Australia (Commonwealth)

Critical Infrastructure Risk Management Program (CIRMP) Rules 2023

41 controls. 4 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

41 controls 4 frameworks share controls with it Australia (Commonwealth) verified against its source document

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

There is no implementation kit for this framework yet. The control list and the overlap above are free and complete.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

Every control

CodeControlAlso in
CIRMP-GOV-ADOPTAdoption and board approval of the CIRMP0
CIRMP-GOV-REPORTAnnual report to the Commonwealth regulator1
CIRMP-GOV-REVIEWAnnual review and currency of the CIRMP0
CIRMP-s10Supply chain hazard management1
CIRMP-s11Physical security and natural hazard management0
CIRMP-s5Application to designated critical infrastructure asset classes0
CIRMP-s6Identification of material risks2
CIRMP-s7General requirement - minimise, eliminate and mitigate all hazards1
CIRMP-s8Cyber and information security hazard management2
CIRMP-s8-FWAdoption of a recognised cyber security framework2
CIRMP-s9Personnel hazard management0
10s 10 Supply chain hazards: six material risks and impact mitigation, major suppliers listed0
10A(2)s 10A(2) Supply chain mapping: major suppliers and critical components, risks to critical components and business critical data, maximum acceptable outage, mitigation0
10A(4)s 10A(4) Vendor assessment of each existing or proposed major supplier: FOCI legal exposure, sanctions, access and control, combined risk against the MAO, steps0
11s 11 Physical security and natural hazards: identify physical critical components, control access, respond to intrusions, test the arrangements0
11A(1)s 11A(1) Central management of physical security and natural hazards, with the physical consequences of every hazard family outlined0
11A(3)s 11A(3) Enhanced physical controls: access controls for workers, visitors and the public, continuous surveillance and alarms, business and out-of-hours measures, deter-detect-dela0
12Transitional: assets declared under s 51 before 10 June 2026 (s 12)0
3-5Definitions, the relevant Commonwealth regulator and the designated hospitals (ss 3, 5, Schedule 1)0
4s 4 Which assets the Rules bind: thirteen classes, six-month grace, and the baseline requirements0
4(4)s 4(4) Compliance through another Part 2A instrument for an entity holding assets under two instruments0
4As 4A Enhanced requirements: the nine asset classes, precedence over baseline, and the 12- and 24-month grace periods0
6s 6 Material risks the program must address0
6As 6A Additional material risks for enhanced assets: national significance, FOCI, offshore and remote access0
7(1)s 7(1) General all-hazards process: operational context, material risks, minimise and mitigate, review and currency0
7(2)s 7(2) CIRMP content the board must have regard to: context outcome, interdependencies, responsible positions, methodology, review circumstances0
8(2)s 8(2) Cyber and information security hazards: minimise the material risk and mitigate the impact0
8(3)s 8(3) Adopt one of five cyber frameworks, or an equivalent, within 12 months of the grace period0
8A(2)s 8A(2) Enhanced cyber material risks: patching, legacy systems, and advanced, novel or emerging technology0
8A(3)s 8A(3) Enhanced cyber framework: 27001:2023, Essential Eight level two, CSF 2.0, C2M2 v2.1 MIL2 or AESCSF 2023 SP2, or an equivalent0
8Bs 8B Credential compromise hazards: phishing-resistant multi-factor authentication where the chosen framework does not require it, with central logging0
8Cs 8C Lateral movement hazards: inventory of critical systems, recovery and continued availability, and network segregation with a three-month independence standard0
9(1)s 9(1) Personnel hazards: identify critical workers, permit access only on suitability, address malicious, negligent and off-boarding risks0
9(2)s 9(2) AusCheck background checks where the CIRMP uses them: criminal history criteria, dual identity verification, notification, Secretary's advice0
9A(2)s 9A(2) Enhanced personnel access management: unauthorised or unsupervised access, credential misuse, non-critical-worker access, joiners and leavers0
9A(3)s 9A(3) Enhanced suitability: AusCheck plus the entity's assessment, or a security clearance; documented risk where a worker cannot meet it; proactive monitoring0
9A(5)s 9A(5) Enhanced suitability upkeep: AusCheck at least every five years for ongoing access, and clearance revalidation before lapse0
APPPart 1: Application, asset classes, enhanced classes and grace periods0
BASEPart 2 baseline requirements: material risks and the four hazard families (all CIRMP Rule assets)0
ENHPart 2 enhanced requirements: additional material risks, cyber, credential, lateral movement, personnel, supply chain and physical (nine asset classes)0
RULESThe CIRMP Rules (LIN 23/006) 2023 as amended to 10 June 2026: what they are, what is held and their status0

Tell me when Critical Infrastructure Risk Management Program (CIRMP) Rules 2023 files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What this page is

A control-level reference for Critical Infrastructure Risk Management Program (CIRMP) Rules 2023, drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition