Australia · AEMO (in partnership with CISC and industry) · AESCSF

Australian Energy Sector Cyber Security Framework

A tailored assessment framework used across the Australian electricity, gas and liquid-fuels sectors to measure cyber-security maturity.

What it is

The AESCSF is a lightweight, criticality-tiered assessment framework developed by AEMO, the AEMC and CISC. It draws on NIST CSF, ES-C2M2 (US Department of Energy) and the Essential Eight, and sits on top of a "Criticality Assessment Tool" that determines the level of rigour expected. Participants self-assess each year, with results reported to regulators and used to satisfy the CIRMP attestation pathway for energy-sector critical-infrastructure assets.

Who it applies to

Electricity, gas and liquid-fuels sector participants - primarily those registered with AEMO, plus major retailers and network operators. Adopted by water-sector operators voluntarily.

Requirements

Criticality assessment

Establish the target Security Profile (SP) level against which the organisation will be assessed.

Domain-level self-assessment

Score maturity across 11 domains including Risk Management, Asset Change, Identity & Access, Situational Awareness and Cyber Incident Management.

Uplift planning

Identify gaps to the target SP level and plan uplift activity, typically within the annual cycle.

Reporting

Submit results to AEMO; use the output to satisfy related CIRMP cyber-hazard obligations.

Read next

Other places this turns up on the site.

Security, engineered around you.

Talk to an engineer - not a call centre. Most Vectra conversations start with a 30-minute technical briefing and end with a written plan.