0% found this document useful (0 votes)
18 views3 pages

Understanding the CIRMP Obligations

Uploaded by

cybertino1919
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
18 views3 pages

Understanding the CIRMP Obligations

Uploaded by

cybertino1919
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Critical Infrastructure Risk Management Program

Part 2A Security of Critical Infrastructure (SOCI) Act 2018


Factsheet

This guidance material has been prepared to assist in the understanding of the Security of Critical Infrastructure
(Critical infrastructure risk management program) Rules (LIN 23/006), subordinate legislation to the Security of
Critical Infrastructure Act 2018 (SOCI Act)

What is the CIRMP obligation? • Identify material risks – Entities have a responsibility to take an
The Critical Infrastructure Risk Management Program (CIRMP) is all-hazards approach when identifying hazards that may affect
intended to uplift core security practices that relate to the the availability, integrity, reliability and confidentiality of their
management of certain critical infrastructure assets. It aims to critical infrastructure asset.
ensure responsible entities take a holistic and proactive approach • Minimise risks to prevent incidents – Entities are required to
toward identifying, preventing and mitigating risks. consider risks to their critical infrastructure asset (cyber and
information security hazards, personnel hazards, supply chain
Responsible entities of the asset classes listed in the SOCI Act
hazards and physical security and natural hazards) and
Application Rules are required to establish, maintain, and comply
establish appropriate strategies to minimise or eliminate the
with a written risk management program that manages the
risk of hazards occurring, so far as is reasonably practicable.
‘material risk’ of a ‘hazard’ occurring, which could have a relevant
Entities should consider both proactive risk management as
impact on their critical infrastructure asset.
well as establishing and managing processes to detect and
respond to threats as they are being realised to prevent the
Responsible entities must identify, and as far as is reasonably
risk from eventuating.
practicable, take steps to minimise or eliminate these ‘material
risks’ that could have a ‘relevant impact’ on their asset. • Mitigate the impact of realised incidents – Entities are required
to have robust procedures in place to mitigate, so far as is
The Security of Critical Infrastructure and Other Legislation reasonably practicable, the impacts of a hazard, and recover
Amendment (Enhanced Response and Prevention) Act 2024 from that impact as quickly as possible.
(ERP Act) clarifies that the protection of certain business critical
• Effective governance - Entities are required to provide an
data and the secondary systems that store it should be
annual report that has been signed by their board, council or
considered under the CIRMP obligations. To enact obligations
other governing body, to the relevant regulator and in some
relating to risks to data storage systems holding ‘business critical
instances the Secretary of the Department of Home Affairs.
data’ as ‘material risks’, the Security of Critical Infrastructure
The approved form that has been signed by a board, council
Amendment (2025 Measures No. 1) Rules 2025.
or other governing body must be submitted along with the
Additionally, Schedule 5 of the ERP Act uplifts, enhances and annual report. The annual report does not need to contain the
clarifies current security and related obligations under the CIRMP but must be sufficient to assure the relevant regulator
Telecommunications Sector Security Reforms (TSSR) into the that the program is up-to-date and appropriate.
SOCI Act. The ERP Act is supported by the Security of Critical
Infrastructure (Telecommunications Security and Risk
What assets are affected by the obligations?
Management Program) Rules 2025 (TSRMP Rules). The TSRMP
Rules commenced on 4 April 2025, and apply to those The Rules apply to the following critical infrastructure assets:
responsible entities that own and/or operate a carrier asset or
relevant carriage service provider asset. Further guidance on the • critical electricity assets
TSRMP Rules can be found on the CISC website. • critical energy market operator assets
• critical gas assets
Principles-based outcomes • critical liquid fuels assets
• critical water assets
The SOCI Act and Security of Critical Infrastructure (Critical • critical financial market infrastructure assets used in
infrastructure risk management program) Rules (LIN 23/006) 2023 connection with the operation of payment systems
(the Rules) specify requirements to be contained in a CIRMP. • critical data storage or processing assets, including secondary
These requirements are based on the following principles-based systems
outcomes:
• designated hospitals (listed in the Rules)
• critical domain name systems
• critical food and grocery assets
• critical telecommunications assets (via separate rules,
Telecommunications guidance)

The information contained in this document is general in nature and does not constitute legal advice. Readers are encouraged to obtain
legal advice that applies to their particular circumstances. The Commonwealth of Australia does not guarantee the accuracy, currency
or completeness of any information in this document.

Contact Us | 1300 27 25 24 | enquiries@[Link] | [Link] |


CISC on Twitter and LinkedIn
April 2025
• critical freight infrastructure assets (Rule 8 of the Security of Critical
Infrastructure (Definitions) Rules (LIN 21/039) 2021 specifies that What are the annual reporting
intermodal transfer facilities mentioned in schedule one of the requirements?
instrument will be critical to the transportation of goods between states
Entities are required to provide an
or territories. At this stage, only these facilities are subject to positive
annual report to the relevant
security obligations).
Commonwealth regulator or the
• critical freight services assets
Secretary of the Department of Home
• critical broadcasting assets Affairs, regarding the entities’ CIRMP.
Entities must submit this report within
What is a material risk? 90 days after the end of the financial
year and the report must be approved
A risk is a material risk to a critical infrastructure asset when the risk has a relevant by the entity’s board, council, or other
impact on the asset. Rule 5 (a-g) of the Rules provides the parameters of material governing body.
risk. These include the risk of impairment, stoppage, loss of access to or
interference with the asset. The report must be in the approved
form and state whether the risk
management program was up to date,
What is a relevant impact? any variations to the program, and
details of how the program was
A ‘relevant impact’ is an impact on the availability, integrity, and reliability of the effective in mitigating any relevant
asset, and the impact on the confidentiality of information about the asset, impacts that hazards may have had on
information stored in the asset if any, and, if the asset is computer data, the that asset during that year.
computer data.
The report does not need to contain
The relevant impact may be direct or indirect. It must be more serious than a the full risk management program, but
reduction in the quality of service being provided. must be sufficient to assure the
relevant Commonwealth regulator or
CIRMP Hazard Rules the Secretary that the program
remains up to date and appropriate.
The Rules contain obligations relating to protections within four key hazard vectors: The online annual reporting form can
• Cyber and information security – ‘cyber’ risks to digital systems, computers, datasets, be found here: Responsible Entity Risk
and networks that underpin critical infrastructure systems. Management Program - Annual Report
• Personnel – the ‘trusted insider’ risk posed by critical workers who have the access and
ability to disrupt the functioning of the asset.
• Supply chain – risk of disruption to critical supply chains leading to a relevant impact on
the critical infrastructure asset. The threat could be naturally occurring, malicious or
purposefully intended to compromise the critical infrastructure asset.
• Physical and natural – physical risks to parts of the asset critical to the functioning of
the asset, including physical access to sensitive facilities (e.g., control rooms) or natural
disasters.

What does ‘so far as it is reasonably practicable’ mean? The 2023-24 trial audits indicated that
common deficiencies in critical
The requirement to minimise or eliminate material risks ‘so far as it is reasonably infrastructure risk management programs
practicable’ advises the responsible entities to act at a particular time that is reasonably related to:
possible to address those risks.
Personnel management – lack of insider
In considering the material risks to their business, responsible entities must weigh up what threat mitigation and policies to identify
can be done to mitigate those risks - i.e., what is possible in the circumstances and critical workers
whether those actions are reasonable in the circumstance. There is no expectation that
entities pursue risk mitigation measures that are disproportionate relative to the likelihood Physical hazard – lack of formal
and consequences of a particular risk. documented processes, guidelines and
review mechanisms
The requirement provides responsible entities flexibility to determine how they address
material risk and relevant impact in relation to their business size, maturity, income and
overall asset criticality. The intent is for responsible entities to seek to minimise or
eliminate material risk where it is reasonably possible, in order to secure their critical
infrastructure asset.

In the annual attestation the Board, Council or other governing body (if the entity has one)
are required to approve the risk management plan and in doing so, appropriately balance
the costs of risk mitigation measures with the impact of those measures in reducing
material risk within their own operational context.

The information contained in this document is general in nature and does not constitute legal advice. Readers are encouraged to obtain
legal advice that applies to their particular circumstances. The Commonwealth of Australia does not guarantee the accuracy, currency
or completeness of any information in this document.

Contact Us | 1300 27 25 24 | enquiries@[Link] | [Link] |


CISC on Twitter and LinkedIn
April 2025
Review and Remedy power
Reforms to the SOCI Act under section 2A allow the regulator last resort powers to direct
an entity to remedy their risk management program, should it be found to be seriously
deficient and not meeting the minimum protective standards. ‘Serious deficiency’ is
defined as one that poses a material risk to the national security, defence, or social or
economic stability of Australia or its people.

The power is managed with appropriate oversight mechanisms, with guidance and good-
faith consultation remaining the first course of action to correct an identified deficiency in a
risk management program. The regulator must first engage with the entity, alerting them
to their intention to issue a direction and present them with an opportunity to respond
before a direction can be issued.

The Department’s intention is that where deficiencies are identified, these directions
would be issued in accordance with the Cyber and Infrastructure Security Centre’s (CISC)
Compliance and Enforcement Strategy. The CISC seeks to work in partnership with
industry to ensure regulated entities understand and effectively manage their risks,
reserving compliance levers as last resort measures.

While risk management programs will not be required to be submitted to the CISC as a
matter of course; entities will continue to be required to submit an annual attestation
within 90 days of the end of the financial year – for further information refer to Guidance
for the Critical Infrastructure Risk Management Program.

The information contained in this document is general in nature and does not constitute legal advice. Readers are encouraged to obtain
legal advice that applies to their particular circumstances. The Commonwealth of Australia does not guarantee the accuracy, currency
or completeness of any information in this document.

Contact Us | 1300 27 25 24 | enquiries@[Link] | [Link] |


CISC on Twitter and LinkedIn
April 2025

You might also like