Whilst reading through the New Zealand Information Security Manual (NZISM) I came across this recommendation in section 9.4 Using the Internet within 9. Personnel security:
It sounds almost trite, but the only practical approach to developing a security architecture for an organisation is to start at the most abstract level and consider what the business drivers and requirements are. This is fundamental to any approach for developing an organisation-wide strategy.
GCSB have published the New Zealand Information Security Manual (NZISM) which replaces the New Zealand Security of Information Technology (NZSIT) 400 series documents which were published in 2008.