UNCLASSIFIED (iii) administrative (privileged user) authentication credentials: (d) any place in a public telecommunications network where data belonging to a customer or end user aggregates in large volumes, being either data in transit or stored data: (e) any area prescribed under subsection (2). Although many of these terms are common to network operators, some further guidance on what they mean is provided below. a) Network Operations Centres (NOC) – The NOC is the function or functions through which network operations are controlled, either as a function distributed among business units, or as a discrete business unit in itself. This includes Security Operations Centres (SOCs) if distinct from the NOC (since they also perform key functions of network governance and oversight). Proposals that affect the operation of the NOC or SOC, their oversight, control, and effective supervision, as well as core equipment used must be notified. b) Lawful interception equipment or operations – Are any equipment used to provide Lawful Intercept solutions as part of Section 2 of TICSA c) Parts of networks that manage or store aggregates of information – These are the places where sensitive information is likely to be stored, making the systems hardware and its support/operation of specific security interest. i. Aggregated information about a significant number of customers. This refers to:    ii. Aggregated authentication credentials of a significant number of customers. This refers to:   iii. Databases which store data in bulk, such as call records or network traffic data. Operations Support Systems (OSS), or Business Support Systems (BSS) and other forms of business customer databases. Proposals affecting the equipment or systems which interact directly and modify the network core require notification. Areas of the network which store authentication credentials and encryption keys. The Evolved Packet Core (EPC) and the Home Location Register (HLR/HSS) in mobile networks. Administrative (privileged user) authentication credentials. This refers to:  Places where privileged user credentials are stored and audit and oversight controls are retained. Contact the TICSA team at ticsa@ncsc.govt.nz Page 8

Select target paragraph3