreditation or approval-to-operate work.
Snowflake said on October 7 that an independent third party had assessed its deployment in the Amazon Web Services Auckland region against identified New Zealand Information Security Manual controls at the Restricted level.
For New Zealand government agencies, the result provides reusable evidence about Snowflake platform controls. It does not certify or accredit an agency system, nor does it grant that system approval to operate. Snowflake said agencies must complete their own certification and accreditation process before an authority to operate can be issued.
According to Snowflake, the unnamed assurance provider evaluated its controls against identified NZISM requirements. The company said agency chief information security officers and assessors can use the resulting control mappings and risk documentation to review their own configurations and integrations. Snowflake also said the work could avoid full-stack infrastructure audits and accelerate certification and accreditation, though it published no measured time saving.
The assessment concerns control evidence for Snowflake’s AWS Auckland deployment. For related context on the company’s regional infrastructure strategy, Snowflake has also outlined a separate EU sovereign-cloud integration plan.
The NZISM accreditation rules make the authorization boundary explicit. All systems must be certified as part of the accreditation process. A documented exception allows an accreditation decision before certification only when delaying operation would have a devastating and potentially long-lasting effect on an agency. Certification must then occur as soon as possible.
Accreditation is the step in which an Accreditation Authority accepts the residual security risk and formally approves a system to operate. For an agency, that authority is the agency head or a formally authorized delegate. The manual lists third-party reviews and assurance reports among the material the authority may consider. That makes the Snowflake assessment an input to the decision, not a replacement for it.
New Zealand’s Protective Security Requirements likewise direct agencies to validate that their security measures are correctly implemented and fit for purpose, and to complete the NZISM certification and accreditation process for ICT systems.
Government cloud guidance draws the same line around reusable evidence. The NZISM baseline security templates can reduce assurance work when combined with agency and all-of-government control certifications. But they do not cover every relevant NZISM control or line-of-business requirement, so additional agency certification work is likely. Separate NZISM cloud guidance says cloud decisions must be made case by case after a risk assessment and appropriate security consideration and implementation. It also says only data classified Restricted or below may be stored in a cloud service, whether hosted onshore or offshore.
Snowflake did not publish the assessment report, the assessor’s identity, the complete control list, testing period, exceptions, findings or remediation status. Its announcement also did not identify any New Zealand agency that has received certification, accreditation or approval to operate based on the assessment.
More news

Michael Smith gets 18 months for AI-assisted music streaming fraud

Anthropic cuts live internet access from all internal evaluations

AWS adds query-time source permission checks to Quick and Bedrock RAG
