AESCSF
What is AESCSF?
Australian Energy Sector Cyber Security Framework
A cyber security framework maintained by AEMO for the Australian energy sector, adapted from the US DOE C2M2. It scores eleven domains against Maturity Indicator Levels, and bundles practices into three Security Profiles that set a target state by criticality. It is one of the frameworks a responsible entity can nominate under the CIRMP Rules. The Enhanced CIRMP Rules raise the target for named energy asset classes to Security Profile 2, with a deadline of June 2028.
How the framework is structured
The AESCSF scores eleven domains against Maturity Indicator Levels running MIL-0 to MIL-3. It is adapted from the US Department of Energy C2M2, with Australian additions.
Separately, practices are bundled into three Security Profiles — SP-1, SP-2 and SP-3 — which set a target state according to how critical the entity is to the sector. MILs measure where you are. Security Profiles say where you are supposed to be.
What the Enhanced CIRMP Rules changed
Energy entities nominating the AESCSF were previously working towards Security Profile 1. For the named asset classes the Enhanced CIRMP Rules raise that to Security Profile 2, with a deadline of June 2028.
Security Profiles are cumulative, so SP-2 requires SP-1 to be achieved in full across every domain first. The work is not a short list of additional items.
Where assessments usually stall
Asset inventory gates almost everything downstream and is genuinely hard in an estate assembled over decades. Third-party and supply chain visibility is usually worse than assumed. Situational awareness needs instrumentation that older networks never had.
Because an overall position is set by the weakest domain rather than an average, one neglected domain holds the whole assessment down.
Read more
- AESCSF Security Profile 2: What the Enhanced CIRMP Rules Now Require
The AESCSF has two scales and people mix them up. Maturity Indicator Levels measure where you are; Security Profiles say where you must be. The Enhanced CIRMP Rules move named energy asset classes to SP-2 by June 2028, and cumulative profiles make that further than it looks.
See also
- SP Security Profile The target state scale used by the AESCSF, running SP-1, SP-2 and SP-3 for low, moderate and high criticality entities.
- MIL Maturity Indicator Level The maturity scale used by C2M2 and by the AESCSF, running from MIL-0 to MIL-3.
- C2M2 Cybersecurity Capability Maturity Model A maturity model published by the US Department of Energy.
- CIRMP Critical Infrastructure Risk Management Program The risk management program that responsible entities must establish and maintain under the SOCI Act.
O/IT Cyber advises Australian critical infrastructure operators on risk management programs, framework nomination and OT security. Talk to us.