Cyber hazards
Adopt and maintain a permitted cybersecurity framework - AESCSF, Essential Eight ML1+, NIST CSF, ISO 27001 or an equivalent.
The risk-management program that responsible entities must establish under the SOCI Act across cyber, personnel, physical and supply-chain hazards.
The CIRMP Rules put the SOCI Act's Risk Management Program obligation into practice. Responsible entities must establish, maintain and review a program that identifies and mitigates material risks across four hazard vectors - cyber, personnel, physical and supply chain - and align the cyber element with one of a permitted set of frameworks (AESCSF, Essential Eight ML1+, NIST CSF, ISO 27001 or an equivalent). Annual board-approved attestation is required.
Responsible entities for critical-infrastructure assets captured under the CIRMP Rules - including water, energy, financial services, data storage and processing, food and grocery, healthcare and transport.
Adopt and maintain a permitted cybersecurity framework - AESCSF, Essential Eight ML1+, NIST CSF, ISO 27001 or an equivalent.
Minimise the risk from insiders and contractors through vetting, access management and ongoing suitability checks.
Identify and mitigate natural hazards and hostile physical acts that would disrupt the asset.
Understand the supply chain dependencies of the asset and how those dependencies could be exploited or disrupted.
Review the program annually and submit a board-approved attestation to the Department of Home Affairs.
Talk to an engineer - not a call centre. Most Vectra conversations start with a 30-minute technical briefing and end with a written plan.