Australia

Security of Critical Infrastructure Act 2018 (SOCI)

35 controls. 152 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

35 controls 152 frameworks share controls with it Australia verified against its source document

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

There is no implementation kit for this framework yet. The control list and the overlap above are free and complete.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

Every control

CodeControlAlso in
AUSOCI-1Register and Sector Coverage0
AUSOCI-2Critical Infrastructure Risk Management Program (CIRMP)0
AUSOCI-3Cyber Incident Reporting (12/72 hours)0
AUSOCI-4Government Assistance Powers and Direction Authority0
AUSOCI-5Enhanced Cyber Security Obligations and Continuous Improvement0
SOCI-CIRMP-CYBERCIRMP hazard vector: Cyber and information security0
SOCI-CIRMP-PERSONNELCIRMP hazard vector: Personnel7
SOCI-CIRMP-PHYSICALCIRMP hazard vector: Physical security and natural hazards68
SOCI-CIRMP-SUPPLYCIRMP hazard vector: Supply chain67
SOCI-S19Register of Critical Infrastructure Assets0
SOCI-S23Initial obligation to give information0
SOCI-S24Ongoing obligation to update information0
SOCI-S30ACObligation to adopt a CIRMP50
SOCI-S30ADCompliance with CIRMP50
SOCI-S30AEAnnual review of CIRMP50
SOCI-S30BCNotification of critical cyber security incidents (12 hours)30
SOCI-S30BDNotification of other cyber security incidents (72 hours)30
SOCI-S30CBStatutory incident response planning61
SOCI-S30CMCyber security exercises0
SOCI-S30CUVulnerability assessments78
SOCI-S30DBSystem information access0
SOCI-S35ABMinisterial authorisation for government assistance61
SOCI-S35AKInformation gathering directions0
SOCI-S35AQAction directions0
SOCI-SECTOR-COMMSCommunications sector4
SOCI-SECTOR-DATAData storage or processing sector0
SOCI-SECTOR-DEFENCEDefence industry sector0
SOCI-SECTOR-EDUHigher education and research sector0
SOCI-SECTOR-ENERGYEnergy sector4
SOCI-SECTOR-FINANCEFinancial services and markets sector0
SOCI-SECTOR-FOODFood and grocery sector0
SOCI-SECTOR-HEALTHHealthcare and medical sector7
SOCI-SECTOR-SPACESpace technology sector0
SOCI-SECTOR-TRANSPORTTransport sector0
SOCI-SECTOR-WATERWater and sewerage sector0

Tell me when Security of Critical Infrastructure Act 2018 (SOCI) files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What an auditor will ask you to produce

The artefacts named on the failure modes this framework speaks to.

  • remediation tracking
  • Vulnerability assessment of shipboard IT/OT
  • Register of identified vulnerabilities and remediation
  • Review of obsolete/unsupported systems
  • Remediation tracker
  • Mitigation verification
  • legal review documentation
  • outcome tracking
  • ministerial authorisation records
  • request documentation

How programmes fail on this

Failure modes named by this framework and others. Each opens the full record.

What this page is

A control-level reference for Security of Critical Infrastructure Act 2018 (SOCI), drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition