UNCLASSIFIED
(a) comply with subsection (1)(a) before any steps are taken, as part of the procurement or
acquisition decision-making process, to approach the market (whether by request for quote,
tender , or otherwise) or comply with subsection (1)(b) during the development of a
business or change proposal; and
(b) ensure any notice given to the Director-General in compliance with subsection (1) is given
within sufficient time for the Director-General to consider whether to take action under
section 51.
“Proposed decision, course of action, or change…”
The timing of notification is important. Network Operators are required to notify the GCSB at the stage
when the decisions, courses of action or changes described are still proposals, yet to be implemented.
If a network operator is looking at procurement or acquisitions of any equipment, system, or service that
falls within an area of specified security interest, TICSA requires they must notify the GCSB before taking
any steps, as part of the procurement or acquisition decision-making process, to approach the market
(whether by request for quote, tender, or otherwise).
This means, for example, that notification is required either prior to (or at the time) a Request for
Proposals (RFP) is issued. If a network operator does not use a RFP process or similar, notification is
required before making the decision about procurement.
Providing notification before issuing a Request for Information (RFI) from vendors may in many cases be
too early, however some network operators may choose to provide notification at this point if the scope of
the proposal is narrowed so it can be practically assessed.
With any other change to the network in an area of specified security interest, network operators are
required to notify the GCSB during the development of a business or change proposal. This would include
for example notifying of purchasing of or sale to, another organisation, changing a contracted third party
provider, and changing remote access methods and/or authentication.
These requirements are to ensure the GCSB has sufficient time to consider proposals and fulfil its
regulatory function under TICSA. They also enable any network security risks to be identified and
addressed as early as possible in the network operator’s decision, course of action, or change process.
Allowing sufficient time for the GCSB to consider proposals will also help ensure minimal disruption to
network operators’ plans.
“… decision, course of action or change”
A proposed decision, course of action or change includes standard builds which might cover a particular
change replicated at many points of a network, and also ‘bulk changes’ - a series of changes that can be
treated as one overarching ‘bulk change’.
Network operators can submit a single (rather than repeated) notification for a standard build or a bulk
change.
Only proposed decisions, courses of action or changes that affect an “area of specified security interest”
need to be notified under section 48.
Section 47 of the TICSA defines area of specified security interest:
(1) In this section and section 48, an area of specified security interest, in relation to a network
operator, means—
(a) network operations centres:
(b) lawful interception equipment or operations:
(c) any part of a public telecommunications network that manages or stores—
(i) aggregated information about a significant number of customers:
(ii) aggregated authentication credentials of a significant number of customers:
Contact the TICSA team at ticsa@ncsc.govt.nz
Page 7