UNCLASSIFIED
TICSA Guidelines
The following Guidance has been prepared to support the management of the network security part (Part
3) of the Telecommunications (Interception Capability and Security) Act 2013 (the TICSA).
It sets out the process established by the TICSA and is designed to assist network operators and the
Government Communications Security Bureau (the GCSB) to work co-operatively and collaboratively with
each other, so that network security risks can be identified and addressed as early as possible.
Network Operator or Service Provider?
A network operator (as defined in section 3 of the TICSA) is;
a) a person who owns, controls, or operates a public telecommunications network; or,
b) a person who supplied (whether by wholesale or retail) another person with the capability to
provide a telecommunications service.
A service provider (also defined in section 3 of the TICSA) is;
a) means any person who, from within or outside New Zealand, provides or makes available in New
Zealand a telecommunications service to an end-user (whether or not as part of a business
undertaking and regardless of the nature of that business undertaking); but
b) does not include a network operator.
The Network Security provisions in Part 3 of TICSA only apply to network operators as defined in that
Act.
Part 3 of the TICSA relates to network security and outlines a framework under which network operators
are required to engage with the GCSB about proposed changes and developments with their networks
where these intersect with national security.
The framework sets out a path to identify and address, prevent, mitigate, or remove the network security
risks which may arise.
Section 7 of the TICSA;
Purpose of this Act relating to network security;
The purpose of this Act in relation to network security is to prevent, sufficiently mitigate, or remove
security risks arising from—
(a) the design, build, or operation of public telecommunications networks; and
(b) interconnections to or between public telecommunications networks in New Zealand or with
networks over-seas.
The TICSA (section 8) also sets out principles relating to network security that must, as far as practicable,
be applied by both the Director-General and each network operator in relation to network security risks.
Those principles are:
(a) The principle that network security risks that might arise from a proposed decision, course of action,
or change if implemented should be identified and addressed as early as possible:
(b) The principle that the Director-General and each network operator should work co-operatively and
collaboratively with each other in relation to the principle in paragraph (a).
Overview of the Guidance
This Guidance is issued by the Director-General of the GCSB under section 58 of the TICSA, to provide
information about the requirements on network operators under Part 3 of the TICSA.
Contact the TICSA team at ticsa@ncsc.govt.nz
Page 3