UNCLASSIFIED notify the other cyber security agencies. The process is represented below (Figure 1) and in all cases the responses are in accordance with the principles in paragraph 10. Incident Identified (refer para. 12) Categorisation (refer para. 14) Minor Moderate Severe NCSC Cat. 1 Major NCSC Cat. 3 - 2 Coordination mechanism Incident response, business as usual Cyber Security Emergency Coordination Group Typically chaired by CERT NZ, NCSC or NCPO (refer para. 18) National Security System. May include Watch Groups and ODESC (refer para. 17) Regular reassessment of severity (refer para. 16) Figure 1: Indicative severity and corresponding coordination mechanism 20. When activated, the Cyber Security Emergency Coordination Group will typically be convened and chaired by a senior representative from the agency leading the response and operates without activating the National Security System. The group will be comprised of sufficiently senior officials to enable decision making, representing relevant policy and operational agencies. Quorum for the group requires attendance of CERT NZ, DIA, DPMC, NCSC and the New Zealand Police. Other agencies and organisations may be invited as required. 21. Responsibilities of the chair include secretariat services. Where required this may include providing briefs and updates to senior officials and relevant Ministers. Location and facilities of the group rests with the chair. Guidance for members and a draft agenda is included in Annex A and Annex B. Escalation to the National Security System 22. The Cyber Security Emergency Coordination Group enables quick consultation across agencies and considers whether an incident categorisation accurately reflects national security risk and whether the operational response is sufficient. Its two primary functions are to: • assist or expedite the process of activating the CSERP; • consider the necessity of escalating the response and activating the NSS. Page 7 of 12 UNCLASSIFIED 7 • C o o r d i n a t i o n

Select target paragraph3