CSIRP
What is CSIRP?
Cyber Security Incident Response Plan
A documented plan for responding to a cyber security incident. Under the enhanced cyber security obligations of the SOCI Act, a responsible entity for a System of National Significance can be required to adopt, maintain, review, and exercise one.
What it has to contain
A documented, activatable plan for responding to a cyber security incident: roles, escalation paths, communications, containment and recovery steps, and the criteria for declaring an incident.
Where it is required under the enhanced cyber security obligations, the duty extends beyond writing it to maintaining, reviewing and exercising it. A plan that has never been exercised is a document rather than a capability.
Read more
- Three Things Called "Enhanced" in Your SOCI Obligations
The regime now has three obligation layers and two of them are called enhanced. They apply to different populations, are triggered differently, and demand different things. Which ones you can look up today, and which one arrives privately.
See also
- SoNS Systems of National Significance A subset of critical infrastructure assets privately declared by the Minister under Part 6A of the SOCI Act, on the basis that a disruption would have cascading consequences for other critical infrastructure.
- CIRMP Critical Infrastructure Risk Management Program The risk management program that responsible entities must establish and maintain under the SOCI Act.
O/IT Cyber advises Australian critical infrastructure operators on risk management programs, framework nomination and OT security. Talk to us.