Security of Critical Infrastructure (Critical infrastructure risk management program) Rules (LIN 23/006) 2023

Administered by Department of Home Affairs

Legislation au F2023L00112 Rules In force Legislative Instrument

Legislation content

 

 

Security of Critical Infrastructure (Critical infrastructure risk management program) Rules (LIN 23/006) 2023

Made under section 61 of the Security of Critical Infrastructure Act 2018 (the Act)

Compilation No. 2

Compilation date: 10 June 2026

Includes amendments: F2026L00701

About this compilation

This compilation

This is a compilation of the Security of Critical Infrastructure (Critical infrastructure risk management program) Rules (LIN 23/006) 2023 that shows the text of the law as amended and in force on 10 June 2026 (the compilation date).

The notes at the end of this compilation (the endnotes) include information about amending laws and the amendment history of provisions of the compiled law.

Uncommenced amendments

The effect of uncommenced amendments is not shown in the text of the compiled law. The details of amendments made up to, but not commenced at, the compilation date are underlined in the endnotes. Any uncommenced amendments affecting the law are accessible on the Register (www.legislation.gov.au).

Application, saving and transitional provisions

If the operation of a provision or amendment of the compiled law is affected by an application, saving or transitional provision that is not included in this compilation, details are included in the endnotes.

Modifications

If the compiled law is modified by another law, the compiled law operates as modified but the modification does not amend the text of the law. Accordingly, this compilation does not show the text of the compiled law as modified. Any modifications affecting the law are accessible on the Register.

Selfrepealing provisions

If a provision of the compiled law has been repealed in accordance with a provision of the law, details are included in the endnotes.

 

 

 

Contents

Part 1 Preliminary

1  Name

3  Definitions

4  Application of Part 2A of the Act

4A  Application of enhanced CIRMP requirements

5  Relevant Commonwealth Regulator

Part 2 Requirements for a critical infrastructure risk management program

6  Material risk

6A  Additional material risks—enhanced requirements

7  General—all hazards

8  Cyber and information security hazards

8A  Cyber and information security hazards—enhanced requirements

8B  Credential compromise hazards

8C  Lateral movement hazards

9  Personnel hazards

9A  Personnel hazards—enhanced requirements

10  Supply chain hazards

10A  Supply chain hazards—enhanced requirements

11  Physical security hazards and natural hazards

11A  Physical security hazards and natural hazards—enhanced requirements

Part 3 Application and transitional provisions

12  Application of LIN 26/075

Schedule 1—Designated hospitals

Endnotes

Endnote 1—About the endnotes

Endnote 2—Abbreviation key

Endnote 3—Legislation history

Endnote 4—Amendment history

 

 

Part 1 Preliminary

1  Name

  This instrument is the Security of Critical Infrastructure (Critical infrastructure risk management program) Rules (LIN 23/006) 2023.

3  Definitions

Note A number of expressions used in this instrument are defined in in the Act, including:

  1.       business critical data;

(aa)   computer;

(ab) connected;

(b) critical component;

(c) critical hospital;

(d) critical infrastructure asset;

(e) critical worker;

(f) relevant impact;

(g) responsible entity;

(h) security.

  In this instrument:

Act means the Security of Critical Infrastructure Act 2018.

AusCheck Act means the AusCheck Act 2007.

AusCheck Regulations means the AusCheck Regulations 2017.

background check means a background check under the AusCheck Act.

baseline CIRMP requirement means any requirement specified in Part 2 of this instrument for the purpose of paragraph 30AH(2)(b) of the Act, other than an enhanced CIRMP requirement.

CI asset means a critical infrastructure asset.

CIRMP is short for critical infrastructure risk management program.

CIRMP criminal record has the same meaning as defined in the AusCheck Regulations.

credential compromise hazard means a hazard where credentials associated with:

 (a) internet-connected computers or critical components; or

 (b) remote access to those internet-connected computers or critical components;

are used to introduce vulnerabilities that could compromise the availability, integrity, reliability or confidentiality of the CI asset.

criminal history criteria means the assessment of:

 (a) whether the person has a CIRMP criminal record; and

 (b) the nature of the offence.

critical system means any systems including operational technology or enabling systems that form critical components which are vital to the delivery of a CI asset’s function, or the compromise or degradation of which could have a relevant impact on the asset.

cyber and information security hazard includes where a person, whether authorised or not:

 (a) improperly accesses or misuses information or computer systems about or related to the CI asset; or

 (b) uses a computer system to obtain unauthorised control of, or access to the CI asset that might impair its proper functioning.

designated hospital means a critical hospital mentioned in Schedule 1.

enhanced CIRMP requirement means a requirement specified in subsection 4A(5).

FOCI means foreign ownership, control or influence.

lateral movement hazard means a hazard where a computer is used by a user (whether authorised or otherwise) to move between computer systems to critical systems, or between two critical systems, which could compromise the availability, integrity, reliability or confidentiality of the CI asset.

major supplier means any vendor that by nature of the product or service they offer, has a significant influence over the security of a responsible entity’s CI asset.

maximum acceptable outage means the maximum period of time for which a critical component, service or any other thing for the CI asset can be unavailable without unreasonably disrupting the ongoing availability, integrity, reliability or confidentiality of the CI asset.

natural hazard includes fire, flood, cyclone, storm, heatwave, earthquake, tsunami, space weather or biological health hazard (such as a pandemic).

personnel hazard includes where a critical worker acts, through malice or negligence:

 (a) to compromise the proper function of the asset; or

 (b) to cause significant damage to the asset.

physical security hazard includes the unauthorised access to, interference with, or control of CI assets, to compromise the proper function of the asset or cause significant damage to the asset.

relevant security clearance means an active security clearance that is:

 (a) issued by an Australian Government entity that is authorised to undertake security and grant security clearances; and

 (b) at a Negative Vetting 1 level or higher.

Secretary has the same meaning as defined in the AusCheck Act.

supply chain hazard includes malicious people both internal and external exploiting, misusing, accessing or disrupting the supply chain and over-reliance on particular suppliers.

4  Application of Part 2A of the Act

 (1) For paragraph 30AB(1)(a) of the Act, each of the following is specified:

 (a) a critical broadcasting asset;

 (b) a critical domain name system;

 (c) a critical data storage or processing asset;

 (d) a critical electricity asset;

 (e) a critical energy market operator asset;

 (f) a critical gas asset;

 (g) a designated hospital;

 (h) a critical food and grocery asset;

 (i) a critical freight infrastructure asset;

 (j) a critical freight services asset;

 (k) a critical liquid fuel asset;

 (l) a critical financial market infrastructure asset mentioned in paragraph 12D(1)(i) of the Act;

 (m) a critical water asset.

Note A data storage system that satisfies all of the requirements under subsection 9(7) of the Act in respect of a critical infrastructure asset specified in subsection (1) is taken to be part of the critical infrastructure asset.

 (2) For subsection 30AB(3) of the Act, Part 2A of the Act does not apply to a CI asset mentioned in subsection 4(1) during the period beginning when the asset became a CI asset and ending the later of:

 (a) 6 months after the commencement of this instrument; and

 (b) 6 months after the asset became a CI asset.

 (3) The requirements specified in this instrument for paragraph 30AH(1)(c), and subsections 30AKA(1), (3) and (5) of the Act, apply to a CI asset:

 (a) that is:

 (i) specified in subsection 4(1); and

 (ii) not specified in another instrument for paragraph 30AB(1)(a) of the Act; or

 (b) referred to in paragraph 30AB(1)(b) of the Act.

Compliance with Part 2A obligations through other instruments

 (4) Part 2 of this instrument does not apply in relation to a CI asset specified in subsection 4(1) (CIRMP Rule asset) if:

 (a) an entity is the responsible entity for the CIRMP Rule asset; and

 (aa) the CIRMP Rule asset is not an asset specified in subsection 4A(1); and

 (b) that entity is also the responsible entity for a CI asset specified in another instrument for the purposes of paragraph 30AB(1)(a) of the Act (other asset); and

 (c) a CIRMP that applies to the entity for the CIRMP Rule asset complies with the requirements specified for paragraph 30AH(1)(c) in the other instrument relating to the other asset (as if those requirements relate to the CIRMP Rule asset); and

 (d) the entity complies with the requirements specified for subsections 30AKA(1),(3) and (5) in the other instrument (as if those requirements relate to the CIRMP Rule asset).

Example: Where an entity is the responsible entity for two types of assets—one is an asset specified in subsection 4A(1) of this instrument (subsection 4A(1) asset), and the other is a relevant critical infrastructure asset, that is specified in another instrument—the entity will need to comply with the requirements in the other instrument for the relevant critical infrastructure asset, while complying with the requirements in Part 2 of this instrument for the subsection 4A(1) asset.

Example: Where an entity is the responsible entity for two types of assets—one being an asset that is not specified in subsection 4A(1) (baseline asset), and the other is a relevant critical infrastructure asset that is specified in another instrument—the entity applies the requirements in the other instrument to the baseline asset as if that asset were the relevant critical infrastructure asset. If the entity complies with the requirements in the other instrument for both assets, it is taken to have complied with the requirements in this instrument.

4A  Application of enhanced CIRMP requirements

Asset classes subject to enhanced CIRMP requirements

 (1) For the purpose of paragraph 30AH(2)(b) of the Act, the following CI assets are specified to be subject to enhanced CIRMP requirements:

 (a) a critical broadcasting asset;

 (b) a critical domain name system;

 (c) a critical electricity asset;

 (d) a critical energy market operator asset;

 (e) a critical freight infrastructure asset;

 (f) a critical freight services asset;

 (g) a critical gas asset;

 (h) a critical liquid fuel asset;

 (i) a critical water asset.

Note: Requirements specified under paragraph 30AH(1)(c) of the Act may relate to one or more specified CI assets.

Enhanced CIRMP requirements

 (2) For the purposes of paragraph 30AH(2)(b) of the Act, the requirements specified under subsection (5) for paragraph 30AH(1)(c) and subsections 30AKA(1), (3) and (5) of the Act, apply to a CI asset that is:

 (a) specified in subsection (1); or

 (b) covered by paragraph 30AB(1)(b) of the Act.

 (3) A CIRMP for a responsible entity of a CI asset that is specified in subsection (1) must comply with both enhanced CIRMP requirements and baseline CIRMP requirements.

 (4) To the extent that any inconsistency may arise between a baseline CIRMP requirement and an enhanced CIRMP requirement, the responsible entity must comply with the enhanced CIRMP requirement.

 (5) For the purpose of subsection (2), and for paragraph 30AH(1)(c) and subsections 30AKA(1), (3) and (5) of the Act, the matters specified in the following provisions of this instrument are enhanced CIRMP requirements:

 (a) section 6A;

 (b) sections 8A, 8B and 8C;

 (c) section 9A;

 (d) section 10A;

 (e) section 11A.

Grace periods

 (6) For the purposes of subsection 30AB(3) of the Act, the following provisions do not apply to a CI asset specified in subsection (1) during the period:

 (a) for section 6A and subsections 8A(2) and 9A(2):

 (i) for an asset that is a CI asset before the commencement of this instrument—beginning when the asset becomes a CI asset and ending at the end of the last day of the period of 12 months after the commencement of this instrument;

 (ii) for an asset that becomes a CI asset on or after the commencement of this instrument beginning when the asset first becomes a CI asset and ending at the end of the last day of the period of 12 months after the asset has become a CI asset; 

 (b) for sections 8A (other than subsection 8A(2)), 8B, 8C, 9A (other than subsection 9A(2)), 10A and 11A:

 (i) for an asset that is a CI asset before the commencement of this instrument—beginning when the asset becomes a CI asset and ending at the end of the last day of the period of 24 months after the commencement of this instrument;

 (ii) for an asset that becomes a CI asset on or after the commencement of this instrument—beginning when the asset first becomes a CI asset and ending at the end of the last day of the period of 24 months after the asset has become a CI asset.

5  Relevant Commonwealth Regulator

  For subparagraph (b)(ii) of the definition of relevant Commonwealth regulator in section 5 of the Act, the Reserve Bank of Australia is specified for a critical financial market infrastructure asset mentioned in paragraph 12D(1)(i) of the Act.


Part 2 Requirements for a critical infrastructure risk management program

6  Material risk

  For subsection 30AH(8) of the Act, material risk includes:

 (a) a stoppage or major slowdown of the CI asset’s function for an unmanageable period;

 (b) a substantive loss of access to, or deliberate or accidental manipulation of, a critical component of the CI asset;

Example The position, navigation and timing systems affecting provision of service or functioning of the asset.

 (c) an interference with the CI asset’s operational technology or information communication technology essential to the functioning of the asset;

Example A Supervisory Control and Data Acquisition (SCADA) system.

 (d) the storage, transmission or processing of sensitive operational information outside Australia, which includes:

 (i) layout diagrams;

 (ii) schematics;

 (iii) geospatial information;

 (iv) configuration information;

 (v) operational constraints or tolerances information;

 (vi) data that a reasonable person would consider to be confidential or sensitive about the asset;

 (e) remote access to operational control or operational monitoring systems of the CI asset;

 (f) impact to the availability, integrity, reliability or confidentiality of the data storage system holding business critical data.

6A  Additional material risks—enhanced requirements

 (1) For the purposes of paragraph 30AH(1)(c) of the Act, a responsible entity for a CI asset specified in subsection 4A(1) must establish and maintain a process or system in the entity’s CIRMP to, as far as reasonably practicable to do so minimise or eliminate the additional material risks mentioned in subsection (2).

 (2) For subsection 30AH(8) of the Act, the following specified risks are additional material risks:

 (a) any impairment of the functions of the CI asset that could prejudice the social stability, economic stability, national security or defence of Australia;

 (b) compromise or impairment of the functions of the CI asset as a result of, or in connection with FOCI;

 (c) offshore or remote access to critical components; and

 (d) offshore or remote access to business critical data.

7  General—all hazards

 (1) For paragraph 30AH(1)(c) of the Act, a responsible entity must establish and maintain a process or system in the entity’s CIRMP:

 (a) to identify the operational context of the CI asset; and

 (b) to identify the material risks to the CI asset; and

 (c) as far as it is reasonably practicable to do so:

 (i) to minimise or eliminate the material risks, which may include those mentioned in sections 6 and 6A; and

 (ii) to mitigate the relevant impact of each hazard on the CI asset; and

Note:  Material risks that are applicable to CI assets specified in subsection 4(1) are found in section 6. CI assets that are specified in subsection 4A(1) are further subject to enhanced CIRMP obligations and will need to account for the material risks specified in section 6 as well as the additional material risks that are introduced in the provisions listed in 4A(5), which includes section 6A.

 (d) to review the CIRMP to ensure compliance with section 30AE of the Act; and

 (e) to keep the CIRMP current to ensure it complies with section 30AF of the Act.

 (2) For subsections 30AKA(1), (3) and (5) of the Act, a responsible entity must have regard to whether the entity’s CIRMP:

 (a) describes the outcome of the process or system mentioned in paragraph (1)(a);

 (b) describes interdependencies between the entity’s CI asset and other CI assets;

 (c) identifies each position within the entity:

 (i) that is responsible for developing and implementing the CIRMP; and

 (ii) for the processes mentioned in paragraph (1)(d)—that is responsible for reviewing the CIRMP or keeping the CIRMP up to date;

 (d) contains the contact details for the positions described under paragraph (c);

 (e) contains a risk management methodology;

 (f) describes the circumstances in which the entity will review the CIRMP.

8  Cyber and information security hazards

 (1) For paragraph 30AH(1)(c) of the Act, subsections (2) and (3) specify requirements for cyber and information security hazards.

 (2) A responsible entity must establish and maintain a process or system in the CIRMP to—as far as it is reasonably practicable to do so:

 (a) minimise or eliminate any material risk of a cyber and information security hazard occurring; and

 (b) mitigate the relevant impact of a cyber and information security hazard on the CI asset.

 (3) Within 12 months after the end of the applicable period mentioned in subsection 4(2), a responsible entity must comply with subsection (4) or (5).

 (4) A responsible entity must establish and maintain a process or system in the CIRMP to:

 (a) comply with a framework contained in a document mentioned in the following table as in force from time to time; and

 (b) meet any conditions mentioned in the table for the document.

 

Item

Document

Condition

1

Australian Standard AS ISO/IEC 27001:2015

 

2

Essential Eight Maturity Model published by the Australian Signals Directorate

Meet maturity level one as indicated in the document

3

Framework for Improving Critical Infrastructure Cybersecurity published by the National Institute of Standards and Technology of the United States of America

 

4

Cybersecurity Capability Maturity Model published by the Department of Energy of the United States of America

Meet Maturity Indicator Level 1 as indicated in the document

5

The 202021 AESCSF Framework Core published by Australian Energy Market Operator Limited (ACN 072 010 327)

Meet Security Profile 1 as indicated in the document

 

Note Sections 30AN and 30ANA of the Act provide for the incorporation of the documents mentioned in this subsection as in force from time to time.

 (5) A responsible entity must establish and maintain a process or system in the entity’s CIRMP to comply with a framework that is equivalent to a framework in a document mentioned in subsection (4), including any conditions.

 (6) For subsections 30AKA(1), (3) and (5) of the Act, a responsible entity must have regard to whether the entity’s CIRMP describes the cyber and information security hazards that could have a relevant impact on the asset.

8A  Cyber and information security hazards—enhanced requirements

 (1) For paragraph 30AH(1)(c) of the Act, subsections (2), (3) and (4) of this section specify enhanced requirements in relation to cyber and information security hazards.

 (2) A responsible entity for a CI asset specified in subsection 4A(1) must establish and maintain a process in the entity’s CIRMP to—so far as it is reasonably practicable to do so—minimise or eliminate each of the following material risks:

 (a) failure to patch or update operating or security systems in a timely manner;

 (b) failure to replace legacy systems, or adequately mitigate risks associated with components or technology that are redundant, unsupported, obsolete or discontinued;

 (c) deployment or hosting of advanced, novel or emerging technology in a manner that could prejudice the availability, integrity, reliability or confidentiality of the CI asset; and

 (d) use of advanced, novel or emerging technology against the asset, in a manner that could prejudice the availability, integrity, reliability or confidentiality of the CI asset.

 (3) A responsible entity for a CI asset specified in subsection 4A(1) must establish and maintain a process or system in the entity’s CIRMP to:

 (a) comply with a framework contained in a document specified in column 1 of an item in the following table as in force from time to time; and

 (b) meet any conditions mentioned in column 2 of the same table item in relation to the framework specified in column 1 of the item.

 


Item

Column 1
Document

Column 2
Condition

1

Australian Standard AS ISO/IEC 27001:2023

 

2

Essential Eight Maturity Model published by the Australian Signals Directorate

Meet maturity level two as indicated in the document

3

The NIST Cybersecurity Framework (CSF) 2.0 published by the National Institute of Standards and Technology of the United States of America.

 

4

Cybersecurity Capability Maturity Model (Version 2.1) published by the Department of Energy of the United States of America

Meet Maturity Indicator Level 2 as indicated in the document

5

The 2023 AESCSF Framework Core published by Australian Energy Market Operator Limited (ACN 072 010 327)

Meet Security Profile 2 as indicated in the document

 

Note: Section 30AN and 30ANA of the Act provide for the incorporation of the documents mentioned in this subsection as in force from time to time.

 (4) A responsible entity for a CI asset specified in subsection 4A(1) may otherwise comply with subsection (3) of this section by establishing and maintaining a process or system in their CIRMP to comply with another framework, that achieves a level of security equivalent to a framework contained in a document specified in column 1 of items 2, 4 or 5 of subsection (3), and including any relevant conditions specified in column 2.

 (5) For subsections 30AKA(1), (3) and (5) of the Act, a responsible entity for a CI asset specified in subsection 4A(1) must also have regard to whether the CIRMP contains appropriate measures that minimise or eliminate material risks to the asset including those specified in subsection (2).

8B  Credential compromise hazards

 (1) This section applies if a responsible entity for a CI asset specified in subsection 4A(1) complies with a framework specified under subsection 8A(3) or (4) which does not require the implementation of phishing resistant multi-factor authentication controls.

 (2) For paragraph 30AH(1)(c) of the Act, subsection (3) specifies requirements for credential compromise hazards.

 (3) A responsible entity for a CI asset specified in subsection 4A(1) must establish and maintain a process or system in the CIRMP to—so far as is reasonably practicable to do so:

 (a) outline the systems or networks where phishing resistant multi-factor authentication is required to authenticate;

 (i) access to their organisation’s internet connected computers and critical systems;

 (ii) privileged and unprivileged access to critical components;

 (iii) remote access to computer applications, systems or services; and

 (b) minimise or eliminate any material risk of a credential compromise hazard occurring; and

 (c) mitigate the relevant impact of the credential compromise hazard on the CI asset.

 (4) For subsection 30AH(9) of the Act, the implementation of phishing resistant multi-factor authentication controls, as provided for in subsection (5), is taken to be the action that minimises or eliminates any material risk that the credential compromise hazard could have a relevant impact on the asset.

 (5) For the purposes of subsection (4), a responsible entity for a CI asset specified in subsection 4A(1) must:

 (a) implement phishing resistant multi-factor authentication controls for the systems and networks outlined in paragraph (3)(a); and

 (b) centrally log, monitor and routinely review both successful and unsuccessful multi-factor authentication attempts.

Note:  Where a responsible entity for a CI asset specified in subsection 4A(1) cannot implement the measures outlined in subsections 8B(4) and (5), they should still include a process or system in their CIRMP containing reasonable steps that must be taken to minimise or eliminate the material risks associated with the occurrence of a credential compromise hazard, in line with the general obligation in subsection 8B(3).

 (6) For subsections 30AKA(1), (3) and (5) of the Act, a responsible entity for a CI asset specified in subsection 4A(1) must also have regard to whether the CIRMP:

 (a) includes a process or system capable of outlining all of the systems and networks where phishing resistant multi-factor authentication is required under paragraph (3)(a);

 (b) describes the credential compromise hazards that could have a relevant impact on the asset; and

 (c) contains appropriate measures to minimise or eliminate material risks to the asset.

8C  Lateral movement hazards

 (1) For paragraph 30AH(1)(c) of the Act, subsection (2) specifies requirements for lateral movement hazards.

 (2) A responsible entity for a CI asset specified in subsection 4A(1) must establish and maintain a process or system in the entity’s CIRMP to:

 (a) identify and maintain an inventory of critical systems and how they are connected with other critical systems and other computers; and

 (b) recover and restore critical systems in the event where an incident has had or is having a relevant impact on the asset; and

 (c) ensure the continued availability of the asset whilst rebuilding or restoring critical systems; and

 (d) as far as it is reasonably practicable to do so:

 (i) minimise or eliminate any material risk of a lateral movement hazard occurring; and

 (ii) mitigate the relevant impact of the lateral movement hazard on the CI asset.

 (3) For subsection 30AH(9) of the Act, the implementation of network segregation that complies with subsection (4), is taken to be the action that minimises or eliminates any material risk that the occurrence of a lateral movement hazard could have a relevant impact on the CI asset.

 (4) For the purposes of subsection (3), the following elements are required to achieve network segregation of critical systems:

 (a) ensuring critical systems can be segregated as between critical systems, and between critical systems and other computers;

 (b) ensuring critical systems can be operationally independent from other internet connected computers and critical systems;

 (c) ensuring critical systems can continue to be operational for a period of at least three months while other computers are in a state of restoration or recovery;

 (d) implementing logical access controls for network traffic between critical systems, and between critical systems and other computers;

 (e) centrally logging, monitoring and routinely reviewing access logs for communication paths between critical systems, and between critical systems and other computers; and

 (f) implementing principles of least privilege across computers that connect to critical systems.

Note:  Where a responsible entity for a CI asset specified in subsection 4A(1) cannot implement the measures outlined in subsections 8C(3) and (4), they should still include a process or system in their CIRMP containing reasonable steps that must be taken to minimise or eliminate the material risks associated with the occurrence of a lateral movement hazard, in line with their general obligation in subsection 8C(2).

 (5) For subsections 30AKA(1), (3) and (5) of the Act, a responsible entity for a CI asset specified in subsection 4A(1) must also have regard to whether the CIRMP:

 (a) describes the lateral movement hazards that could have a relevant impact on the asset;

 (b) includes a process or system capable of identifying the matters at paragraphs (2)(a), (b) and (c); and

 (c) contains appropriate measures to minimise or eliminate material risks to the asset.

9  Personnel hazards

 (1) For paragraph 30AH(1)(c) of the Act, for personnel hazards, a responsible entity must establish and maintain a process or system in the entity’s CIRMP:

 (a) to identify the entity’s critical workers; and

 (b) to permit a critical worker access to critical components of the CI asset only where the critical worker has been assessed to be suitable to have such access; and

 (c) as far as it is reasonably practicable to do so—to minimise or eliminate the following material risks:

 (i) arising from malicious or negligent employees or contractors; and

 (ii) arising from the off-boarding process for outgoing employees and contractors.

 (2) For paragraph (1)(b) and paragraph 30AH(4)(a) of the Act, the process or system for assessing the suitability of a critical worker may be a background check conducted under the AusCheck scheme.

Note:  Subject to subsection 9A(4), a responsible entity is not required to use the AusCheck scheme to assess the suitability of critical workers, unless the responsible entity is a responsible entity of an asset specified in subsection 4A(1).

 (3) If a CIRMP permits a background check to be conducted under subsection (2), the background check must include assessment of information relating to the matters mentioned in paragraphs 5(a), (b), (c) and (d) of the AusCheck Act; and

 (a) for paragraph 30AH(4)(c) of the Act—the criteria against which the information must be assessed are the criminal history criteria; and

 (b) for paragraph 30AH(4)(d) of the Act—the assessment must consist of both an electronic identity verification check and an in person identity verification check.

 (4) A responsible entity must notify the Secretary if a background check is no longer required for a critical worker.

 (5) In making a suitability assessment mentioned in paragraph (1)(b), a responsible entity must consider the following:

 (a) any advice from the Secretary under the following provisions of the AusCheck Regulations:

 (i) paragraph 21DA(2)(a);

 (ii) paragraph 21DA(2)(b);

 (iii) subsection 21DA(4);

 (iv) subsection 21DA(5); and

 (b) whether permitting a critical worker to have access to critical components of the CI asset would be prejudicial to security; and

 (c) any other information that may affect the person’s suitability to have access to the critical components of the CI asset.

Note A responsible entity may be required to inform the Secretary of a decision to grant or revoke access to a critical infrastructure asset, in certain circumstances—see AusCheck Regulations, section 21ZA.

 (6) For subsections 30AKA(1), (3) and (5) of the Act, a responsible entity must have regard:

 (a) to whether the CIRMP lists the entity’s critical workers; and

 (b) to whether the CIRMP describes the personnel risks, the occurrence of which could have a relevant impact on the asset.

9A  Personnel hazards—enhanced requirements

 (1) For paragraph 30AH(1)(c) of the Act, subsections (2), (3), (4), (5), (6) and (7) specify enhanced requirements for personnel hazards.

Personnel security—access management

 (2) A responsible entity for a CI asset specified in subsection 4A(1) must establish and maintain a process or system in the entity’s CIRMP to minimise or eliminate the material risk associated with:

 (a) unauthorised or unsupervised access to critical components;

 (b) the compromise or misuse of credentials and privileged access used by individuals to access the CI asset;

 (c) access to the CI asset by persons other than critical workers for the CI asset; and

 (d) incoming and outgoing critical workers.

Suitability of critical workers

 (3) A responsible entity for a CI asset specified in subsection 4A(1) must establish and maintain a process or system in the entity’s CIRMP to:

 (a) permit a critical worker access to critical components only where:

 (i)  the critical worker has been assessed to be suitable in accordance with subsection (4); or

 (ii) if the critical worker is unable to meet the requirements outlined in subsection (4) –the responsible entity has outlined in their CIRMP the risk associated with the employment of the critical worker and actions taken, or actions that will be taken as soon as reasonably practicable to do so, to minimise or eliminate the risk to the asset; and

 (b) proactively monitor, identify and take action in relation to any developments or changes that may affect the ongoing suitability of a critical worker.

 (4) For paragraph (3)(a) of this instrument and paragraph 30AH(4)(a) of the Act, a critical worker may be assessed as suitable only if:

 (a) the critical worker has:

 (i) been the subject of an AusCheck background check; and

 (ii) following the completion of the AusCheck background check, has been assessed as suitable by the responsible entity considering the matters in subsection 9(5); or

 (b) the critical worker holds a relevant security clearance at the time the person was identified to be a critical worker.

Note: Where a critical worker holds a relevant security clearance they will not be required to undergo an AusCheck background check. However, where that worker is yet to receive their relevant security clearance as their application is pending, the critical worker will still need to be assessed as suitable under paragraph (4)(a). Only after the critical worker has been assessed as suitable under either paragraphs (4)(a) or (b), or if subparagraph (3)(a)(ii) applies, can a critical worker be permitted access to critical components.

Further matters relating to the AusCheck background check

 (5) If a CIRMP permits an AusCheck background check to be conducted for the purposes of paragraph (4)(a), the background check must:

 (a) include an assessment of the information outlined in subsection 9(3);

 (b) be conducted in accordance with subsection 9(4); and

 (c) if the background check relates to a person requiring ongoing access to critical components—be conducted (at minimum) every 5 years.

Further matters relating to relevant security clearances

 (6) If a CIRMP permits a critical worker access to critical components where the critical worker has been assessed as suitable by holding a relevant security clearance for the purposes of paragraph (4)(b), the responsible entity for a CI asset specified in subsection 4A(1) must establish and maintain a process or system in their CIRMP to ensure that, before that clearance lapses or expires, the person has:

 (a) undergone a revalidation of their relevant security clearance; or

 (b) undergone an AusCheck background check and has been assessed as suitable by the responsible entity considering the matters in subsection 9(5).

 (7) For subsections 30AKA(1), (3) and (5) of the Act, a responsible entity must also have regard to whether the entity’s CIRMP:

 (a) contain appropriate measures that minimise or eliminate material risks to the CI asset, including those specified in subsection (2) of this section.

 (b) includes processes or systems capable of identifying the matters in subsections  (3) and (4) of this section for their CI asset.

10  Supply chain hazards

 (1) For paragraph 30AH(1)(c) of the Act, for supply chain hazards, a responsible entity must establish and maintain in the entity’s CIRMP a process or system to:

 (a) as far as it is reasonably practicable to do so—minimise or eliminate the following material risks:

 (i) unauthorised access, interference or exploitation of the asset’s supply chain; and

 (ii) misuse of privileged access to the asset by any provider in the supply chain; and

 (iii) disruption of the asset due to an issue in the supply chain; and

 (iv) arising from threats to people, assets, equipment, products, services, distribution and intellectual property within supply chains; and

 (v) arising from major suppliers; and

 (vi) any failure or lowered capacity of other assets and entities in the entity’s supply chain; and

 (b) as far as it is reasonably practicable to do so—mitigate the relevant impact of a supply chain hazard on the asset.

 (2) For subsections 30AKA(1), (3) and (5) of the Act, a responsible entity must have regard:

 (a) to whether the CIRMP lists the entity’s major suppliers; and

 (b) to whether the CIRMP describes the supply chain hazards, which could have a relevant impact on the asset.

10A  Supply chain hazards—enhanced requirements

 (1) For paragraph 30AH(1)(c) of the Act, subsections (2), (3), (4) and (5) specify enhanced requirements for supply chain hazards.

Supply chain mapping

 (2) A responsible entity of a CI asset specified in subsection 4A(1) must establish and maintain a system or process in the entity’s CIRMP to map their supply chain for major suppliers and critical components across their supply chains.

 (3) In accordance with subsection (2), the entity’s CIRMP must:

 (a) identify risks in the entity’s supply chain that may affect the availability, integrity, reliability or confidentiality of critical components or compromise business critical data; and

 (b) identify the maximum acceptable outage for the CI asset or any of its critical components arising from the disruption to the entity’s supply chain; and

 (c) as far as is reasonably practicable to do so—include measures to minimise or eliminate those risks, or mitigate the impact of an outage that exceeds the maximum acceptable outage identified in paragraph (3)(b).

Note:  Mitigation measures for the purpose of paragraph (3)(c) may include, but are not limited to, supplier diversification, redundancy planning, recovery, resilience and restoration processes.

Vendor assessment

 (4) A responsible entity for a CI asset specified in subsection 4A(1) must establish and maintain a system or process in the entity’s CIRMP to assess the risks associated with an existing or proposed major supplier for the CI asset.

 (5) The system or process outlined in subsection (4) must identify, for each existing or proposed major supplier:

 (a) in relation to FOCI risks—legislative or other legal requirements to which the supplier is subject to; and

 (b) restrictions, sanctions or other impediments affecting the jurisdiction to which the entity may be subject to; and

 (c) the access, influence and control the supplier has over the CI asset in connection with the product or service the supplier provides; and

 (d) the extent to which the matters in paragraphs (a), (b) and (c) together may present a material risk for the CI asset, or could exceed a maximum acceptable outage of the service or product provided by the supplier; and

 (e) as far as reasonably practicable to do so—steps to minimise or eliminate material risks and mitigate the relevant impact of the hazard on the CI asset.

 (6) For subsections 30AKA(1), (3) and (5) of the Act, a responsible entity must have regard to:

 (a) whether the CIRMP includes a process or system capable of identifying the matters in paragraphs (3)(a), (b) and (c) for their CI asset; and

 (b) whether the CIRMP includes a process or system capable of identifying the matters in paragraphs (5)(a) to (e).

11  Physical security hazards and natural hazards

 (1) For paragraph 30AH(1)(c) of the Act, for physical security hazards and natural hazards, a responsible entity must establish and maintain a process or system in the entity’s CIRMP:

 (a) to identify the physical critical components of the CI asset; and

 (b) as far as it is reasonably practicable to do so—to minimise or eliminate a material risk, and mitigate a relevant impact, of:

 (i) a physical security hazard on a physical critical component; and

 (ii) a natural hazard on the CI asset; and

 (c) to respond to incidents where unauthorised access to a physical critical component occurs; and

 (d) to control access to physical critical components, including restricting access to only those individuals who are critical workers or accompanied visitors; and

 (e) to test that security arrangements for the asset are effective and appropriate to detect, delay, deter, respond to and recover from a breach in the arrangements.

 (2) For subsections 30AKA(1), (3) and (5) of the Act, a responsible entity must have regard to whether:

 (a) the asset’s critical components are described in the CIRMP; and

 (b) the physical security hazards, the occurrence of which could have a relevant impact on a physical critical component, are described in the CIRMP; and

 (c) the security arrangements for the asset are described in the CIRMP; and

 (d) the CIRMP describes the natural hazards, the occurrence of which could have a relevant impact on the physical critical component.

11A  Physical security hazards and natural hazards—enhanced requirements

 (1) For the purpose of paragraph 30AH(1)(c) of the Act, for physical security hazards and natural hazards, a responsible entity for a CI asset specified in subsection 4A(1) must establish and maintain a process or system in the entity’s CIRMP to:

 (a) centrally manage physical security and natural hazards; and

 (b) as far as it is reasonably practicable to do so—outline and consider the physical security consequences arising from the occurrence of all hazards, including cyber and information security hazards, credential compromise hazards, lateral movement hazards, other physical and natural hazards, personnel hazards and supply chain hazards.

Note:  Some examples of non-physical hazards that have physical security consequences could include malicious cyber incidents that opens gates to allow unauthorised access, or a supply chain delay that results in changes to workplace operations that decrease the ability to deter, detect, delay, respond to and recover from a breach in security.

 (2) For the purposes of paragraph (1)(a), the responsible entity for a CI asset specified in subsection 4A(1) must outline:

 (a) the location, ownership, and nature of the site upon which their asset is located; and

 (b) the critical components of the CI asset; and

 (c) areas within the asset that hold business critical data or contain critical components including critical systems.

 (3) For the purposes of paragraph (1)(b), the responsible entity for a CI asset specified in subsection 4A(1) must, as far as reasonably practicable, consider and outline the following:

 (a) any physical access controls to the CI asset for workers, official visitors, and the public, including but not limited to:

 (i) access controls for critical components and critical systems to restrict access to critical workers or accompanied visitors;

 (ii) maintaining surveillance and security alarm systems, such that critical components and critical systems are subject to continuous monitoring;

 (iii) specific protective security measures for business hours and out-of-hours; and

 (b) other security measures that increase the ability to deter, detect, delay, respond to and recover from a breach in security for all critical components; and

 (c) mitigation and response measures to be taken where a physical security incident or a physical security consequence has been detected.

 (4) For the purposes of subsections 30AKA(1), (3) and (5) of the Act, a responsible entity for a CI asset specified in subsection 4A(1) must have regard to whether the CIRMP contains systems or processes capable of identifying the matters in subsections (1), (2) and (3).

Part 3 Application and transitional provisions

12  Application of LIN 26/075

  The amendments of this instrument made by the Security of Critical Infrastructure Legislation Amendment (Enhanced Critical Infrastructure Risk Management Program) Rules 2026 (LIN 26/075) do not apply in relation to an asset:

 (a) that was declared to be a critical infrastructure asset under section 51 of the Act before the commencement of LIN 26/075; and

 (b) where the declaration provides that the asset is subject to Part 2A of the Act; and

 (c) where the declaration as made before the commencement of LIN 26/075 continues to be in force.

Note: Where an asset was declared to be a critical infrastructure asset under section 51 of the Act prior to the commencement of this provision, and the declaration declares that asset is subject to Part 2A of the Act, that obligation does not automatically include compliance with the enhanced CIRMP requirements specified in subsection 4A(5).


Schedule 1—Designated hospitals

(section 3)

  A designated hospital means a critical hospital mentioned in an item in the following table located in the State or Territory mentioned in the item.

 

Item

Hospital

State or Territory

1

Bankstown-Lidcombe Hospital

Blacktown Hospital

Calvary Mater Newcastle

Campbelltown Hospital

Children's Hospital Westmead

Coffs Harbour Health Campus

Concord Repatriation General Hospital

Dubbo Base Hospital

Gosford Hospital

Hornsby Ku-Ring-Gai Hospital

John Hunter Hospital

Lake Macquarie Private Hospital

Lismore Base Hospital

Liverpool Hospital

Nepean Hospital

Northern Beaches Hospital

Northern Beaches Hospital

Orange Base Hospital

Port Macquarie Base Hospital

Prince of Wales Hospital

Royal North Shore Hospital

Royal Prince Alfred Hospital

St George Hospital

St Vincent's Hospital (Darlinghurst)

Sydney Children's Hospital

Tamworth Hospital

The Sutherland Hospital

The Tweed Hospital

Wagga Wagga Base Hospital

Westmead Hospital

Wollongong Hospital

New South Wales

2

Austin Hospital – Austin Health

Box Hill Hospital – Eastern Health

Cabrini Malvern

Dandenong Hospital – Monash Health

Frankston Hospital – Peninsula Health

Knox Private Hospital

Monash Children’s Hospital – Monash Health

Monash Medical Centre (Clayton) – Monash Health

Northern Hospital – Northern Health

Royal Melbourne Hospital – Melbourne Health

St Vincent’s Hospital (Melbourne) Limited

The Alfred – Alfred Health

The Royal Children's Hospital

The Royal Women's Hospital

University Hospital (Geelong) – Barwon Health

Victoria

3

Bundaberg Base Hospital

Caboolture Hospital

Cairns Base Hospital

Gold Coast University Hospital

Greenslopes Private Hospital

Hervey Bay Hospital

Ipswich Hospital

Logan Hospital

Mackay Base Hospital

Mater Adult Hospital

Mater Hospital Brisbane

Princess Alexandra Hospital

Queen Elizabeth II Jubilee Hospital

Queensland Children's Hospital

Redcliffe Hospital

Robina Hospital

Rockhampton Hospital

Royal Brisbane & Women's Hospital

Sunshine Coast Public University Hospital

The Prince Charles Hospital

The Wesley Hospital

Toowoomba Hospital

Townsville University Hospital

Queensland

4

Armadale Hospital

Bunbury Regional Hospital

Fiona Stanley Hospital

Hollywood Private Hospital

Joondalup Health Campus

Joondalup Health Campus

King Edward Memorial Hospital

Perth's Children’s Hospital

Rockingham General Hospital

Royal Perth Hospital

Sir Charles Gairdner Hospital

St John of God Midland Public Hospital

Western Australia

5

Calvary Hospital Adelaide

Flinders Medical Centre

Lyell McEwin Hospital

Royal Adelaide Hospital

The Queen Elizabeth Hospital

Women's and Children's Hospital

South Australia

6

Launceston General Hospital

Royal Hobart Hospital

Tasmania

7

Canberra Hospital

Australian Capital Territory

8

Alice Springs Hospital

Royal Darwin Hospital

Northern Territory

 

 

Endnotes

Endnote 1—About the endnotes

The endnotes provide information about this compilation and the compiled law.

The following endnotes are included in every compilation:

Endnote 1—About the endnotes

Endnote 2—Abbreviation key

Endnote 3—Legislation history

Endnote 4—Amendment history

Abbreviation key—Endnote 2

The abbreviation key sets out abbreviations that may be used in the endnotes.

Legislation history and amendment history—Endnotes 3 and 4

Amending laws are annotated in the legislation history and amendment history.

The legislation history in endnote 3 provides information about each law that has amended (or will amend) the compiled law. The information includes commencement details for amending laws and details of any application, saving or transitional provisions that are not included in this compilation.

The amendment history in endnote 4 provides information about amendments at the provision (generally section or equivalent) level. It also includes information about any provision of the compiled law that has been repealed in accordance with a provision of the law.

Misdescribed amendments

A misdescribed amendment is an amendment that does not accurately describe how an amendment is to be made. If, despite the misdescription, the amendment can be given effect as intended, then the misdescribed amendment can be incorporated through an editorial change made under section 15V of the Legislation Act 2003.

If a misdescribed amendment cannot be given effect as intended, the amendment is not incorporated and “(md not incorp)” is added to the amendment history.

 

Endnote 2—Abbreviation key

 

ad = added or inserted

orig = original

am = amended

p = page(s)

amdt = amendment

para = paragraph(s)/subparagraph(s)

C[x] = Compilation No. x

/subsubparagraph(s)

ch = Chapter(s)

pres = present

cl = clause(s)

prev = previous

cont. = continued

(prev…) = previously

def = definition(s)

pt = Part(s)

Dict = Dictionary

r = regulation(s)/Court rule(s)

disallowed = disallowed by Parliament

reloc = relocated

div = Division(s)

renum = renumbered

exp = expires/expired or ceases/ceased to have

rep = repealed

effect

rs = repealed and substituted

gaz = gazette

s = section(s)/subsection(s)

LA = Legislation Act 2003

/rule(s)/subrule(s)/order(s)/suborder(s)

LIA = Legislative Instruments Act 2003

sch = Schedule(s)

(md not incorp) = misdescribed amendment

SLI = Select Legislative Instrument

cannot be given effect

SR = Statutory Rules

mod = modified/modification

sub ch = SubChapter(s)

No. = Number(s)

sub div = Subdivision(s)

Ord = Ordinance

sub pt = Subpart(s)

 

underlining = whole or part not

 

commenced or to be commenced

 

Endnote 3—Legislation history

 

Name

Registration

Commencement

Application, saving and transitional provisions

Security of Critical Infrastructure (Critical infrastructure risk management program) Rules (LIN 23/006) 2023)

16 February 2023

17 February 2023

-

Security of Critical Infrastructure Amendment (2025 Measures No. 1) Rules 2025

13 March 2025

04 April 2025

-

Security of Critical Infrastructure Legislation Amendment (Enhanced Critical Infrastructure Risk Management Program) Rules 2026

9 June 2026

10 June 2026

-

 

Endnote 4—Amendment history

 

Provision affected

How affected

Section 2

Section 3

rep LA s 48D

am F2025L00324; F2026L00701

Section 4

ad F2025L00324

am F2026L00701

Section 4A

Section 6

ad F2026L00701

ad F2025L00324

Section 6A

ad F2026L00701

Section 7

am F2026L00701

Section 8A

ad F2026L00701

Section 8B

ad F2026L00701

Section 8C

ad F2026L00701

Section 9

am F2026L00701

Section 9A

ad F2026L00701

Section 10A

ad F2026L00701

Section 11A

ad F2026L00701

Section 12

ad F2026L00701

 

Interactions

Authorises

All Versions

Sourced from the Federal Register of Legislation at 26 August 2026. For the latest information on Australian Government law please go to https://www.legislation.gov.au.