Schedule 1 Security of critical infrastructure Part 1 General amendments (a) an entity is the responsible entity for a critical infrastructure asset; and (b) the entity becomes aware that: (i) a cyber security incident has occurred, is occurring or is imminent; and (ii) the incident has had, is having, or is likely to have, a relevant impact on the asset; the entity must: (c) give the relevant Commonwealth body (see section 30BF) a report that: (i) is about the incident; and (ii) includes such information (if any) as is prescribed by the rules; and (d) do so as soon as practicable, and in any event within 72 hours, after the entity becomes so aware. Civil penalty: 50 penalty units. Form of report etc. (2) A report under subsection (1) may be given: (a) orally; or (b) in writing. (3) If a report under subsection (1) is given orally, the entity must: (a) do both of the following: (i) make a written record of the report in the approved form; (ii) give a copy of the written record of the report to the relevant Commonwealth body (see section 30BF); and (b) do so within 48 hours after the report is given. Civil penalty: 50 penalty units. (4) If the report is given in writing, the entity must ensure that the report is in the approved form. Civil penalty: 58 50 penalty units. Security Legislation Amendment (Critical Infrastructure) Act 2021 Authorised Version C2021A00124 No. 124, 2021

Select target paragraph3