UNCLASSIFIED
Activation of The Plan
11. Activation of the CSERP occurs when a cyber security incident is identified as meeting the
threshold of a cyber security emergency. If there are different views from agencies on
whether the threshold for an emergency has been met, or not met, the CSERP is activated
and a coordinated categorisation process is undertaken.
Identification
12. The responsibility for identifying a cyber security emergency resides within the operational
cyber security agencies:
•
CERT NZ
•
NCSC
13. These agencies receive reports from the public, from their partnerships (including the New
Zealand Police) or from technical capabilities that identify vulnerabilities or threats, which
may lead to a cyber security emergency.
Categorisation
14. Categorisation occurs initially through a triage process performed by the operational cyber
security agencies. The triage process is designed to ensure that resources dedicated to
the response is commensurate to the severity and considers potential impacts as well as
realised impact. Operational cyber security agencies undertake regular meetings that
provide a basis of common understanding for incident severity.
15. The Coordinated Incident Management System (CIMS)3 is used when dealing with events
managed by the National Security System – such as cyber security emergencies. The
cyber incident categorisation matrix has been mapped to CIMS.
16. Categorisation is valuable to quickly inform and guide an appropriate response but given
the dynamic nature of cyber security incidents and emergencies, the categorisation may
change over time. The lead agency, in consultation with the coordination group, or a watch
group will be responsible for reviewing the categorisation.
Coordination
17. Cyber security emergencies categorised as SEVERE would be expected to activate the
National Security System including establishment of a watch group and possibly ODESC.
18. Where a cyber security emergency is categorised as having a MAJOR severity rating, the
identifying agency must consider whether broader discussion or interagency response is
required. In such cases a Cyber Emergency Coordination Group may be held.
19. The identifying agency may also assess that the impacts of a MAJOR severity cyber
emergency do not warrant the establishment of a Cyber Security Emergency Coordination
Group. Where this occurs, the operational lead agency will coordinate the response and
3
The New Zealand Coordinated Incident Management System (CIMS) 3rd edition,
https://www.civildefence.govt.nz/resources/coordinated-incident-management-system-cims-third-edition/
Page 6 of 12
UNCLASSIFIED
6