AUSTRALIA Law and Practice Contributed by: Dennis Miralis, Jack Dennis, Henry Yu and Phillip Salakas, Nyman Gibson Miralis
• fulfil statutory response planning obligations; • undertake a cybersecurity exercise (see 3.6 Threat- Led Penetration Testing ); • undertake a vulnerability assessment (see 3.6 Threat-Led Penetration Testing ); and • where the system is a computer or needs a com - puter to operate the system, undertake periodic reports, provide event-based reports or install soft - ware that transmits system information to the ASD. It is also worth noting that the SOCI Act also includes: • an information gathering power for the Secretary of the DoHA to monitor compliance; and • a directions power for the Home Affairs Minister to direct regulated entities to do or not do a specified thing that is reasonably necessary to protect criti - cal infrastructure from national security risks. 2.3 Incident Response and Notification The SOCI Act imposes mandatory incident reporting obligations for responsible entities of critical infra - structure assets with regards to cybersecurity inci - dents. Responsible entities must report cybersecurity inci - dents that have a significant or relevant impact on their asset. In other words, a “responsible entity” must make a report when it becomes aware of the follow - ing. Obligations The SOCI Act • Under Section 30BC a “cyber security incident” that “has had, or is having, a significant impact (whether direct or indirect) on the availability of the asset” – such a “significant impact” is defined as being where “the incident has materially disrupted the availability of [the] essential goods or service” in connection with which the asset is used to pro - vide. The report must be made “as soon as prac - ticable, and in any event within 12 hours, after the entity becomes aware”. If the initial report is oral, then a written report must be made within 84 hours after the oral report is given; and • Under Section 30BD a “cyber security incident” that “has had, or is having, or is likely to have, a relevant impact on the asset” – such a “relevant
impact” is defined (for critical infrastructure assets) as a (direct or indirect) impact on the availability, integrity, reliability of the asset, or on the confiden - tiality of information about the asset, information stored on the asset or computer data constituting the asset. The report must be made “as soon as practicable, and in any event within 72 hours, after the entity becomes aware. If the initial report is oral, then a written report must be filed within 48 hours of the oral report. A “cyber security incident”, as defined under Section 12M, is the: • unauthorised access to or modification of com - puter data or computer program; • unauthorised impairment of electronic communica - tions to or from a computer (but does not include “a mere interception of any such communication”); or • unauthorised impairment of the availability, reli - ability, security or operation of computer data, a computer program or a computer. Either of these reports must be given to the ASD (unless another relevant Commonwealth body is specified in the rules). Failure to make a report at all or in writing, or in the approved form, is punishable by 50 penalty units (AUD16,500 fine). The Cyber Security Act Irrespective of whether the cybersecurity incident meets the above significance or relevance thresholds, most critical infrastructure assets (being “a reporting business entity”) have additional reporting obligations under the Cyber Security Act. In summary, there is an obligation to report to the ASD (or another designated Commonwealth agency) where: • there is a cybersecurity incident that has had, is having, or could reasonably be expected to have a (direct or indirect) impact on a reporting business entity; • an entity (the extorting entity) demands a benefit; and
16 CHAMBERS.COM
Powered by FlippingBook