The implementation of Australia’s critical infrastructure law, which makes reporting of information security events mandatory for many industry sectors, has been released by Home Affairs Minister Karen Andrews.
Multiple industry assets are classified as critical under the Security of Critical Infrastructure 2018 Act.
Telcos and internet service providers are among them, as are gasoline companies, data storage and processing firms, freight forwarders, banking, insurance, and finance firms, as well as food and grocery assets.
For addressing consumer searches of links to internet protocol addresses, domain name systems are deemed crucial.
The regulation also applies to four sugar mills in Queensland.
The ACSC requests that critical cyber security incidents that have a significant impact on the availability of Act-covered assets be notified within 12 hours of discovery by the operators.
According to the government, verbal reports to the ACSC must be accompanied by written notifications within 84 hours.
When an infrastructure incident has materially affected the availability of important goods and services, it is said to have had a significant impact.
Other occurrences affecting industrial assets must be notified to the ACSC within 72 hours.
Incidents that compromise the integrity, reliability, or confidentiality of assets covered by the Act, or the systems that support them, are considered relevant.


