AUCSA-CIRB-EST | Establishment, functions and powers of the Cyber Incident Review Board | 0 |
AUCSA-CIRB-INFO | Compulsory information production and protection of review information | 0 |
AUCSA-CIRB-REVIEW | Conduct of no-fault post-incident reviews | 1 |
AUCSA-CIRB-RPT | Board reports and recommendations | 0 |
AUCSA-INT-SOCI | Interaction with the SOCI Act and other laws | 1 |
AUCSA-IOT-COC | Statement of compliance for connectable products | 0 |
AUCSA-IOT-ENF | Compliance, stop and recall notices for smart devices | 0 |
AUCSA-IOT-STD | Security standards for relevant connectable products | 0 |
AUCSA-LU-INTERACT | Interaction with other reporting requirements | 1 |
AUCSA-LU-LIMITED | Limited use obligation on shared incident information | 0 |
AUCSA-LU-SHARE | Voluntary information sharing with the National Cyber Security Coordinator | 0 |
AUCSA-P1-OBJ | Objects and application of the Act | 0 |
AUCSA-RAN-CONTENT | Content of a ransomware payment report | 0 |
AUCSA-RAN-PROT | Limited use and protection of ransomware report information | 0 |
AUCSA-RAN-RPT | Ransomware and cyber-extortion payment reporting obligation | 1 |
AUCSA-REG-MON | Monitoring, investigation and infringement notices | 0 |
AUCSA-REG-PEN | Civil penalty provisions and enforceable undertakings | 0 |
13 | s 13 Application: relevant connectable products manufactured or supplied new after commencement | 0 |
15(1)-(2) | s 15(1)-(2) Manufacturer must manufacture to the security standard and meet its other obligations | 0 |
15(3)-(4) | s 15(3)-(4) Supplier must not supply a non-compliant product and must meet the standard's supplier obligations | 0 |
16(1)-(2) | s 16(1)-(2) Manufacturer must provide a statement of compliance and retain it | 0 |
16(3)-(4) | s 16(3)-(4) Supplier must supply the product with a statement of compliance and retain it | 0 |
16(5) | s 16(5) Statement of compliance contents: product, manufacturer and representatives, declarations, support period, signatory | 0 |
17 | s 17 Comply with a compliance notice within the specified period | 0 |
18 | s 18 Comply with a stop notice after a failed compliance notice | 0 |
19 | s 19 Comply with a recall notice: stop acquisition and supply, arrange return | 0 |
22 | s 22 Right to internal review of a compliance, stop, recall or variation notice within 30 days | 0 |
23 | s 23 Provide the product and statement of compliance for independent examination on request | 0 |
26 | s 26 Determine whether the entity is a reporting business entity: AUD 3 million turnover or a SOCI Part 2B responsible entity | 0 |
27(1) | s 27(1) Report a ransomware payment to the designated Commonwealth body within 72 hours | 0 |
27(2) | s 27(2) Ransomware payment report contents: entity details, the incident and its impact, the demand, the payment, the communications | 0 |
29 | s 29 Designated Commonwealth body may use a ransomware payment report only for permitted purposes and not to enforce other laws against the reporter | 0 |
30 | s 30 Secondary recipients of report information: permitted purposes only, civil penalty of 60 penalty units | 0 |
34-37 | Significant cyber security incident, voluntary provision to the Coordinator and the Coordinator's role (ss 33 to 37) | 0 |
35 | s 35 Impacted entity may voluntarily provide information about a significant incident to the Coordinator | 0 |
38 | s 38 Coordinator may use information about a significant incident only to assist the entity or for a permitted cyber security purpose | 0 |
40 | s 40 Secondary recipients of Coordinator information: permitted purposes only, civil penalty of 60 penalty units | 0 |
41-43 | Part 4 protections: privilege, non-admissibility and the Coordinator not compellable (ss 41 to 43) | 0 |
46 | s 46 Reviews only on written referral, against the criteria, after the incident and immediate response have ended, under Minister-approved terms of reference | 0 |
49 | s 49 Produce documents to the Board within at least 14 days of a notice, civil penalty of 60 penalty units | 0 |
51 | s 51 Prepare a draft review report, give it to the Minister and invite submissions within a reasonable period | 0 |
52 | s 52 Final review report: findings, evidence summary, recommendations with reasons, no blame, liability or identification, published | 0 |
53 | s 53 Redact sensitive review information and prepare a protected review report for the Minister and Prime Minister | 0 |
55 | s 55 Board may use information it receives only for review functions and permitted purposes, not to enforce other laws against the provider | 0 |
56 | s 56 Secondary recipients of review information: permitted purposes only, civil penalty of 60 penalty units | 0 |
57-58 | Part 5 protections: privilege preserved and non-admissibility of information given to the Board (ss 57 and 58) | 0 |
59 | s 59 Do not disclose or use a draft review report, civil penalty of 60 penalty units | 0 |
60-63 | The Cyber Incident Review Board: establishment, constitution, functions and independence (ss 60 to 63) | 0 |
76 | s 76 Annual report to include the Board's reviews, discontinuances, refused terms of reference and Expert Panel numbers | 0 |
ACT | Cyber Security Act 2024 (Cth), No. 98 of 2024: what it is, what is held and its status | 0 |
P1 | Part 1: definitions, cyber security incident, permitted cyber security purpose, disclosure to State bodies (ss 1 to 11) | 0 |
P2 | Part 2: Security standards for smart devices (relevant connectable products) | 0 |
P3 | Part 3: Ransomware payment reporting | 0 |
P3-PROT | Part 3 protections: legal professional privilege preserved and non-admissibility against the reporter (ss 31 and 32) | 0 |
P4 | Part 4: Coordination of significant cyber security incidents (National Cyber Security Coordinator) | 0 |
P5 | Part 5: Cyber Incident Review Board | 0 |
P6 | Part 6: regulatory powers applied from the Regulatory Powers (Standard Provisions) Act 2014 (ss 78 to 83) | 0 |
P7 | Part 7: non-legal persons, delegation, rules with 28-day consultation, and PJCIS review after 1 December 2027 (ss 84 to 88) | 0 |
Sch1-2 | s Sch1-2 Security standard: no universal default passwords | 0 |
Sch1-3 | s Sch1-3 Security standard: publish how to report security issues, with acknowledgement and status updates | 0 |
Sch1-4 | s Sch1-4 Security standard: publish the defined support period for security updates and never shorten it | 0 |