Electrical substation, a physical critical component where critical infrastructure CCTV supports detection and response

CCTV guide

CCTV for critical infrastructure

Video surveillance that meets the SOCI Act risk management rules and protects physical critical components.

Critical infrastructure CCTV is the video surveillance that operators of energy, water, transport and other critical assets use to detect, verify and record unauthorised access to their physical critical components. Under the SOCI Act, responsible entities must manage physical security hazards in their critical infrastructure risk management program (CIRMP), government guidance names CCTV as an example control, and the enhanced rules expect surveillance and alarm systems that keep critical components under continuous monitoring.

  • The CIRMP Rules require a process to identify physical critical components, control access to them, respond to unauthorised access, and test that security arrangements can detect, delay, deter, respond to and recover from a breach.
  • For nine asset classes, the enhanced CIRMP Rules add a duty to maintain surveillance and security alarm systems so that critical components and critical systems are continuously monitored, which existing assets must meet by 10/06/2028.
  • For electricity networks, the Energy Networks Australia national protective security guidelines set operational requirements for video surveillance, including image quality by location and at least 31 days of storage.
  • Cameras and video management systems are themselves connected assets, so they must be secured against cyber attack.
The rules

What rules apply to CCTV at critical infrastructure sites?

  • The CIRMP baseline: section 11 of the CIRMP Rules requires a responsible entity to identify the physical critical components of its asset, minimise or eliminate material risk from physical security hazards, respond to incidents of unauthorised access, restrict access to critical workers or accompanied visitors, and test that its security arrangements are effective and appropriate to detect, delay, deter, respond to and recover from a breach.1
  • Government guidance: the Cyber and Infrastructure Security Centre (CISC) gives installing CCTV or motion detection sensors to improve the ability of security staff to detect unauthorised access as an example of managing physical hazards. The same guidance lists locking down industrial control systems, including cameras, against attack.2
  • The enhanced rules: since 10/06/2026, new section 11A applies to critical broadcasting, domain name system, electricity, energy market operator, freight infrastructure, freight services, gas, liquid fuel and water assets. It requires measures that include maintaining surveillance and security alarm systems such that critical components and critical systems are subject to continuous monitoring.3 Existing assets have until 10/06/2028 to comply.4
  • Reporting: each CIRMP annual report must be approved by the entity’s board, council or other governing body, and given to the CISC within 90 days of the end of the Australian financial year.5
  • Electricity networks: ENA DOC 015-2022, National Guidelines for the Protective Security of Electricity Networks, sets baseline operational requirements for video surveillance. These include alignment with the IEC 62676 series, target image quality by location (identification at building entries, recognition at site and substation gates, observation across perimeters and yards), recording at 12 images per second rising to 25 on alarm, and at least 31 days of storage.6
Good practice

What does good critical infrastructure CCTV look like?

The CISC’s 2025 annual risk review highlights copper theft causing power outages and sabotage as a growing tool of geopolitical disruption.7 CCTV only helps against these threats when it is designed around the risk and connected to a response. A well designed system has:

  • a threat and risk assessment linked to the CIRMP, with an operational requirement for each camera (observe, detect, recognise or identify);
  • integration with perimeter intrusion detection, access control and a security management system, so that alarms are verified by video;
  • continuous monitoring by an operator or monitoring centre, with a documented response;
  • thermal cameras and analytics on long perimeters, tested on site before they are relied on;
  • lighting designed to support camera performance;
  • cameras and video management systems on segregated networks, patched and supplied by vetted vendors;
  • secure retention, evidential export and signage; and
  • regular testing, so the CIRMP can show the arrangements work.
How we help

How Agilient supports critical infrastructure CCTV

Agilient provides independent CCTV consulting and critical infrastructure risk management for operators: CIRMP physical hazard reviews, operational requirements, electronic security design and specifications, and testing of security arrangements. Agilient does not sell or install equipment. The SOCI Act guide, CIRMP physical security playbook and enhanced CIRMP Rules guide give more detail.

Other CCTV sector guides: councils, stadiums and venues, racing, hospitals, aged care, universities, schools and childcare centres.

Testing CCTV against your CIRMP?

A short briefing will help you test your surveillance and monitoring against the CIRMP Rules and the enhanced requirements.

FAQs

Critical infrastructure CCTV FAQs

Does the SOCI Act require CCTV?
The CIRMP Rules do not name CCTV for every asset, but they require arrangements that detect, delay, deter, respond to and recover from breaches, and government guidance gives CCTV as an example. For nine asset classes, the enhanced rules require surveillance and security alarm systems that keep critical components under continuous monitoring, which existing assets must meet by 10/06/2028.
Which assets do the enhanced physical security rules cover?
Critical broadcasting, domain name system, electricity, energy market operator, freight infrastructure, freight services, gas, liquid fuel and water assets.
What is ENA DOC 015?
ENA DOC 015-2022 is the National Guidelines for the Protective Security of Electricity Networks, published by Energy Networks Australia in 2022. It sets protective security guidance for network service providers, including operational requirements for video surveillance.
How long should critical infrastructure CCTV footage be kept?
For electricity networks, ENA DOC 015 recommends at least 31 days of storage for all cameras at full frame rate and target resolution. Other operators should set retention from their risk assessment and evidence needs.
References

  1. Federal Register of Legislation, Security of Critical Infrastructure (Critical infrastructure risk management program) Rules (LIN 23/006), legislation.gov.au
  2. Cyber and Infrastructure Security Centre, Guidance for the Critical Infrastructure Risk Management Program, March 2025, cisc.gov.au
  3. Federal Register of Legislation, Enhanced Critical Infrastructure Risk Management Program Rules 2026 (LIN 26/075), legislation.gov.au
  4. Cyber and Infrastructure Security Centre, Enhanced CIRMP implementation factsheet, cisc.gov.au
  5. Cyber and Infrastructure Security Centre, Risk management program annual report, cisc.gov.au
  6. Energy Networks Australia, ENA DOC 015-2022, National Guidelines for the Protective Security of Electricity Networks, energynetworks.com.au
  7. Cyber and Infrastructure Security Centre, Critical Infrastructure Annual Risk Review 2025, cisc.gov.au