Schedule 1 Security of critical infrastructure
Part 1 General amendments
(a) an entity is the responsible entity for a critical infrastructure
asset; and
(b) the entity becomes aware that:
(i) a cyber security incident has occurred, is occurring or is
imminent; and
(ii) the incident has had, is having, or is likely to have, a
relevant impact on the asset;
the entity must:
(c) give the relevant Commonwealth body (see section 30BF) a
report that:
(i) is about the incident; and
(ii) includes such information (if any) as is prescribed by
the rules; and
(d) do so as soon as practicable, and in any event within 72
hours, after the entity becomes so aware.
Civil penalty:
50 penalty units.
Form of report etc.
(2) A report under subsection (1) may be given:
(a) orally; or
(b) in writing.
(3) If a report under subsection (1) is given orally, the entity must:
(a) do both of the following:
(i) make a written record of the report in the approved
form;
(ii) give a copy of the written record of the report to the
relevant Commonwealth body (see section 30BF); and
(b) do so within 48 hours after the report is given.
Civil penalty:
50 penalty units.
(4) If the report is given in writing, the entity must ensure that the
report is in the approved form.
Civil penalty:
58
50 penalty units.
Security Legislation Amendment (Critical Infrastructure) Act 2021
Authorised Version C2021A00124
No. 124, 2021