What Australia Security of Critical Infrastructure Act 2018 - 11-Sector CIRMP, Cyber Incident Reporting, and Government Assistance Powers requires
The Australian Security of Critical Infrastructure Act 2018 (Cth) (SOCI Act), significantly expanded by the Security Legislation Amendment (Critical Infrastructure) Act 2021 (SLACI) and the Security Legislation Amendment (Critical Infrastructure Protection) Act 2022 (SLACIP), establishes Australia's primary regulatory framework for the protection of critical infrastructure across 11 sectors. Part 1 of the Act defines critical infrastructure asset and identifies the 11 covered sectors: communications, financial services and markets, data storage and processing, water and sewerage, energy (electricity, gas, liquid fuels), healthcare and medical, higher education and research, food and grocery, transport (ports, airports, freight, rail, road), space technology, and defence industry. A responsible entity is the entity that holds the critical infrastructure asset and bears compliance obligations. Part 2 establishes the Register of Critical Infrastructure Assets maintained by the Department of Home Affairs Cyber and Infrastructure Security Centre (CISC) - confidential under section 22. Part 2A requires every responsible entity to establish and maintain a Critical Infrastructure Risk Management Program (CIRMP) addressing cyber, supply chain, personnel, physical, and natural hazard risks; the CIRMP Rules under section 30AH specify mandatory risk management standards aligned to standards such as ISO 27001 and AESCSF. Part 2B requires mandatory cyber incident reporting to the Australian Cyber Security Centre (ASD ACSC) within 12 hours for a critical cyber security incident having a significant impact on the availability of the asset, and within 72 hours for any other cyber security incident having a relevant impact. Part 2C applies Enhanced Cyber Security Obligations to Systems of National Significance designated by the Minister - including statutory incident response plans, cyber security exercises, vulnerability assessments, and system information reporting. Part 3 grants ministerial Government Assistance powers - the Minister may issue an Authorisation to permit the Australian Signals Directorate to step in, install software, or take other action to respond to a serious cyber security incident. Maximum civil penalty 1,000 penalty units (approximately AUD 330,000 indexed) per contravention; criminal offences carry imprisonment penalties.
Pillar: Industrial IoT & Energy · Authority: Australian Parliament - Security of Critical Infrastructure Act 2018 (Cth); Department of Home Affairs Cyber and Infrastructure Security Centre (CISC); Australian Signals Directorate (ASD) Australian Cyber Security Centre (ACSC); Minister for Home Affairs · Version: 1.0.0 · Last updated:
Primary source: https://www.legislation.gov.au/C2018A00029/latest/text
SHA-256 integrity: eb5dcce4f00d9d9faa1bb7e42fc13a77da77918239e75e02e54ae06e2feae25e
Primary Citations — 8 traced to source
- Security of Critical Infrastructure Act 2018 (Cth) https://www.legislation.gov.au/C2018A00029/latest/text
- SOCI Act Part 2A Critical Infrastructure Risk Management Program https://www.legislation.gov.au/C2018A00029/latest/text
+ 6 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
- Discovery (free): /api/v1/nodes/au-soci-act-2018-security-of-critical-infrastructure.json — 6-field metadata
- Vault (full node): /api/v1/vault/nodes/au-soci-act-2018-security-of-critical-infrastructure.json — full 13-key payload, $0.01 USDC (L402/Skyfire/Direct Base)
- Canonical URL: https://bidda.com/intelligence/au-soci-act-2018-security-of-critical-infrastructure
- Back to registry: Browse all 10,085 compliance nodes