• Skip to primary navigation
  • Skip to main content
  • Skip to footer
Logo of Agilient Security Consultants, Australia

Agilient Security Consultants Australia

Cybersecurity & Risk Management Specialists

Menu
  • Home
  • Industries
      • Aviation
      • Defence & Defence Industry
      • Government
      • Health & Hospitals
      • Corrections and Detention
      • Maritime
      • Aged Care Facilities
      • Mining, Oil & Gas
      • Public Venues & Events
      • Rail
      • Research and Education Industry
      • Telecommunications
      • Utilities
    • advice-colleagues-communication-newIndustries
  • Services
      • Cybersecurity
      • Protective Security
      • Business Resilience
      • Building Security Consultants
      • Security Audits
      • Pandemic Planning
      • Electronic Security
      • IT Disaster Recovery Plan
      • Security Consultants
      • CCTV and Security Cameras
      • Duress Alarms
      • Security Risk Assessment Consultants
      • Managed Security Service Provider
      • Protection against Vehicles as a Weapon
    • training-1Services
  • Solutions
    • banner-menuUnisys Solutions
    • CTO-Blog-110619-Header-GraphicLookingGlass Solutions
    • menu-bg-2Dell Technologies (RSA) Solutions
    • Sightline-Visualization-menuSightline Solutions
  • Resources
    • menumanagers-dealing-customer-agreTraining
    • working-together-newJoin The Tribe
    • Webinars_3-1.jpgUpcoming and Past Events
    • hacking-detected-shutterstock_newResources
  • Articles
  • About
    • About Us
      We are an Australian owned and operated security company specialising in risk, cybersecurity, protective security, crisis and business continuity management services.
    • frequently-asked-questions-smallFAQ’s
    • bg-menu-government-institutionsConsultant Registration
  • Contact Us
Contact Us

Risk Management and Cybersecurity Obligations for Critical Infrastructure

You are here: Home / Security News / Risk Management and Cybersecurity Obligations for Critical Infrastructure

The Security Legislation Amendment (Critical Infrastructure) Act 2021 was submitted and enacted on 2 December 2021, and a new set of amendments will be submitted in early 2022, to form a second Bill. A draft version of the Bill discusses three main requirements:

  1. Risk Management Programs
  2. Enhanced Cybersecurity Obligations
  3. Declarations of Systems of National Significance

Risk Management Programs

This section states that any entity responsible for one or more critical infrastructures must have, and comply with, a Risk Management Program. The purpose of this program focuses on:

  1. Identifying each hazard where there is a material risk that the occurrence of the hazard could have a relevant impact on the asset;
  2. Minimizing or eliminating any material risk of such hazard occurring; and
  3. Mitigating the relevant impact of such a hazard on the asset.

The responsible entity must submit a report each year related to this program for the critical infrastructure, which should be approved by the board or council of this entity.

A more in-depth discussion of the rules, penalties and annual reporting requirements can be discussed with our team.

Enhanced Cybersecurity Obligations

This section sets out enhanced cybersecurity obligations that relate to systems of national significance. The entity responsible for a system of national significance may be subject to statutory incident response planning obligations, and may even be required to undertake a cybersecurity exercise, or a vulnerability assessment.

If a computer is a system of national significance, or is needed to operate a system of national significance, the responsible entity of the system may be required to:

  1. Give the Australian Signals Directorate (ASD) periodic reports of system information; or
  2. Give ASD event-based reports of system information; or
  3. Install software that transmits system information to ASD.

For more information about the statutory incident response planning obligations, cybersecurity exercises, the vulnerability assessment requirements, or any of the reports for the system information and the special software for transmitting system information, our professional team can offer you expert advice.

Declarations of Systems of National Significance

The draft of the Bill states that the Minister may privately declare a critical infrastructure asset to be a “system of national significance”. This can only be done by notifying each reporting entity for an asset that is a declared system of national significance.

If a reporting entity for an asset that is a declared system of national significance ceases to exist, or becomes aware of another reporting entity for the asset, the entity must notify the Secretary of the ASD.

If your critical infrastructure asset is declared to be a system of national significance, be aware that new measures and procedures are required in order to comply with the new obligations, and this is where our team can step in to ensure all of your organisation’s reporting and compliance requirements are met.

Author: Mahdi Kobeissi, Cybersecurity Consultant

Tweet
Share

Security News ASD,  Australian government,  Bill 2,  critical infrastructure,  cybersecurity,  risk management,  Security Legislation Amendment (Critical Infrastructure) Act 2021,  systems of national significance

Looking for a security partner? Get in touch with Agilient.

Looking for practical and cost-effective security and risk solutions for your government department, agency or company? Speak with Australia’s leading senior security, risk and resilience experts.


Looking for a pandemic planning partner? Get in touch with Agilient.

Looking for practical and cost-effective risk management solutions for your government department, agency or company? Speak with Australia’s leading senior risk and emergency management experts.



Footer

Agilient is a proud member of

Ai Group Defence Council
Australian Industry & Defence Network
Australian Security Industry Association
Sydney Aerospace & Defence Interest Group

Company and Licensing Details:

ABN: 37 157 911 441
NSW Security Master Licence # 410783087
ACT Security Master Licence # 17502184
Vic Security Registration # 878-460-40S
Qld Security Firm Licence # 3834422

Join The Tribe

Sign up to receive our regular Agilient newsletter including the latest security, risk and resilience updates

Sign up now

Copyright © 2022 Agilient – Level 14, 275 Alfred St, North Sydney NSW 2060 Australia – 1300 341 692