SP
What is SP?
Security Profile
The target state scale used by the AESCSF, running SP-1, SP-2 and SP-3 for low, moderate and high criticality entities. A Security Profile groups the framework practices into a bundle that an entity of that criticality is expected to meet. The profiles are cumulative, so SP-2 requires SP-1 to be achieved first across every domain. This is a different scale from the Maturity Indicator Level, which measures current maturity per domain rather than the target.
How profiles differ from maturity levels
A Maturity Indicator Level describes current maturity in a single domain. A Security Profile describes the target state for the whole organisation, assigned according to criticality — roughly low, moderate and high for SP-1, SP-2 and SP-3.
Mixing the two produces assessments that measure the wrong thing. An entity can be at MIL-2 in several domains and still be short of SP-1 overall.
Why cumulative matters
SP-2 requires SP-1 to be achieved first, across every domain. Planning that treats SP-2 as a discrete list of extra controls underestimates the work, because any unfinished SP-1 practice has to be closed as well.
Read more
- AESCSF Security Profile 2: What the Enhanced CIRMP Rules Now Require
The AESCSF has two scales and people mix them up. Maturity Indicator Levels measure where you are; Security Profiles say where you must be. The Enhanced CIRMP Rules move named energy asset classes to SP-2 by June 2028, and cumulative profiles make that further than it looks.
- Three Things Called "Enhanced" in Your SOCI Obligations
The regime now has three obligation layers and two of them are called enhanced. They apply to different populations, are triggered differently, and demand different things. Which ones you can look up today, and which one arrives privately.
See also
- AESCSF Australian Energy Sector Cyber Security Framework A cyber security framework maintained by AEMO for the Australian energy sector, adapted from the US DOE C2M2.
- MIL Maturity Indicator Level The maturity scale used by C2M2 and by the AESCSF, running from MIL-0 to MIL-3.
- C2M2 Cybersecurity Capability Maturity Model A maturity model published by the US Department of Energy.
O/IT Cyber advises Australian critical infrastructure operators on risk management programs, framework nomination and OT security. Talk to us.