UNCLASSIFIED
notify the other cyber security agencies. The process is represented below (Figure 1) and
in all cases the responses are in accordance with the principles in paragraph 10.
Incident Identified (refer para. 12)
Categorisation (refer para. 14)
Minor
Moderate
Severe
NCSC Cat. 1
Major
NCSC Cat. 3 - 2
Coordination mechanism
Incident
response,
business as
usual
Cyber Security Emergency
Coordination Group
Typically chaired by CERT NZ,
NCSC or NCPO (refer para. 18)
National Security System.
May include Watch Groups and
ODESC (refer para. 17)
Regular reassessment of severity (refer para. 16)
Figure 1: Indicative severity and corresponding coordination mechanism
20. When activated, the Cyber Security Emergency Coordination Group will typically be
convened and chaired by a senior representative from the agency leading the response
and operates without activating the National Security System. The group will be comprised
of sufficiently senior officials to enable decision making, representing relevant policy and
operational agencies. Quorum for the group requires attendance of CERT NZ, DIA, DPMC,
NCSC and the New Zealand Police. Other agencies and organisations may be invited as
required.
21. Responsibilities of the chair include secretariat services. Where required this may include
providing briefs and updates to senior officials and relevant Ministers. Location and
facilities of the group rests with the chair. Guidance for members and a draft agenda is
included in Annex A and Annex B.
Escalation to the National Security System
22. The Cyber Security Emergency Coordination Group enables quick consultation across
agencies and considers whether an incident categorisation accurately reflects national
security risk and whether the operational response is sufficient. Its two primary functions
are to:
•
assist or expedite the process of activating the CSERP;
•
consider the necessity of escalating the response and activating the NSS.
Page 7 of 12
UNCLASSIFIED
7
•
C
o
o
r
d
i
n
a
t
i
o
n