UNCLASSIFIED
d) Places where data belonging to customers or end users, aggregates in large volumes,
either in transit or at rest - In particular, this covers:
iv.
Large databases which reside in the core of the network and customer Voice Mail Systems
(VMS), large email or message systems; and
v.
Any part of the network through which a significant proportion of the traffic on the network
travels. This includes points of interconnection or intersection with other networks or aggregation
points within the network. i.e. at the point of interconnection where the traffic of 10000 or more
end-users may be impacted.
Section 46(1) – Network operator identified Network Security Risks
A network operator must engage with the GCSB as soon as practicable after becoming aware of any
network security risk that may arise if the proposed decision, course of action, or change is
implemented.
If a network operator becomes aware that by implementing a proposed decision, course of action or
change – to any part of their network – a network security risk may arise, they are required to engage with
the GCSB.
In some cases a known security risk may be identified in a network by a network operator. A network
operator can look to the factors listed in section 50 of the TICSA to help identify if an implemented
decision, course of action, or change might give rise to a “network security risk”.
To keep the network security processes streamlined, network operators may notify the GCSB of the
network security risk using the notification template supplied. These will be treated in the same way as a
section 48 notification.
Exemptions from Duty to Provide Notification
Exemptions from the duty to engage and notify pursuant to ss 46(1) and 48, may be granted by the
Director-General of the GCSB, if the Director-General is satisfied that the matter to which the exemption
relates will not give rise to a network security risk (section 49).
Exemptions can be granted to individual network operators or a class of network operators. The GCSB will
notify individual network operators directly in writing of any exemption applying only to them. Exemptions
that apply to a class of network operators will be published on the GCSB website. Written notification will
also be sent to all network operators falling in that class.
Network operators may request exemptions from the GCSB. A template for such requests is available on
our website. Sufficient information is required to allow consideration of whether the matter to which the
requested exemption relates will give rise to a network security risk or not.
Exemptions are set out in a separate notice issued by the Director-General.
The current exemptions applicable to all or a class of network operators are available on the NCSC
website: www.ncsc.govt.nz/ticsa
Contact the TICSA team at ticsa@ncsc.govt.nz
Page 9