Skip to main content
Rules Mate

SoNS — Systems of National Significance (SOCI)

Declared SoNS face enhanced cyber security obligations.

criticalcurrentongoing

Who must comply

The responsible entity for an asset the Minister has declared a System of National Significance, and only for those Enhanced Cyber Security Obligations the Secretary has applied by written notice. Other critical infrastructure owners and operators are outside Part 2C.

What triggers it

A ministerial declaration under s 52B (the Minister must notify the responsible entity within 30 days), followed by a written notice or determination from the Secretary applying a specific obligation. The Secretary must consult the entity, and any relevant Commonwealth regulator, before applying the incident response planning obligation.

When due

Incident response planning applies from the time stated in the Secretary's determination, at least 30 days after notice; exercises and vulnerability assessments within the period in the notice (at least 30 days for exercises); an internal evaluation report to the Secretary within 30 days after completing an exercise; system information reports at the intervals the notice specifies.

Evidence required

Adopted and maintained written incident response plan for cyber security incidents affecting the system; cyber security exercise records and the internal (and any external) evaluation report given to the Secretary; vulnerability assessment reports; periodic system information reports; copies of the s 52B declaration and each Secretary notice, lodged through the department's secure SoNS portal.

Max penalty

Civil penalty of 200 penalty units ($72,800) for each Part 2C failure, including not adopting and maintaining an incident response plan (s 30CD), not complying with a notice to undertake a cyber security exercise (s 30CP) and not giving the Secretary the evaluation report within 30 days (s 30CQ).

Who must comply with this? The applicability test by industry, business structure and size.

Summary

Under s 52B of the Security of Critical Infrastructure Act 2018 the Minister for Home Affairs may declare a critical infrastructure asset to be a System of National Significance (SoNS), having regard to the consequences a significant hazard would have for Australia's social or economic stability, defence or national security, and to its interdependencies with other assets. SoNS are a very small subset of the 22 asset classes across 11 critical infrastructure sectors. Responsible entities for a SoNS may then be subject to four Enhanced Cyber Security Obligations in Part 2C, applied case by case by the Secretary of Home Affairs after considering cost, reasonableness and proportionality: a statutory incident response plan, cyber security exercises, vulnerability assessments, and system information reporting to the Australian Signals Directorate. These sit on top of the general SOCI obligations.

Enforced by

Source legislation

Topics

cyber-securitycritical-infrastructure

Related

Frequently asked questions

Who must comply with SoNS — Systems of National Significance (SOCI)?
The responsible entity for an asset the Minister has declared a System of National Significance, and only for those Enhanced Cyber Security Obligations the Secretary has applied by written notice. Other critical infrastructure owners and operators are outside Part 2C.
What triggers SoNS — Systems of National Significance (SOCI)?
A ministerial declaration under s 52B (the Minister must notify the responsible entity within 30 days), followed by a written notice or determination from the Secretary applying a specific obligation. The Secretary must consult the entity, and any relevant Commonwealth regulator, before applying the incident response planning obligation.
When is SoNS — Systems of National Significance (SOCI) due?
Incident response planning applies from the time stated in the Secretary's determination, at least 30 days after notice; exercises and vulnerability assessments within the period in the notice (at least 30 days for exercises); an internal evaluation report to the Secretary within 30 days after completing an exercise; system information reports at the intervals the notice specifies.
What is the maximum penalty for SoNS — Systems of National Significance (SOCI)?
Civil penalty of 200 penalty units ($72,800) for each Part 2C failure, including not adopting and maintaining an incident response plan (s 30CD), not complying with a notice to undertake a cyber security exercise (s 30CP) and not giving the Secretary the evaluation report within 30 days (s 30CQ).
What evidence is required for SoNS — Systems of National Significance (SOCI)?
Adopted and maintained written incident response plan for cyber security incidents affecting the system; cyber security exercise records and the internal (and any external) evaluation report given to the Secretary; vulnerability assessment reports; periodic system information reports; copies of the s 52B declaration and each Secretary notice, lodged through the department's secure SoNS portal.

Source: https://www.cisc.gov.au/how-we-support-industry/regulatory-obligations/enhanced-cyber-security-obligations. Rules Mate is not a law firm. Always verify against the live regulator source before acting.