Australia · Cyber and Infrastructure Security Centre (CISC) · CIRMP

Critical Infrastructure Risk Management Program

The risk-management program that responsible entities must establish under the SOCI Act across cyber, personnel, physical and supply-chain hazards.

What it is

The CIRMP Rules put the SOCI Act's Risk Management Program obligation into practice. Responsible entities must establish, maintain and review a program that identifies and mitigates material risks across four hazard vectors - cyber, personnel, physical and supply chain - and align the cyber element with one of a permitted set of frameworks (AESCSF, Essential Eight ML1+, NIST CSF, ISO 27001 or an equivalent). Annual board-approved attestation is required.

Who it applies to

Responsible entities for critical-infrastructure assets captured under the CIRMP Rules - including water, energy, financial services, data storage and processing, food and grocery, healthcare and transport.

Requirements

Cyber hazards

Adopt and maintain a permitted cybersecurity framework - AESCSF, Essential Eight ML1+, NIST CSF, ISO 27001 or an equivalent.

Personnel hazards

Minimise the risk from insiders and contractors through vetting, access management and ongoing suitability checks.

Physical hazards

Identify and mitigate natural hazards and hostile physical acts that would disrupt the asset.

Supply chain hazards

Understand the supply chain dependencies of the asset and how those dependencies could be exploited or disrupted.

Annual attestation

Review the program annually and submit a board-approved attestation to the Department of Home Affairs.

Read next

Other places this turns up on the site.

Security, engineered around you.

Talk to an engineer - not a call centre. Most Vectra conversations start with a 30-minute technical briefing and end with a written plan.