Schedule 1 Security of critical infrastructure Part 1 General amendments (i) used in connection with the provision of an air service; and (ii) owned or operated by a regulated air cargo agent; the regulated air cargo agent; or (c) if the asset is used by an airport operator in connection with the operation of an airport—the airport operator; or (d) if another entity is prescribed by the rules in relation to the asset—that other entity. Critical defence industry asset (22) The responsible entity for a critical defence industry asset is: (a) the entity referred to in paragraph (a) of the definition of critical defence industry asset; or (b) if another entity is prescribed by the rules in relation to the asset—that other entity. Assets prescribed by the rules (23) The responsible entity for an asset prescribed by the rules in relation to the asset for the purposes of paragraph 9(1)(f) is the entity specified in the rules. Assets declared to be a critical infrastructure asset (24) The responsible entity for an asset declared under section 51 to be a critical infrastructure asset is the entity specified in the declaration as the responsible entity for the asset (see subsection 51(2)). 12M Meaning of cyber security incident A cyber security incident is one or more acts, events or circumstances involving any of the following: (a) unauthorised access to: (i) computer data; or (ii) a computer program; (b) unauthorised modification of: (i) computer data; or (ii) a computer program; 50 Security Legislation Amendment (Critical Infrastructure) Act 2021 Authorised Version C2021A00124 No. 124, 2021

Select target paragraph3