Criticality assessment
Establish the target Security Profile (SP) level against which the organisation will be assessed.
A tailored assessment framework used across the Australian electricity, gas and liquid-fuels sectors to measure cyber-security maturity.
The AESCSF is a lightweight, criticality-tiered assessment framework developed by AEMO, the AEMC and CISC. It draws on NIST CSF, ES-C2M2 (US Department of Energy) and the Essential Eight, and sits on top of a "Criticality Assessment Tool" that determines the level of rigour expected. Participants self-assess each year, with results reported to regulators and used to satisfy the CIRMP attestation pathway for energy-sector critical-infrastructure assets.
Electricity, gas and liquid-fuels sector participants - primarily those registered with AEMO, plus major retailers and network operators. Adopted by water-sector operators voluntarily.
Establish the target Security Profile (SP) level against which the organisation will be assessed.
Score maturity across 11 domains including Risk Management, Asset Change, Identity & Access, Situational Awareness and Cyber Incident Management.
Identify gaps to the target SP level and plan uplift activity, typically within the annual cycle.
Submit results to AEMO; use the output to satisfy related CIRMP cyber-hazard obligations.
Talk to an engineer - not a call centre. Most Vectra conversations start with a 30-minute technical briefing and end with a written plan.