UNCLASSIFIED
the likelihood that the proposal will lead to:
o
the compromise or degradation of the public telecommunications network; and
o
the impairment of the confidentiality, availability or integrity of telecommunications across the
network; and,
the potential effect of that on the provision of certain services (including for example, central or local
government services, health or transport services); and
Any other matter that the GCSB considers relevant.
In some cases, a “network security risk” as defined above, may also be or overlap with a common security
risk. The difference is in the likelihood and how that risk may be exploited, and the potential effect that it
may have on critical national networks and services.
The focus on New Zealand’s national security in the Part 3 TICSA means that the duty to notify under the
TICSA is limited to:
Proposals that affect parts of networks which are designated “areas of specified security interest” –
these are the areas where these network security risks are more likely to arise (section 48 of the
TICSA); and
Situations when the network operator becomes aware of any network security risk that may arise if a
proposal is implemented (in any part of the network) (section 46(1) of the TICSA).
It also means that any consideration of a proposal that is found not to give rise to a “network security risk”
has only been reviewed in relation to New Zealand’s national security for the purpose of Part 3 TICSA, and
not broader network security risks which a network operator might commonly consider (such as privacy, or
commercial security controls).
The GCSB’s consideration of proposals will not constitute an endorsement of the proposal in any broader
security sense, and must not be considered as a substitute for standard business risk assessments,
standard due diligence, enterprise security reviews or any other form of assessment that a network
operator would usually perform when initiating a new project or change.
Similarly, while employing good information assurance practises supports the security of networks, the
GCSB will not consider in its assessment adherence to ‘information assurance’ practices (which network
operators would commonly use as part of their normal business practice) such as;
adherence to international standards;
privacy protection obligations;
any duties required of network operators under New Zealand legislation (other than TICSA); or
any other network security risk that does not involve a risk to national security.
What are the General Requirements?
Registration
Under Part 4 of the TICSA, network operators are required to register (section 60). The Register has been
established, and is maintained by the New Zealand Police. A Registrar has also been appointed.
Information about the Register and the registration process is available from the New Zealand Police.
Network operators must be registered within three months after becoming a network operator. Once
submitted, registration details need to be kept up-to-date with an annual review from November 2015.
If an organisation is uncertain whether they meet the definition of a network operator they should contact
the Registrar. Enquiries about registration should be directed to New Zealand Police, which oversee the
registration process.
Network operators can register by completing a form made available by contacting the Registrar through
the New Zealand Police website. 1
1http://www.police.govt.nz/advice-services/businesses-and-organisations/telecommunications-interception-
capability-security-0
Contact the TICSA team at ticsa@ncsc.govt.nz
Page 5