UNCLASSIFIED
(iii) administrative (privileged user) authentication credentials:
(d) any place in a public telecommunications network where data belonging to a customer or
end user aggregates in large volumes, being either data in transit or stored data:
(e) any area prescribed under subsection (2).
Although many of these terms are common to network operators, some further guidance on what they
mean is provided below.
a) Network Operations Centres (NOC) – The NOC is the function or functions through which network
operations are controlled, either as a function distributed among business units, or as a discrete
business unit in itself.
This includes Security Operations Centres (SOCs) if distinct from the NOC (since they also perform key
functions of network governance and oversight). Proposals that affect the operation of the NOC or SOC,
their oversight, control, and effective supervision, as well as core equipment used must be notified.
b) Lawful interception equipment or operations – Are any equipment used to provide Lawful
Intercept solutions as part of Section 2 of TICSA
c) Parts of networks that manage or store aggregates of information – These are the places
where sensitive information is likely to be stored, making the systems hardware and its
support/operation of specific security interest.
i.
Aggregated information about a significant number of customers. This refers to:
ii.
Aggregated authentication credentials of a significant number of customers. This refers to:
iii.
Databases which store data in bulk, such as call records or network traffic data.
Operations Support Systems (OSS), or Business Support Systems (BSS) and other forms of
business customer databases.
Proposals affecting the equipment or systems which interact directly and modify the network
core require notification.
Areas of the network which store authentication credentials and encryption keys.
The Evolved Packet Core (EPC) and the Home Location Register (HLR/HSS) in mobile
networks.
Administrative (privileged user) authentication credentials. This refers to:
Places where privileged user credentials are stored and audit and oversight controls are
retained.
Contact the TICSA team at ticsa@ncsc.govt.nz
Page 8