Schedule 1 Security of critical infrastructure
Part 1 General amendments
(a) a person causes any access, modification or impairment of a
kind mentioned in that subsection; and
(b) the person does so:
(i) under a warrant issued under a law of the
Commonwealth, a State or a Territory; or
(ii) under an emergency authorisation given to the person
under Part 3 of the Surveillance Devices Act 2004 or
under a law of a State or Territory that makes provision
to similar effect; or
(iii) under a tracking device authorisation given to the
person under section 39 of the Surveillance Devices Act
2004; or
(iv) in accordance with a technical assistance request; or
(v) in compliance with a technical assistance notice; or
(vi) in compliance with a technical capability notice;
the person is entitled to cause that access, modification or
impairment.
12P Examples of responding to a cyber security incident
The following are examples of responding to a cyber security
incident:
(a) if the incident is imminent—preventing the incident;
(b) mitigating a relevant impact of the incident on:
(i) a critical infrastructure asset; or
(ii) a critical infrastructure sector asset;
(c) if a critical infrastructure asset or a critical infrastructure
sector asset has been, or is being, affected by the incident—
restoring the functionality of the asset.
33 Paragraph 13(1)(b)
Omit “that is a reporting entity for,”, insert “, so far as the entity is the
responsible entity for, a reporting entity for, a relevant entity for,”.
34 At the end of paragraph 13(1)(b)
Add:
or (iv) used in the course of, or in relation to, banking to which
paragraph 51(xiii) of the Constitution applies; or
52
Security Legislation Amendment (Critical Infrastructure) Act 2021
Authorised Version C2021A00124
No. 124, 2021