Australia · Cyber and Infrastructure Security Centre (CISC), Department of Home Affairs · SOCI Act

Security of Critical Infrastructure Act

The legislative framework that imposes cyber-security and risk-management obligations on responsible entities across 11 critical-infrastructure sectors.

What it is

The SOCI Act sets the baseline obligations for Australia's 11 critical-infrastructure sectors including communications, data storage and processing, financial services, water, healthcare, higher education, food and grocery, transport, space, defence industry, and energy. Key obligations include a register of critical-infrastructure assets, mandatory cyber-incident reporting, a Risk Management Program (CIRMP) and, for Systems of National Significance, enhanced cyber-security obligations agreed directly with the Minister.

Who it applies to

"Responsible entities" for assets across 11 critical-infrastructure sectors. A separate class of "Systems of National Significance" carries additional obligations.

Requirements

Register of critical-infrastructure assets

Provide operational and ownership information to the Register maintained by the CISC.

Cyber-incident reporting

Notify the ACSC within 12 hours of a critical incident and 72 hours of any other reportable incident.

Risk Management Program (CIRMP)

Identify and mitigate hazards across cyber, personnel, physical and supply-chain domains.

Enhanced cyber-security obligations

For Systems of National Significance only - vulnerability assessments, system-information periodic reporting, and cyber-security exercises.

Read next

Other places this turns up on the site.

Security, engineered around you.

Talk to an engineer - not a call centre. Most Vectra conversations start with a 30-minute technical briefing and end with a written plan.