UNCLASSIFIED
The Guidance is subordinate to TICSA itself, but is intended to give network operators more detail on what
to expect and what is required from the process. It sets out the GCSB’s understanding of the processes
that implement the TICSA’s network security framework.
It is intended to inform network operators of their obligations and duties as they relate to network
security under TICSA, in particular;
identify the types of network proposal the GCSB requires notification of;
identify the types of network proposal the GCSB does not require notification of;
outlines the process by which the GCSB can grant exemptions to the duty to notify;
outlines the process through which the GCSB will assess proposals and communicate responses; and
establishes expected timeframes and information required to be supplied with a proposal.
This Guidance is not binding on network operators, however, in any proceedings related to TICSA,
compliance with the Guidance will be treated as evidence of compliance with the applicable requirements
in the legislation (section 58).
TICSA places network security regulation responsibilities on the Director-General of the GCSB and so
refers to “the Director-General” throughout Parts 3 and 4. A team in GCSB’s National Cyber Security
Centre (NCSC) is tasked to work on this process and they will be the primary point of contact available
for network operators. For ease of reference, the Guidance refers to “the GCSB” when describing the
duties placed on the GCSB’s Director-General under TICSA.
This Guidance is the result of a process of consultation with network operators. The GCSB will continue to
work with network operators on the use and development of the Guidance.
Please raise any questions you have about the processes and responsibilities laid out in the Guidance to:
ticsa@ncsc.govt.nz
Focus of the network security part of TICSA:
New Zealand’s National Security
The focus of the network security part of the TICSA is the prevention, mitigation or removal of network
security risks.
The GCSB will work with network operators co-operatively and collaboratively so that risks to New
Zealand’s national security, arising from the design, build or operation of public telecommunications
networks and their interconnection to other networks both domestically and overseas, are identified and
addressed.
Proposed decisions, courses of action or changes notified by network operators (called “proposals”) are
considered by the GCSB to identify whether they would raise a network security risk.
“Network security risk” has a specific meaning under TICSA, it is defined as;
“any actual or potential security risk arising from –
(a) The design, build or operation of a public telecommunications network; or
(b) Any interconnection to or between public telecommunications networks in New Zealand or
with telecommunications networks overseas.”
“Security risk” is also defined by TICSA;
“it means any actual or potential risk to New Zealand’s national security.”
While “national security” is not specifically defined, for the purposes of the network security provision of
the TICSA, its meaning is inferred from the list of factors in s 50 that the GCSB must consider when
deciding whether a network security risk or significant network security risk is raised.
Section 50 is set out in full later in this Guidance, however in short, a network security risk requires
consideration of –
Contact the TICSA team at ticsa@ncsc.govt.nz
Page 4