UNCLASSIFIED (a) comply with subsection (1)(a) before any steps are taken, as part of the procurement or acquisition decision-making process, to approach the market (whether by request for quote, tender , or otherwise) or comply with subsection (1)(b) during the development of a business or change proposal; and (b) ensure any notice given to the Director-General in compliance with subsection (1) is given within sufficient time for the Director-General to consider whether to take action under section 51. “Proposed decision, course of action, or change…” The timing of notification is important. Network Operators are required to notify the GCSB at the stage when the decisions, courses of action or changes described are still proposals, yet to be implemented. If a network operator is looking at procurement or acquisitions of any equipment, system, or service that falls within an area of specified security interest, TICSA requires they must notify the GCSB before taking any steps, as part of the procurement or acquisition decision-making process, to approach the market (whether by request for quote, tender, or otherwise). This means, for example, that notification is required either prior to (or at the time) a Request for Proposals (RFP) is issued. If a network operator does not use a RFP process or similar, notification is required before making the decision about procurement. Providing notification before issuing a Request for Information (RFI) from vendors may in many cases be too early, however some network operators may choose to provide notification at this point if the scope of the proposal is narrowed so it can be practically assessed. With any other change to the network in an area of specified security interest, network operators are required to notify the GCSB during the development of a business or change proposal. This would include for example notifying of purchasing of or sale to, another organisation, changing a contracted third party provider, and changing remote access methods and/or authentication. These requirements are to ensure the GCSB has sufficient time to consider proposals and fulfil its regulatory function under TICSA. They also enable any network security risks to be identified and addressed as early as possible in the network operator’s decision, course of action, or change process. Allowing sufficient time for the GCSB to consider proposals will also help ensure minimal disruption to network operators’ plans. “… decision, course of action or change” A proposed decision, course of action or change includes standard builds which might cover a particular change replicated at many points of a network, and also ‘bulk changes’ - a series of changes that can be treated as one overarching ‘bulk change’. Network operators can submit a single (rather than repeated) notification for a standard build or a bulk change. Only proposed decisions, courses of action or changes that affect an “area of specified security interest” need to be notified under section 48. Section 47 of the TICSA defines area of specified security interest: (1) In this section and section 48, an area of specified security interest, in relation to a network operator, means— (a) network operations centres: (b) lawful interception equipment or operations: (c) any part of a public telecommunications network that manages or stores— (i) aggregated information about a significant number of customers: (ii) aggregated authentication credentials of a significant number of customers: Contact the TICSA team at ticsa@ncsc.govt.nz Page 7

Select target paragraph3