Schedule 1 Security of critical infrastructure Part 1 General amendments (3) If: (a) an entity (the first entity) is the responsible entity for a critical infrastructure asset; and (b) the first entity becomes aware that a data storage or processing service: (i) is provided by another entity on a commercial basis to the first entity; and (ii) relates to business critical data; the first entity must: (c) take reasonable steps to inform that other entity that the first entity has become aware that the data storage or processing service: (i) is provided by the other entity on a commercial basis to the first entity; and (ii) relates to business critical data; and (d) do so as soon as practicable after becoming so aware. Civil penalty for contravention of this subsection: units. 50 penalty 12G Meaning of critical banking asset (1) An asset is a critical banking asset if it is any of the following assets: (a) an asset where the following conditions are satisfied: (i) the asset is owned or operated by an authorised deposit-taking institution; (ii) the authorised deposit-taking institution is an authorised deposit-taking institution that, in accordance with subsection (2), is critical to the security and reliability of the financial services and markets sector; (iii) the asset is used in connection with the carrying on of banking business; (b) an asset where the following conditions are satisfied: (i) the asset is owned or operated by a body corporate that is a related body corporate of an authorised deposit-taking institution; (ii) the body corporate is a body corporate that, in accordance with subsection (3), is critical to the security 38 Security Legislation Amendment (Critical Infrastructure) Act 2021 Authorised Version C2021A00124 No. 124, 2021

Select target paragraph3