Skip to main content

PSO

What is PSO?

Positive Security Obligation

The requirement under Part 2A of the SOCI Act for responsible entities to adopt and maintain a critical infrastructure risk management program. Distinct from the enhanced cyber security framework obligations.

What it obliges you to do

Adopt and maintain a critical infrastructure risk management program, comply with it, review it regularly, and submit an annual report. The program must cover all hazards.

It is a standing obligation that follows from operating a critical infrastructure asset. No notice is issued and no declaration is required.

How it relates to the other tiers

The positive security obligation is the baseline. The Enhanced CIRMP Rules raise the standard of that same program for nine named asset classes. The enhanced cyber security obligations are a separate regime for Systems of National Significance, and doing the baseline well does not produce them as a by-product.

Read more

  • Three Things Called "Enhanced" in Your SOCI Obligations

    The regime now has three obligation layers and two of them are called enhanced. They apply to different populations, are triggered differently, and demand different things. Which ones you can look up today, and which one arrives privately.

See also

Search all glossary terms

O/IT Cyber advises Australian critical infrastructure operators on risk management programs, framework nomination and OT security. Talk to us.