Schedule 1 Security of critical infrastructure
Part 1 General amendments
(d) if the Minister is aware that an entity is the responsible entity
for an asset that is, or is proposed to be, specified in the rules:
(i) give the entity a copy of the draft rules or amendments;
and
(ii) if a submission is received from the entity within the
28-day period mentioned in paragraph (a)—give the
entity a written statement that sets out the Minister’s
response to the submission.
30BC Notification of critical cyber security incidents
(1) If:
(a) an entity is the responsible entity for a critical infrastructure
asset; and
(b) the entity becomes aware that:
(i) a cyber security incident has occurred or is occurring;
and
(ii) the incident has had, or is having, a significant impact
(whether direct or indirect) on the availability of the
asset;
the entity must:
(c) give the relevant Commonwealth body (see section 30BF) a
report that:
(i) is about the incident; and
(ii) includes such information (if any) as is prescribed by
the rules; and
(d) do so as soon as practicable, and in any event within 12
hours, after the entity becomes so aware.
Civil penalty:
50 penalty units.
Form of report etc.
(2) A report under subsection (1) may be given:
(a) orally; or
(b) in writing.
(3) If a report under subsection (1) is given orally, the entity must:
(a) do both of the following:
56
Security Legislation Amendment (Critical Infrastructure) Act 2021
Authorised Version C2021A00124
No. 124, 2021