Security of Critical Infrastructure (Australian National University) Rules (LIN 22/041) 2022

Administered by Department of Home Affairs

Legislation au F2022L00315 Rules In force Legislative Instrument

Legislation content

EXPLANATORY STATEMENT

Issued by authority of the Minister for Home Affairs

Security of Critical Infrastructure Act 2018

Security of Critical Infrastructure (Australian National University) Rules (LIN 22/041) 2022

1                The instrument, Departmental reference LIN 22/041, is made under section 61 of the Security of Critical Infrastructure Act 2018 (the Act). 

2                The instrument commences on the day after registration on the Federal Register of Legislation and is a legislative instrument for the Legislation Act 2003 (the Legislation Act). 

Purpose

3                Subsection 9(1) of the Act defines a ‘critical infrastructure asset’ to be a ‘critical education asset’ and ‘an asset prescribed by the rules for the purposes of this paragraph’ (see paragraphs (dk) and (f) respectively). Section 5 of the Act defines a ‘critical education asset’ to be a university owned or operated by an entity registered in the Australian university category of the National Register of Higher Education Providers.  As at the time the instrument is made, this includes the Australian National University (ANU). 

4                However, subsection 9(2A) of the Act provides that if an asset is owned by a body corporate established by a law of the Commonwealth, the asset is not a ‘critical infrastructure asset’ unless the asset is prescribed by the rules for the purpose of paragraph 9(1)(f) of the Act. As ANU is a body corporate established by a law of the Commonwealth, it is captured by this exception (see section 4 of the Australian National University Act 1991).

5                The purpose of the rules is to prescribe certain assets owned or operated by ANU as a critical infrastructure asset for paragraph 9(1)(f) of the Act so as to override the exception in subsection 9(2A).

6                Subsection 9(3) of the Act provides that the Minister must not prescribe an asset for the purposes of paragraph 9(1)(f) unless the Minister is satisfied that:

  • the asset is critical to the social or economic stability of Australia or its people, the defence of Australia or national security (paragraph (a)); and
  • the asset relates to a critical infrastructure sector (paragraph (b)).

7                In relation to paragraph 9(3)(a) of the Act, the Minister is satisfied that the assets owned or operated by ANU are critical to the social and economic stability of Australia or its people. The Minister is satisfied that the ANU, like other Australian universities, contributes significantly to the Australian economy, competitiveness, skilled workforce and Australia’s global standing, both as quality providers of education and as cutting-edge research institutions. Equally, Australian universities such as the ANU make a notable contribution to Australia’s security and prosperity by promoting research and innovation.

8                In relation to paragraph 9(3)(b) of the Act, the assets owned or operated by ANU relate to the ‘higher education and research sector’ because they are a critical education asset (see also subsection 8E(8) and section 8F). Paragraph 8D(g) of the Act provides that the higher education and research sector is a kind of critical infrastructure sector. Assets owned or operated by the ANU therefore relate to a critical infrastructure sector for paragraph 9(3)(b) of the Act.

9                The Act also provides that certain Parts of the Act apply to (amongst other things) a critical infrastructure asset prescribed in rules under the Act. As noted above, the assets owned or operated by ANU that are mentioned in the instrument are a critical education asset under the Act. Therefore, if rules are made to apply any Part of the Act to a critical education asset, that Part of the Act will apply to the ANU according to those rules.

Details of the instrument

10            Paragraph (a) of the instrument provides that, for paragraph 9(1)(f) of the Act, an asset is a critical infrastructure asset if:

  • the asset is owned or operated by ANU (ABN: 52 234 063 906); and
  • the asset is used in connection with a program of research that is critical to a critical infrastructure sector (other than the higher education and research sector), the defence of Australia or national security (subparagraphs (i), (ii) and (iii) respectively). 

11            By operation of section 13 of the Legislation Act, the terms ‘critical infrastructure sector’, ‘higher education and research sector’, ‘defence of Australia’ and ‘national security’ used in subparagraphs (a)(i)-(iii) of the instrument have the same meaning as given by the Act. 

12            The limitations on the types of assets that are a critical infrastructure asset outlined in subparagraphs (i)-(iii) are included to align with the updated definition of ‘critical education asset’ that will apply if the Security Legislation Amendment (Critical Infrastructure Protection) Bill 2022, currently before the Parliament, passes and commences.  The intention on limiting types of assets as described in paragraph (a) of the instrument is to only capture those assets that are of security concern, and not capture unrelated assets such as cafeterias and gymnasiums. 

13            Paragraph (b) of the instrument provides that, for subsection 12L(23) of the Act, the responsible entity for the assets mentioned in paragraph (a) is the ANU.

14            The instrument provides that it commences on the day after registration on the Federal Register of Legislation.

Parliamentary scrutiny etc. 

15            The instrument is subject to disallowance under section 42 of the Legislation Act.  A Statement of Compatibility with Human Rights has been prepared in relation to the instrument, and provides that to the extent that the instrument impacts human rights, the impact is reasonable and proportional. The Statement is included at Attachment A to this explanatory statement. 

16            The instrument was made by Karen Andrews, Minister for Home Affairs, in accordance with section 61 of the Act.  

Statement of Compatibility with Human Rights

Prepared in accordance with Part 3 of the Human Rights (Parliamentary Scrutiny) Act 2011

 

Security of Critical Infrastructure (Australian National University) Rules (LIN 22/041) 2022

 

This Disallowable Legislative Instrument is compatible with the human rights and freedoms recognised or declared in the international instruments listed in section 3 of the
Human Rights (Parliamentary Scrutiny) Act 2011.

 

Overview of the Disallowable Legislative Instrument

1                Subsection 9(1) of the Security of Critical Infrastructure Act 2018 (the Act) defines a range of assets as critical infrastructure assets under the Act, including a critical education asset and ‘an asset prescribed by the rules for the purposes of this paragraph’ (see paragraphs (dk) and (f) respectively). Section 5 of the Act defines a critical education asset, which includes assets owned or operated by the Australian National University (ANU).

2                However, the assets owned or operated by ANU are excluded from the definition of critical infrastructure asset due to an exception outlined at subsection 9(2A) of the Act. The exception provides that assets owned by a body corporate established by a law of the Commonwealth are not critical infrastructure assets, unless the asset is prescribed by the rules for the purpose of paragraph 9(1)(f) of the Act. The ANU is owned by a body corporate established under the Australian National University Act 1991.

3                The purpose of the Security of Critical Infrastructure (Australian National University) Rules (LIN 22/041) 2022 (ANU Rules) is to prescribe the ANU as a critical infrastructure asset for paragraph 9(1)(f) of the Act to override the exception in subsection 9(2A) of the Act.

4                Prescribing the ANU as a critical infrastructure asset will enable consistency in the Government’s regulatory approach for the higher education and research sector, as in the absence of a rule the ANU would be excluded from the provisions applying to all other universities. Prescription as a critical infrastructure asset will mean that the ANU will be subject to Government assistance measures under Part 3A of the Act once the ANU Rules commence. In addition, once the ANU commences to be a critical infrastructure asset, if rules are made to apply any of the positive security obligations to critical education assets, these obligations will apply to the ANU.

5                In relation to paragraph 9(3)(b) of the Act, the ANU relates to the higher education and research sector, as defined in section 5 of the Act. Paragraph 8D(g) of the Act provides that the higher education and research sector is a kind of critical infrastructure sector. The ANU therefore ‘relates to a critical infrastructure sector’ for paragraph 9(3)(b) of the Act.

Human rights implications

6                This Disallowable Legislative Instrument engages the following human rights:

  • The right to privacy in Article 17 of the International Covenant on Civil and Political Rights (ICCPR).

Right to privacy

7                Article 17 of the ICCPR provides that no one shall be subjected to arbitrary or unlawful interference with their privacy. Interferences with privacy may be permissible provided that it is authorised by law and is not arbitrary. For an interference with the right to privacy not to be arbitrary, the interference must be for a reason consistent with the provisions, aims and objectives of the ICCPR and be reasonable in the particular circumstances

8                The United Nations Human Rights Committee has interpreted ‘reasonableness’ in this context to mean that ‘any interference with privacy must be proportional to the end sought and be necessary in the circumstances of any given case’. The term unlawful means that no interference can take place except as authorised under domestic law. In order for limitations not to be arbitrary, they must be aimed at a legitimate objective and be reasonable, necessary and proportionate to that objective.

9                The prescription by the ANU Rules of the circumstances in which the ANU falls within the definition of a critical infrastructure asset will allow certain powers to be used in relation to the ANU, and may engage the right to privacy of the ANU’s responsible entity, employees or customers. Such information is held securely by the Government and will not be made available on a public register.

Government assistance: Ministerial authorisation relating to cyber-security incidents

10            As a result of prescribing the ANU as a critical infrastructure asset through the ANU Rules, the ANU is subject to the Government Assistance measures (Part 3A, Division 2 of the Act).

11            To prevent or mitigate a serious cyber-security incident that has had, is having, or is likely to have a relevant impact on a critical infrastructure asset (subsection 35AB(1)), the Minister has the power to authorise the Secretary of the Department administering the Act to use:

  • Information gathering direction power (paragraphs 35AB(2)(a) or (b) and section 35AK), that is, to direct an entity to provide information that may assist with determining whether a power under the Act should be exercised in relation to an incident and the asset;
  • Action direction power (paragraphs 35AB(2)(c) or (d) and section 35AQ), that is, to direct an entity to do, or refrain from doing, a specified act or thing within the period specified in the direction;
  • Intervention direction power, that is, to request that the chief executive of Australian Signals Directorate (ASD) take direct action (paragraphs 35AB(2)(e) or (f) and section 35AX). For a request that is in force under section 35AX, an ASD staff member may require an entity to provide the staff member with access to premises or electronic networks, and provide them with specified information or assistance. This does not apply to premises that are used solely or primarily as a residence.

12            To justify a limitation on the right to privacy, a legitimate objective must address a pressing or substantial concern and not simply seek an outcome that is desirable or convenient.

13            The Government Assistance measures in the Act are intended to protect the Australian community from the risk of espionage, sabotage and coercion arising from foreign involvement in Australia’s critical infrastructure. Foreign involvement remains a significant threat to national security and public safety. Acts of foreign involvement can indiscriminately threaten the lives and physical safety of Australian citizens. Accordingly, the measures are seeking to achieve a legitimate objective.

14            The Government Assistance measures in the Act are also proportionate to the outcome. There are proportionate limitations to the use of Government Assistance measures, including requirements for the Minister, prior to their use to be satisfied that:

  • A cyber-security incident has occurred, is occurring or is imminent (paragraph 35AB(1)(a)).
  • That the incident has had, is having, or is likely to have a relevant impact on a critical infrastructure asset (paragraph 35AB(1)(b)). Subsection 8G(2) provides the definition of a relevant impact in this context, which includes an impact on the availability, integrity, reliability or confidentiality of the asset. Therefore this power can only be used to protect Australia’s critical infrastructure assets.
  • That there is material risk that the incident has seriously prejudiced, or is seriously prejudicing, or is likely to seriously prejudice the social or economic stability of Australia or its people, or the defence of Australia; or Australia’s national security (paragraph 35AB(1)(c)). This requirement ensures that the regime can only be used in the most serious of circumstances where Australia’s national interests are being seriously prejudiced. In such circumstances, the Government’s responsibility to protect Australia’s national interests are engaged. 
  • That the action would be a technically feasible, proportionate (considering the impact of compliance with the request and the consequences of compliance) and a reasonably necessary response to the incident, and that the relevant entity is unwilling or unable to take all reasonable steps to respond to the incident (subsections 35AB(7) and 35AB(10)).
  • For intervention requests, that the Minister has obtained the agreement of the Prime Minister and the Defence Minister before giving the Ministerial authorisation (section 35AB)).

15            The ANU will continue to be primarily responsible for managing cyber-security risks. In the vast majority of cyber-security incidents, the ANU should and will respond to cyber-security incidents, with the support of Government only where necessary.

16            Only in exceptional circumstances, and as a last resort, will the Government Assistances measures be utilised to enable Government to take appropriate steps to prevent and address immediate and serious cyber-security incidents that threaten serious harm to Australia’s interests, mitigate the impacts of such incidents on critical infrastructure, and restore the functioning of those assets.

Conclusion

The Disallowable Legislative Instrument is compatible with human rights because, to the extent that it may limit human rights, those limitations are reasonable, necessary and proportionate to the objective of reducing national security risks, including those presented by foreign interference and cyber threats, to critical infrastructure.

 

 

Overview

The Security of Critical Infrastructure Act 2018 was enacted to protect Australia's critical infrastructure from threats such as espionage, sabotage, and coercion. This legislation addresses the gap in protecting critical assets, particularly those owned by bodies corporate established by Commonwealth law, which might otherwise be excluded from the definition of critical infrastructure assets unless specifically prescribed by rules. The Parliament of Australia introduced this Act to safeguard critical sectors vital to the nation's security and economic stability. The Security of Critical Infrastructure (Australian National University) Rules (LIN 22/041) 2022 were subsequently made under section 61 of the Act to specifically classify the Australian National University (ANU) as a critical infrastructure asset, ensuring it receives the necessary regulatory protections aligned with other universities. This measure ensures the ANU, recognised for its significant contributions to education, research, and national security, is adequately protected under the Act.

Scope and Application

The Security of Critical Infrastructure (Australian National University) Rules (LIN 22/041) 2022, made under the Security of Critical Infrastructure Act 2018, applies specifically to the Australian National University (ANU), which is identified as a critical infrastructure asset due to its significant role in the higher education and research sector. The rules aim to override an exception in the Act that would otherwise exclude ANU from being classified as a critical infrastructure asset because it is owned by a body corporate established by a law of the Commonwealth. By prescribing ANU as a critical infrastructure asset, the rules ensure that ANU is subject to the same provisions as other universities under the Act, facilitating a consistent regulatory approach. This includes subjecting ANU to government assistance measures in the event of serious cyber-security incidents that could impact critical infrastructure. The rules specify that an asset owned or operated by ANU qualifies as a critical infrastructure asset if it is used in connection with a program of research critical to sectors other than higher education and research, the defence of Australia, or national security. These provisions are designed to focus on assets of security concern while excluding unrelated facilities such as cafeterias and gymnasiums. The rules are subject to disallowance and have been assessed for compatibility with human rights, concluding that any impact on human rights is reasonable, necessary, and proportionate to the objective of protecting national security.

Key Provisions

The Security of Critical Infrastructure (Australian National University) Rules (LIN 22/041) 2022, made under section 61 of the Security of Critical Infrastructure Act 2018 (the Act), primarily serve to redefine certain assets owned or operated by the Australian National University (ANU) as critical infrastructure assets. These rules specifically address the exclusion of ANU assets from the Act’s definition of critical infrastructure assets, which occurs due to ANU being a body corporate established by a law of the Commonwealth (subsection 9(2A) of the Act). The primary requirement of these rules, as outlined in paragraph (a), is that an asset owned or operated by the ANU is deemed a critical infrastructure asset if it is used in connection with a research program that is critical to a critical infrastructure sector, the defence of Australia, or national security. This stipulation ensures that only assets of significant security concern are classified as critical infrastructure assets, excluding those that do not pertain to these critical areas such as cafeterias and gymnasiums. The rules impose several obligations on the ANU, particularly in ensuring that the assets it owns or operates meet the criteria set out in the Act for being considered critical infrastructure assets. As the responsible entity for these assets, the ANU must ensure that any research programs using these assets align with the critical sectors outlined in the Act. Additionally, the ANU must comply with any future rules that may apply parts of the Act to these critical infrastructure assets, including positive security obligations that might be prescribed for critical education assets. The rules also require the ANU to cooperate with government measures to prevent or mitigate serious cybersecurity incidents that could impact its critical infrastructure assets. The Act provides for several offences and penalties for breaches related to critical infrastructure assets. Section 35D of the Act, for instance, stipulates that a person must not intentionally or recklessly engage in conduct that poses a serious risk of interference with a critical infrastructure asset. Breaches of this provision can result in significant penalties, including fines of up to $330,000 for individuals and $1.65 million for bodies corporate, along with potential imprisonment for up to 10 years for individuals and 15 years for bodies corporate. Additionally, section 35DA imposes penalties for recklessly endangering a critical infrastructure asset, with fines of up to $165,000 for individuals and $825,000 for bodies corporate, and imprisonment for up to five years for individuals and seven and a half years for bodies corporate. These penalties reflect the serious nature of breaches involving critical infrastructure assets and underscore the importance of compliance with the Act’s provisions. The rules also address human rights implications, particularly the right to privacy under Article 17 of the International Covenant on Civil and Political Rights (ICCPR). The rules ensure that any information gathered in relation to the ANU’s critical infrastructure assets is held securely by the government and not made available on a public register, thereby minimising the risk of arbitrary interference with privacy. The government assistance measures outlined in Part 3A of the Act, which become applicable to the ANU as a result of these rules, are designed to protect the Australian community from the risks posed by foreign involvement in critical infrastructure. These measures, including information gathering, action directions, and intervention directions, are subject to stringent conditions to ensure they are only used in the most serious circumstances and are proportionate to the threat they aim to mitigate. The rules ensure that any limitations on the right to privacy are reasonable, necessary, and proportionate to the legitimate objective of protecting Australia’s critical infrastructure from national security risks.

Legal classification tags

Area of Law
National Security Law
Instrument
Rules
Concepts
Definitions & Interpretation
Prohibited Conduct
Regulatory Standards
Offence Provisions

Interactions

Authorises

All Versions

Sourced from the Federal Register of Legislation at 26 August 2026. For the latest information on Australian Government law please go to https://www.legislation.gov.au.