Skip to main content
Rules Mate

Comply with SOCI Positive Security Obligation (PSO) per sector

Sector-specific cyber + risk obligations under SOCI Part 2.

criticalcurrentongoing

Who must comply

The responsible entity for a critical infrastructure asset to which Part 2A applies (assets specified in the rules or covered by a ministerial declaration). Exemptions apply where the entity holds strategic-level hosting certification for the relevant services, or where a Commonwealth, State or Territory law specified in the rules already covers the entity or asset.

What triggers it

Becoming the responsible entity for an asset covered by Part 2A, after any grace period the rules allow for a newly captured asset.

When due

Continuous: adopt and maintain the program, comply with it, review it regularly and keep it up to date. Annual report due within 90 days after the end of each financial year, to the relevant Commonwealth regulator or, if none, to the Secretary of Home Affairs.

Evidence required

The written risk management program and its adoption record; hazard and material-risk assessment covering each asset; evidence of compliance with the program; review schedule and update log; the annual report in the approved form stating whether the program was up to date, evaluating any hazard with a significant relevant impact, and showing board, council or governing-body approval.

Max penalty

Failing to adopt and maintain, comply with, review or update the program: 200 penalty units ($72,800) each (ss 30AC-30AF). Failing to give an annual report that meets s 30AG: 150 penalty units ($54,600) (s 30AG). A court can order a body corporate to pay up to 5 times these amounts, for example $364,000 for a 200-unit provision (Regulatory Powers (Standard Provisions) Act 2014 s 82(5))

Summary

The Security of Critical Infrastructure Act 2018 (Cth) imposes positive security obligations so that critical infrastructure assets embed risk management, preparedness and resilience as business-as-usual practice. The Cyber and Infrastructure Security Centre lists three that apply to most assets: giving operational and ownership information to the Register (Part 2), reporting cyber incidents with a relevant or significant impact (Part 2B), and adopting, maintaining and complying with a written critical infrastructure risk management program (Part 2A). The program must identify each hazard where there is a material risk of a relevant impact on the asset and, so far as reasonably practicable, minimise or eliminate that risk and mitigate its impact. Each year the responsible entity reports on the program, with board approval where it has a board. Which obligations apply depends on the asset class and the entity's role.

Enforced by

Source legislation

Topics

socicyber

Related

Frequently asked questions

Who must comply with SOCI Positive Security Obligation (PSO) per sector?
The responsible entity for a critical infrastructure asset to which Part 2A applies (assets specified in the rules or covered by a ministerial declaration). Exemptions apply where the entity holds strategic-level hosting certification for the relevant services, or where a Commonwealth, State or Territory law specified in the rules already covers the entity or asset.
What triggers SOCI Positive Security Obligation (PSO) per sector?
Becoming the responsible entity for an asset covered by Part 2A, after any grace period the rules allow for a newly captured asset.
When is SOCI Positive Security Obligation (PSO) per sector due?
Continuous: adopt and maintain the program, comply with it, review it regularly and keep it up to date. Annual report due within 90 days after the end of each financial year, to the relevant Commonwealth regulator or, if none, to the Secretary of Home Affairs.
What is the maximum penalty for SOCI Positive Security Obligation (PSO) per sector?
Failing to adopt and maintain, comply with, review or update the program: 200 penalty units ($72,800) each (ss 30AC-30AF). Failing to give an annual report that meets s 30AG: 150 penalty units ($54,600) (s 30AG). A court can order a body corporate to pay up to 5 times these amounts, for example $364,000 for a 200-unit provision (Regulatory Powers (Standard Provisions) Act 2014 s 82(5))
What evidence is required for SOCI Positive Security Obligation (PSO) per sector?
The written risk management program and its adoption record; hazard and material-risk assessment covering each asset; evidence of compliance with the program; review schedule and update log; the annual report in the approved form stating whether the program was up to date, evaluating any hazard with a significant relevant impact, and showing board, council or governing-body approval.

Source: https://www.cisc.gov.au/how-we-support-industry/regulatory-obligations. Rules Mate is not a law firm. Always verify against the live regulator source before acting.