Preliminary Part 1 Preliminary Division 1 Section 4 (a) improving the transparency of the ownership and operational control of critical infrastructure in Australia in order to better understand those risks; and (b) facilitating cooperation and collaboration between all levels of government, and regulators, owners and operators of critical infrastructure, in order to identify and manage those risks. 4 Simplified outline of this Act This Act creates a framework for managing risks to national security relating to critical infrastructure. The framework consists of the following: (a) the keeping of a register of information in relation to critical infrastructure assets (the register will not be made public); (b) requiring certain entities relating to a critical infrastructure asset to provide information in relation to the asset, and to notify if certain events occur in relation to the asset; (c) allowing the Minister to require certain entities relating to a critical infrastructure asset to do, or refrain from doing, an act or thing if the Minister is satisfied that there is a risk of an act or omission that would be prejudicial to security; (d) allowing the Secretary to require certain entities relating to a critical infrastructure asset to provide certain information or documents; (e) allowing the Secretary to undertake an assessment of a critical infrastructure asset to determine if there is a risk to national security relating to the asset. Certain information obtained under, or relating to the operation of, this Act is protected information. There are restrictions on when a person may make a record of, use or disclose protected information. No. 29, 2018 Security of Critical Infrastructure Act 2018 Authorised Version C2018A00029 3

Select target paragraph3