Security of critical infrastructure Schedule 1 General amendments Part 1 (c) unauthorised impairment of electronic communication to or from a computer; (d) unauthorised impairment of the availability, reliability, security or operation of: (i) a computer; or (ii) computer data; or (iii) a computer program. 12N Meaning of unauthorised access, modification or impairment (1) For the purposes of this Act: (a) access to: (i) computer data; or (ii) a computer program; or (b) modification of: (i) computer data; or (ii) a computer program; or (c) the impairment of electronic communication to or from a computer; or (d) the impairment of the availability, reliability, security or operation of: (i) a computer; or (ii) computer data; or (iii) a computer program; by a person is unauthorised if the person is not entitled to cause that access, modification or impairment. (1A) The following is an example of a situation where a person is not entitled to cause access, modification or impairment of a kind mentioned in subsection (1): a person who is an employee or agent of the responsible entity for an asset would exceed the person’s authority as such an employee or agent in causing such access, modification or impairment in relation to the asset. (2) For the purposes of subsection (1), it is immaterial whether the person can be identified. (3) For the purposes of subsection (1), if: No. 124, 2021 Security Legislation Amendment (Critical Infrastructure) Act 2021 Authorised Version C2021A00124 51

Select target paragraph3