UNCLASSIFIED    the likelihood that the proposal will lead to: o the compromise or degradation of the public telecommunications network; and o the impairment of the confidentiality, availability or integrity of telecommunications across the network; and, the potential effect of that on the provision of certain services (including for example, central or local government services, health or transport services); and Any other matter that the GCSB considers relevant. In some cases, a “network security risk” as defined above, may also be or overlap with a common security risk. The difference is in the likelihood and how that risk may be exploited, and the potential effect that it may have on critical national networks and services. The focus on New Zealand’s national security in the Part 3 TICSA means that the duty to notify under the TICSA is limited to:   Proposals that affect parts of networks which are designated “areas of specified security interest” – these are the areas where these network security risks are more likely to arise (section 48 of the TICSA); and Situations when the network operator becomes aware of any network security risk that may arise if a proposal is implemented (in any part of the network) (section 46(1) of the TICSA). It also means that any consideration of a proposal that is found not to give rise to a “network security risk” has only been reviewed in relation to New Zealand’s national security for the purpose of Part 3 TICSA, and not broader network security risks which a network operator might commonly consider (such as privacy, or commercial security controls). The GCSB’s consideration of proposals will not constitute an endorsement of the proposal in any broader security sense, and must not be considered as a substitute for standard business risk assessments, standard due diligence, enterprise security reviews or any other form of assessment that a network operator would usually perform when initiating a new project or change. Similarly, while employing good information assurance practises supports the security of networks, the GCSB will not consider in its assessment adherence to ‘information assurance’ practices (which network operators would commonly use as part of their normal business practice) such as;     adherence to international standards; privacy protection obligations; any duties required of network operators under New Zealand legislation (other than TICSA); or any other network security risk that does not involve a risk to national security. What are the General Requirements? Registration Under Part 4 of the TICSA, network operators are required to register (section 60). The Register has been established, and is maintained by the New Zealand Police. A Registrar has also been appointed. Information about the Register and the registration process is available from the New Zealand Police. Network operators must be registered within three months after becoming a network operator. Once submitted, registration details need to be kept up-to-date with an annual review from November 2015. If an organisation is uncertain whether they meet the definition of a network operator they should contact the Registrar. Enquiries about registration should be directed to New Zealand Police, which oversee the registration process. Network operators can register by completing a form made available by contacting the Registrar through the New Zealand Police website. 1 1http://www.police.govt.nz/advice-services/businesses-and-organisations/telecommunications-interception- capability-security-0 Contact the TICSA team at ticsa@ncsc.govt.nz Page 5

Select target paragraph3