What is the purpose of Australia’s Security of Critical Infrastructure (SOCI) Act 2018?
The Security of Critical Infrastructure (SOCI) Act 2018 establishes the framework for managing security risks to Australia’s critical infrastructure. In fact, it sits at the center of Australia’s approach to protecting essential services from cyber, physical, personnel, and supply chain threats. Moreover, the Cyber and Infrastructure Security Centre (CISC) administers the Act within the Department of Home Affairs.
In practice, the Act pursues four main objectives:
- Improve transparency around ownership and operational control of critical infrastructure
- Facilitate government and industry cooperation in identifying and managing risks
- Require responsible entities to proactively identify, assess, and manage risks
- Enable government intervention when owners cannot adequately respond to serious incidents
What assets are considered critical infrastructure under the SOCI Act?
The SOCI Act covers 11 sectors of the Australian economy. Moreover, the Minister can privately declare specific assets as critical infrastructure where national security is at risk. In practice, the sectors span essential services, financial systems, food supply, and national defense capabilities.
Specifically, the 11 sectors covered by the Act are:
- Communications: telecommunications, broadcasting, and domain name system assets
- Data storage and processing, including cloud services and data centers
- Financial services: banking, superannuation, insurance, and financial markets
- Water and sewerage
- Energy: electricity, gas, liquid fuel, and energy market operators
- Health care and medical
- Higher education and research
- Food and grocery
- Transport: ports, freight, public transport, and aviation
- Space technology
- Defense industry
What are the main obligations for responsible entities of critical infrastructure assets?
Responsible entities must meet three core obligations. First, they provide operational and ownership information for the non-public Register of Critical Infrastructure Assets. In addition, they keep that information current as ownership or control changes.
Second, they adopt and maintain a Critical Infrastructure Risk Management Program (CIRMP). Specifically, the CIRMP covers cyber and information security, personnel, physical, and supply chain hazards. Finally, they regularly review the program, keep it current, and submit annual compliance reports to the Secretary.
What are the cyber incident reporting requirements under the SOCI Act?
Responsible entities must report cyber security incidents to the Australian Signals Directorate (ASD). In practice, reporting typically goes through the Australian Cyber Security Centre (ACSC) ReportCyber portal. However, the reporting timeframe depends on the severity of the incident:
- Critical cyber security incidents: when an incident has a significant impact on the availability of an asset, report within 12 hours
- Other cyber security incidents: when an incident has a relevant impact on the asset, report within 72 hours
- Oral reports: if you notify by phone to meet the 12-hour window, a written record must follow within a specified timeframe
What government intervention powers exist for serious incidents under the SOCI Act?
The SOCI Act grants the Australian Government significant intervention powers during serious incidents. Specifically, these powers apply when an incident poses a material risk to social or economic stability, defense, or national security. However, the government has signaled it will use them sparingly, as they sit at the top of a graduated escalation ladder.
In practice, three levels of intervention exist:
- Information-gathering direction: the Minister compels the entity to provide information needed to understand the incident and its impact
- Action direction: the Minister directs the entity to take specific steps, or refrain from specific actions, to respond to the incident
- Intervention request: when the entity is unwilling or unable to respond adequately to a cyber incident, the Minister can authorize the ASD to directly intervene, including accessing, modifying, or removing computers and data connected to the asset