CIRMP-GOV-ADOPT | Adoption and board approval of the CIRMP | 0 |
CIRMP-GOV-REPORT | Annual report to the Commonwealth regulator | 1 |
CIRMP-GOV-REVIEW | Annual review and currency of the CIRMP | 0 |
CIRMP-s10 | Supply chain hazard management | 1 |
CIRMP-s11 | Physical security and natural hazard management | 0 |
CIRMP-s5 | Application to designated critical infrastructure asset classes | 0 |
CIRMP-s6 | Identification of material risks | 2 |
CIRMP-s7 | General requirement - minimise, eliminate and mitigate all hazards | 1 |
CIRMP-s8 | Cyber and information security hazard management | 2 |
CIRMP-s8-FW | Adoption of a recognised cyber security framework | 2 |
CIRMP-s9 | Personnel hazard management | 0 |
10 | s 10 Supply chain hazards: six material risks and impact mitigation, major suppliers listed | 0 |
10A(2) | s 10A(2) Supply chain mapping: major suppliers and critical components, risks to critical components and business critical data, maximum acceptable outage, mitigation | 0 |
10A(4) | s 10A(4) Vendor assessment of each existing or proposed major supplier: FOCI legal exposure, sanctions, access and control, combined risk against the MAO, steps | 0 |
11 | s 11 Physical security and natural hazards: identify physical critical components, control access, respond to intrusions, test the arrangements | 0 |
11A(1) | s 11A(1) Central management of physical security and natural hazards, with the physical consequences of every hazard family outlined | 0 |
11A(3) | s 11A(3) Enhanced physical controls: access controls for workers, visitors and the public, continuous surveillance and alarms, business and out-of-hours measures, deter-detect-dela | 0 |
12 | Transitional: assets declared under s 51 before 10 June 2026 (s 12) | 0 |
3-5 | Definitions, the relevant Commonwealth regulator and the designated hospitals (ss 3, 5, Schedule 1) | 0 |
4 | s 4 Which assets the Rules bind: thirteen classes, six-month grace, and the baseline requirements | 0 |
4(4) | s 4(4) Compliance through another Part 2A instrument for an entity holding assets under two instruments | 0 |
4A | s 4A Enhanced requirements: the nine asset classes, precedence over baseline, and the 12- and 24-month grace periods | 0 |
6 | s 6 Material risks the program must address | 0 |
6A | s 6A Additional material risks for enhanced assets: national significance, FOCI, offshore and remote access | 0 |
7(1) | s 7(1) General all-hazards process: operational context, material risks, minimise and mitigate, review and currency | 0 |
7(2) | s 7(2) CIRMP content the board must have regard to: context outcome, interdependencies, responsible positions, methodology, review circumstances | 0 |
8(2) | s 8(2) Cyber and information security hazards: minimise the material risk and mitigate the impact | 0 |
8(3) | s 8(3) Adopt one of five cyber frameworks, or an equivalent, within 12 months of the grace period | 0 |
8A(2) | s 8A(2) Enhanced cyber material risks: patching, legacy systems, and advanced, novel or emerging technology | 0 |
8A(3) | s 8A(3) Enhanced cyber framework: 27001:2023, Essential Eight level two, CSF 2.0, C2M2 v2.1 MIL2 or AESCSF 2023 SP2, or an equivalent | 0 |
8B | s 8B Credential compromise hazards: phishing-resistant multi-factor authentication where the chosen framework does not require it, with central logging | 0 |
8C | s 8C Lateral movement hazards: inventory of critical systems, recovery and continued availability, and network segregation with a three-month independence standard | 0 |
9(1) | s 9(1) Personnel hazards: identify critical workers, permit access only on suitability, address malicious, negligent and off-boarding risks | 0 |
9(2) | s 9(2) AusCheck background checks where the CIRMP uses them: criminal history criteria, dual identity verification, notification, Secretary's advice | 0 |
9A(2) | s 9A(2) Enhanced personnel access management: unauthorised or unsupervised access, credential misuse, non-critical-worker access, joiners and leavers | 0 |
9A(3) | s 9A(3) Enhanced suitability: AusCheck plus the entity's assessment, or a security clearance; documented risk where a worker cannot meet it; proactive monitoring | 0 |
9A(5) | s 9A(5) Enhanced suitability upkeep: AusCheck at least every five years for ongoing access, and clearance revalidation before lapse | 0 |
APP | Part 1: Application, asset classes, enhanced classes and grace periods | 0 |
BASE | Part 2 baseline requirements: material risks and the four hazard families (all CIRMP Rule assets) | 0 |
ENH | Part 2 enhanced requirements: additional material risks, cyber, credential, lateral movement, personnel, supply chain and physical (nine asset classes) | 0 |
RULES | The CIRMP Rules (LIN 23/006) 2023 as amended to 10 June 2026: what they are, what is held and their status | 0 |