Skip to main content

SP

What is SP?

Security Profile

The target state scale used by the AESCSF, running SP-1, SP-2 and SP-3 for low, moderate and high criticality entities. A Security Profile groups the framework practices into a bundle that an entity of that criticality is expected to meet. The profiles are cumulative, so SP-2 requires SP-1 to be achieved first across every domain. This is a different scale from the Maturity Indicator Level, which measures current maturity per domain rather than the target.

How profiles differ from maturity levels

A Maturity Indicator Level describes current maturity in a single domain. A Security Profile describes the target state for the whole organisation, assigned according to criticality — roughly low, moderate and high for SP-1, SP-2 and SP-3.

Mixing the two produces assessments that measure the wrong thing. An entity can be at MIL-2 in several domains and still be short of SP-1 overall.

Why cumulative matters

SP-2 requires SP-1 to be achieved first, across every domain. Planning that treats SP-2 as a discrete list of extra controls underestimates the work, because any unfinished SP-1 practice has to be closed as well.

Read more

  • AESCSF Security Profile 2: What the Enhanced CIRMP Rules Now Require

    The AESCSF has two scales and people mix them up. Maturity Indicator Levels measure where you are; Security Profiles say where you must be. The Enhanced CIRMP Rules move named energy asset classes to SP-2 by June 2028, and cumulative profiles make that further than it looks.

  • Three Things Called "Enhanced" in Your SOCI Obligations

    The regime now has three obligation layers and two of them are called enhanced. They apply to different populations, are triggered differently, and demand different things. Which ones you can look up today, and which one arrives privately.

See also

Search all glossary terms

O/IT Cyber advises Australian critical infrastructure operators on risk management programs, framework nomination and OT security. Talk to us.