Glossary
Key terms and acronyms in Australian critical infrastructure cyber security.
- AESCSF — Australian Energy Sector Cyber Security Framework
- A cyber security framework maintained by AEMO for the Australian energy sector, adapted from the US DOE C2M2. It scores eleven domains against Maturity Indicator Levels, and bundles practices into three Security Profiles that set a target state by criticality. It is one of the frameworks a responsible entity can nominate under the CIRMP Rules. The Enhanced CIRMP Rules raise the target for named energy asset classes to Security Profile 2, with a deadline of June 2028.
- → AESCSF Security Profile 2: What the Enhanced CIRMP Rules Now Require
- ALARP — As Low As Reasonably Practicable
- A risk management principle originating from safety engineering. A risk is ALARP when the cost of further reduction is grossly disproportionate to the benefit gained. Used extensively in rail and industrial safety, and referenced in the SOCI Act context.
- → Safety-of-Life Thinking vs Cyber Risk Management in Rail
- AS 7770 — Australian Standard 7770
- The Australian standard for rail cyber security. Provides a framework for identifying and managing cyber security risks in rail operations, complementing safety management systems.
- → Safety-of-Life Thinking vs Cyber Risk Management in Rail
- C2M2 — Cybersecurity Capability Maturity Model
- A maturity model published by the US Department of Energy. It groups practices into domains and rates each domain against Maturity Indicator Levels. The AESCSF adapts C2M2 for the Australian energy sector.
- → AESCSF Security Profile 2: What the Enhanced CIRMP Rules Now Require
- CIRMP — Critical Infrastructure Risk Management Program
- The risk management program that responsible entities must establish and maintain under the SOCI Act. The CIRMP Rules 2023 set the baseline requirements. The Enhanced CIRMP Rules, which commenced in June 2026, raise those requirements substantially for a set of named asset classes, with staged compliance deadlines in June 2027 and June 2028. Cyber security framework compliance falls in the later of the two.
- → What "All Hazards" Actually Means in Practice→ What Your TSRMP Needs to Contain for Telco Assets→ The Essential Eight Is Being Retired: What It Means for Your CIRMP Nomination
- CISC — Critical Infrastructure Security Centre
- The Australian Government body (within the Department of Home Affairs) responsible for coordinating critical infrastructure protection. Receives CIRMP annual reports and conducts compliance activities.
- CSIRP — Cyber Security Incident Response Plan
- A documented plan for responding to a cyber security incident. Under the enhanced cyber security obligations of the SOCI Act, a responsible entity for a System of National Significance can be required to adopt, maintain, review, and exercise one.
- → Three Things Called "Enhanced" in Your SOCI Obligations
- E8 — Essential Eight
- Eight mitigation strategies published by the Australian Signals Directorate: application control, patch applications, configure Microsoft Office macro settings, user application hardening, restrict administrative privileges, patch operating systems, multi-factor authentication, and regular backups. Each is rated against Maturity Levels 0 to 3. It is one of the cyber security frameworks a responsible entity can nominate under the CIRMP Rules, which makes it the one most operators choose. Note that ASD has announced it will retire the Essential Eight within about two years, replacing it with a domain-split "Essentials" series that includes a chapter for operational technology. It was designed for corporate Windows fleets, so several of the eight need substantial qualification in a control system environment.
- → The Essential Eight Is Being Retired: What It Means for Your CIRMP Nomination→ Essentials for Operational Technology: What We Know, and Why It Matters
- IEC 62443
- The international series of standards for the security of industrial automation and control systems. It divides an environment into zones and conduits, and it defines security levels for each. Unlike frameworks written for corporate IT, it assumes an environment where availability and safety lead, which makes it the usual reference for the operational technology side of a mixed estate.
- → The Essential Eight Is Being Retired: What It Means for Your CIRMP Nomination
- MIL — Maturity Indicator Level
- The maturity scale used by C2M2 and by the AESCSF, running from MIL-0 to MIL-3. It applies to each domain separately, and a domain reaches a level only when every practice at that level and below is performed. An organisation overall sits at the level of its weakest domain, not at an average. A MIL measures where you are, which is a different question from the Security Profile that says where you are supposed to be.
- → AESCSF Security Profile 2: What the Enhanced CIRMP Rules Now Require→ The Essential Eight Is Being Retired: What It Means for Your CIRMP Nomination
- OT — Operational Technology
- Hardware and software that detects or causes changes through direct monitoring or control of physical devices, processes, and events. Includes SCADA systems, PLCs, DCS, and industrial IoT devices.
- → The Essential Eight Is Being Retired: What It Means for Your CIRMP Nomination→ Essentials for Operational Technology: What We Know, and Why It Matters
- PLC — Programmable Logic Controller
- An industrial digital computer adapted for control of manufacturing processes and other automation tasks. PLCs are the workhorses of OT environments.
- → The Essential Eight Is Being Retired: What It Means for Your CIRMP Nomination→ Essentials for Operational Technology: What We Know, and Why It Matters
- PSO — Positive Security Obligation
- The requirement under Part 2A of the SOCI Act for responsible entities to adopt and maintain a critical infrastructure risk management program. Distinct from the enhanced cyber security framework obligations.
- → Three Things Called "Enhanced" in Your SOCI Obligations
- RERA-CYBER — Rail, Emerging Risk and Assurance - CYBER
- A cyber security themes framework for the Australian rail sector, addressing the intersection of safety management and cyber risk in rail operations.
- → Safety-of-Life Thinking vs Cyber Risk Management in Rail
- Responsible Entity
- Under the SOCI Act, the entity that has operational responsibility for a critical infrastructure asset. The responsible entity bears the obligations for risk management, reporting, and compliance.
- → What "All Hazards" Actually Means in Practice→ Three Things Called "Enhanced" in Your SOCI Obligations
- RFFR — Right Fit For Risk
- The accreditation approach used by Services Australia for providers that handle its data. It asks a provider to run an information security management system aligned to ISO/IEC 27001 and to the ASD Information Security Manual, scaled to the risk the provider carries.
- SCADA — Supervisory Control and Data Acquisition
- A control system architecture used to monitor and control geographically distributed industrial processes. Common in utilities, water treatment, oil and gas, and telecommunications infrastructure.
- → Essentials for Operational Technology: What We Know, and Why It Matters
- SOCI — Security of Critical Infrastructure Act 2018
- Australian federal legislation, often searched for as the Security of Critical Infrastructure Act, that imposes positive security obligations on entities responsible for critical infrastructure assets across 11 sectors. It requires a responsible entity to adopt and maintain a risk management program covering all hazards, to report cyber security incidents, and to submit to government assistance measures. A separate tier of enhanced cyber security obligations applies only to assets declared as Systems of National Significance.
- → What "All Hazards" Actually Means in Practice→ Three Things Called "Enhanced" in Your SOCI Obligations→ What Your TSRMP Needs to Contain for Telco Assets
- SoNS — Systems of National Significance
- A subset of critical infrastructure assets privately declared by the Minister under Part 6A of the SOCI Act, on the basis that a disruption would have cascading consequences for other critical infrastructure. A SoNS declaration triggers the enhanced cyber security obligations, which go beyond the risk management program that every responsible entity must maintain.
- → Three Things Called "Enhanced" in Your SOCI Obligations
- SP — Security Profile
- The target state scale used by the AESCSF, running SP-1, SP-2 and SP-3 for low, moderate and high criticality entities. A Security Profile groups the framework practices into a bundle that an entity of that criticality is expected to meet. The profiles are cumulative, so SP-2 requires SP-1 to be achieved first across every domain. This is a different scale from the Maturity Indicator Level, which measures current maturity per domain rather than the target.
- → AESCSF Security Profile 2: What the Enhanced CIRMP Rules Now Require→ Three Things Called "Enhanced" in Your SOCI Obligations
- TSRMP — Telecommunications Security Risk Management Program
- A specialised risk management program required under the TSRMP Rules 2025 for responsible entities operating critical telecommunications assets. Adds requirements beyond the general CIRMP Rules.
- → What Your TSRMP Needs to Contain for Telco Assets