UNCLASSIFIED Activation of The Plan 11. Activation of the CSERP occurs when a cyber security incident is identified as meeting the threshold of a cyber security emergency. If there are different views from agencies on whether the threshold for an emergency has been met, or not met, the CSERP is activated and a coordinated categorisation process is undertaken. Identification 12. The responsibility for identifying a cyber security emergency resides within the operational cyber security agencies: • CERT NZ • NCSC 13. These agencies receive reports from the public, from their partnerships (including the New Zealand Police) or from technical capabilities that identify vulnerabilities or threats, which may lead to a cyber security emergency. Categorisation 14. Categorisation occurs initially through a triage process performed by the operational cyber security agencies. The triage process is designed to ensure that resources dedicated to the response is commensurate to the severity and considers potential impacts as well as realised impact. Operational cyber security agencies undertake regular meetings that provide a basis of common understanding for incident severity. 15. The Coordinated Incident Management System (CIMS)3 is used when dealing with events managed by the National Security System – such as cyber security emergencies. The cyber incident categorisation matrix has been mapped to CIMS. 16. Categorisation is valuable to quickly inform and guide an appropriate response but given the dynamic nature of cyber security incidents and emergencies, the categorisation may change over time. The lead agency, in consultation with the coordination group, or a watch group will be responsible for reviewing the categorisation. Coordination 17. Cyber security emergencies categorised as SEVERE would be expected to activate the National Security System including establishment of a watch group and possibly ODESC. 18. Where a cyber security emergency is categorised as having a MAJOR severity rating, the identifying agency must consider whether broader discussion or interagency response is required. In such cases a Cyber Emergency Coordination Group may be held. 19. The identifying agency may also assess that the impacts of a MAJOR severity cyber emergency do not warrant the establishment of a Cyber Security Emergency Coordination Group. Where this occurs, the operational lead agency will coordinate the response and 3 The New Zealand Coordinated Incident Management System (CIMS) 3rd edition, https://www.civildefence.govt.nz/resources/coordinated-incident-management-system-cims-third-edition/ Page 6 of 12 UNCLASSIFIED 6

Select target paragraph3