AUSTRALIA Law and Practice Contributed by: Dennis Miralis, Jack Dennis, Henry Yu and Phillip Salakas, Nyman Gibson Miralis
Other Laws Areas that are also related to cybersecurity include: • the Broadcasting Services Act 1992 (Cth) (the “Broadcasting Act”) regulates broadcasting ser - vices through internet and other means in Australia and enables the creation of industry codes of prac - tice regulating the content of such services; • the Online Safety Act 2021 (Cth) (OSA) establishes complaint systems for cyberbullying of children, non-consensual sharing of intimate images, cyber- abuse of adults, and the online/social media avail - ability of content that would be subject to broad - casting classifications (restricted or age 18 years or older); • the Spam Act 2003 (Cth) (the “Spam Act”) prohib - its the use of electronic communications for the purpose of sending unsolicited marketing materials to individuals; and • the Do Not Call Register Act 2006 (Cth) (the “DNCR Act”) prohibits unsolicited telemarketing calls being made to phone numbers registered on a Do Not Call Register. 1.3 Cybersecurity Regulators Australia has a range of federal, state, and territory regulators and agencies which deal with cybersecu - rity. The overarching government agencies are: • Department of Home Affairs (DoHA); and • Australian Signals Directorate (ASD). While the key regulators and enforcement bodies include: • Office of the Information Commissioner (OAIC); • Critical Infrastructure Centre (CIC); • Australian Communications and Media Authority (ACMA); • Australian Securities and Investments Commission (ASIC); • Australian Prudential Regulation Authority (APRA); and • Australian Competition and Consumer Commission (ACCC).
Specifically in relation to criminal enforcement, the fol - lowing regulators are key: • Australian Federal Police (AFP); • Commonwealth Director of Public Prosecutions (CDPP); • Australian Security Intelligence Organisation (ASIO); • Australian Transaction Reports and Analysis Centre (AUSTRAC); and • Australian Criminal Intelligence Commission (ACIC). Each of the above are addressed below. Overarching Government Agencies DoHA The DoHA is the lead government department for cyberpolicy. The DoHA develops cybersecurity and cybercrime law and policy, implements Australia’s national cybersecurity strategy, and responds to international and domestic cybersecurity threats and opportunities, including in the areas of critical infra - structure and emerging technologies. The DoHA also has responsibility for cybersecurity and cybercrime operational agencies including the AFP, ACIC, AUS - TRAC, and ASIO. ASD, ACSC and CERT The ASD is Australia’s operational lead on cyberse - curity and plays both a signals intelligence and infor - mation security role. The ASD undertakes cyberthreat monitoring and conducts defensive, disruption, and offensive cyber-operations offshore to support mili - tary operations and to counter terrorism, cyber-espio - nage, and serious cyber-enabled crime. The ASD also advises and co-ordinates operational responses to cyber-intrusions on government, critical infrastructure, information networks and other systems of national significance. Within the ASD sits the Australian Cyber Security Centre (ACSC). The ACSC drives cyber-resilience across the whole Australian economy including with respect to critical infrastructure, government, large organisations and small to medium businesses, aca - demia, NGOs, and the broader Australian community. The ACSC provides general information, advice, and
12 CHAMBERS.COM
Powered by FlippingBook