Schedule 1 Security of critical infrastructure Part 1 General amendments (3) The rules may provide that, if an asset becomes a critical infrastructure asset, this Part does not apply to the asset during the period: (a) beginning when the asset became a critical infrastructure asset; and (b) ending at a time ascertained in accordance with the rules. 18AA Consultation—rules Scope (1) This section applies to rules made for the purposes of section 18A. Consultation (2) Before making or amending the rules, the Minister must: (a) cause to be published on the Department’s website a notice: (i) setting out the draft rules or amendments; and (ii) inviting persons to make submissions to the Minister about the draft rules or amendments within 28 days after the notice is published; and (b) give a copy of the notice to each First Minister; and (c) consider any submissions received within the 28-day period mentioned in paragraph (a). 39 After Part 2 Insert: Part 2B—Notification of cyber security incidents 30BA Simplified outline of this Part If a cyber security incident has a relevant impact on a critical infrastructure asset, the responsible entity for the asset may be required to give a relevant Commonwealth body a report about the incident. Note: 54 See also section 30BB (application of this Part). Security Legislation Amendment (Critical Infrastructure) Act 2021 Authorised Version C2021A00124 No. 124, 2021

Select target paragraph3