Description

Security Legislation Amendment (Critical Infrastructure Protection) Bill 2022 adopted

On 31 March 2022, the Security Legislation Amendment (Critical Infrastructure Protection) Bill 2022, including expanded cybersecurity rules for critical infrastructure, has been adopted by the Australian Parliament after passing in the Senate. The Bill applies to critical infrastructure assets, including certain water, gas, and electricity assets defined in the Security of Critical Infrastructure Act 2018. The Bill would introduce a requirement for entities to create and maintain a risk management program identifying relevant hazards and taking steps to minimise such hazards. The Bill would further create enhanced cybersecurity obligations for systems of national significance, including infrastructure assets of special importance to the stability, defence, or national security of Australia. The additional obligations of systems of national significance include the possibility of being subjected to incident response planning, cybersecurity exercises, and vulnerability assessments. The Bill must still receive Royal Assent and will enter into force on the following day.

Original source

Scope

Policy Area
Data governance
Policy Instrument
Cybersecurity regulation
Regulated Economic Activity
infrastructure provider: other
Implementation Level
national
Government Branch
legislature
Government Body
parliament

Complete timeline of this policy change

Hide details
2022-02-10
under deliberation

On 10 February 2022, the Security Legislation Amendment (Critical Infrastructure Protection) Bill 2…

2022-03-31
adopted

On 31 March 2022, the Security Legislation Amendment (Critical Infrastructure Protection) Bill 2022…

Key regulatory dimensions

Regulated subjects

The businesses, government agencies or individuals affected by this policy or regulatory change.
producer / supplier
1
Type Any
Economic activity infrastructure provider: internet and telecom services
Category All

Policy change by business practice

The detailed activities within the scope of this policy or regulatory change.
service (physically delivered): operate
Regulatory tool
Risk or other impact assessment requirement
Preventive security requirement
Responsive security requirement
Sanctions
Regulated subjects
1

Policy change by business practice

The detailed activities within the scope of this policy or regulatory change.

service (physically delivered): operate