Comply with SOCI Positive Security Obligation (PSO) per sector
Sector-specific cyber + risk obligations under SOCI Part 2.
Who must comply
The responsible entity for a critical infrastructure asset to which Part 2A applies (assets specified in the rules or covered by a ministerial declaration). Exemptions apply where the entity holds strategic-level hosting certification for the relevant services, or where a Commonwealth, State or Territory law specified in the rules already covers the entity or asset.
What triggers it
Becoming the responsible entity for an asset covered by Part 2A, after any grace period the rules allow for a newly captured asset.
When due
Continuous: adopt and maintain the program, comply with it, review it regularly and keep it up to date. Annual report due within 90 days after the end of each financial year, to the relevant Commonwealth regulator or, if none, to the Secretary of Home Affairs.
Evidence required
The written risk management program and its adoption record; hazard and material-risk assessment covering each asset; evidence of compliance with the program; review schedule and update log; the annual report in the approved form stating whether the program was up to date, evaluating any hazard with a significant relevant impact, and showing board, council or governing-body approval.
Max penalty
Failing to adopt and maintain, comply with, review or update the program: 200 penalty units ($72,800) each (ss 30AC-30AF). Failing to give an annual report that meets s 30AG: 150 penalty units ($54,600) (s 30AG). A court can order a body corporate to pay up to 5 times these amounts, for example $364,000 for a 200-unit provision (Regulatory Powers (Standard Provisions) Act 2014 s 82(5))
Summary
The Security of Critical Infrastructure Act 2018 (Cth) imposes positive security obligations so that critical infrastructure assets embed risk management, preparedness and resilience as business-as-usual practice. The Cyber and Infrastructure Security Centre lists three that apply to most assets: giving operational and ownership information to the Register (Part 2), reporting cyber incidents with a relevant or significant impact (Part 2B), and adopting, maintaining and complying with a written critical infrastructure risk management program (Part 2A). The program must identify each hazard where there is a material risk of a relevant impact on the asset and, so far as reasonably practicable, minimise or eliminate that risk and mitigate its impact. Each year the responsible entity reports on the program, with board approval where it has a board. Which obligations apply depends on the asset class and the entity's role.
Enforced by
Source legislation
Topics
Related
- CWLTHReport cyber security incidents to ASD (SOCI)Critical infrastructure asset operators must report critical incidents within 12 hours and other incidents within 72 hours.
- CWLTHAdopt and maintain a Critical Infrastructure Risk Management Program (CIRMP)Covered critical infrastructure entities must adopt a CIRMP addressing cyber, physical, personnel, and supply-chain hazards.
- CWLTHGovernment cyber incident reporting via ASD ACSCFederal entities + critical infrastructure report cyber incidents to ASD ACSC.
- CWLTHAdopt Essential Eight Maturity Level 2 (federal subcontractors)Federal government contractors handling OFFICIAL: Sensitive must meet Right Fit For Risk (RFFR) including E8 ML2.
- CWLTHComply with APRA CPS 234 (Information Security)APRA-regulated entities must maintain information security capability commensurate with the size and extent of threats.
- CWLTHISO/IEC 27001 ISMS certification — increasingly customer-mandatedInformation Security Management System per ISO 27001 increasingly required by customers + government.
Reading
Frequently asked questions
- Who must comply with SOCI Positive Security Obligation (PSO) per sector?
- The responsible entity for a critical infrastructure asset to which Part 2A applies (assets specified in the rules or covered by a ministerial declaration). Exemptions apply where the entity holds strategic-level hosting certification for the relevant services, or where a Commonwealth, State or Territory law specified in the rules already covers the entity or asset.
- What triggers SOCI Positive Security Obligation (PSO) per sector?
- Becoming the responsible entity for an asset covered by Part 2A, after any grace period the rules allow for a newly captured asset.
- When is SOCI Positive Security Obligation (PSO) per sector due?
- Continuous: adopt and maintain the program, comply with it, review it regularly and keep it up to date. Annual report due within 90 days after the end of each financial year, to the relevant Commonwealth regulator or, if none, to the Secretary of Home Affairs.
- What is the maximum penalty for SOCI Positive Security Obligation (PSO) per sector?
- Failing to adopt and maintain, comply with, review or update the program: 200 penalty units ($72,800) each (ss 30AC-30AF). Failing to give an annual report that meets s 30AG: 150 penalty units ($54,600) (s 30AG). A court can order a body corporate to pay up to 5 times these amounts, for example $364,000 for a 200-unit provision (Regulatory Powers (Standard Provisions) Act 2014 s 82(5))
- What evidence is required for SOCI Positive Security Obligation (PSO) per sector?
- The written risk management program and its adoption record; hazard and material-risk assessment covering each asset; evidence of compliance with the program; review schedule and update log; the annual report in the approved form stating whether the program was up to date, evaluating any hazard with a significant relevant impact, and showing board, council or governing-body approval.
Source: https://www.cisc.gov.au/how-we-support-industry/regulatory-obligations. Rules Mate is not a law firm. Always verify against the live regulator source before acting.