What is Responsible Entity?
Under the SOCI Act, the entity that has operational responsibility for a critical infrastructure asset. The responsible entity bears the obligations for risk management, reporting, and compliance.
Identifying the responsible entity
It is the entity with operational responsibility for the asset. That is not always the owner, and in a group structure it is frequently not the parent company. Getting this wrong means the obligations sit with an entity that is not managing them.
Where an asset is operated under contract, the question of who holds operational responsibility needs to be answered explicitly rather than assumed from the ownership chain.
Read more
- Three Things Called "Enhanced" in Your SOCI Obligations
The regime now has three obligation layers and two of them are called enhanced. They apply to different populations, are triggered differently, and demand different things. Which ones you can look up today, and which one arrives privately.
See also
- SOCI Security of Critical Infrastructure Act 2018 Australian federal legislation, often searched for as the Security of Critical Infrastructure Act, that imposes positive security obligations on entities responsible for critical infrastructure assets across 11 sectors.
- CIRMP Critical Infrastructure Risk Management Program The risk management program that responsible entities must establish and maintain under the SOCI Act.
- PSO Positive Security Obligation The requirement under Part 2A of the SOCI Act for responsible entities to adopt and maintain a critical infrastructure risk management program.
O/IT Cyber advises Australian critical infrastructure operators on risk management programs, framework nomination and OT security. Talk to us.