SoNS
What is SoNS?
Systems of National Significance
A subset of critical infrastructure assets privately declared by the Minister under Part 6A of the SOCI Act, on the basis that a disruption would have cascading consequences for other critical infrastructure. A SoNS declaration triggers the enhanced cyber security obligations, which go beyond the risk management program that every responsible entity must maintain.
How an asset becomes a SoNS
The Minister declares it, privately, on the basis that disruption to the asset would have cascading consequences for other critical infrastructure. Being large, well known, or important to your sector does not by itself lead to a declaration.
Because declarations are private, the absence of one is quiet. If nobody has told you, you are not carrying these obligations.
What a declaration switches on
The enhanced cyber security obligations are operational rather than programmatic: adopting, maintaining, reviewing and exercising a cyber security incident response plan, undertaking vulnerability assessments, and providing system information to government.
They are applied selectively, so a declaration does not automatically activate every obligation at once.
Not the same as the enhanced CIRMP requirements
Two different things carry the word "enhanced". The enhanced CIRMP requirements attach to nine named asset classes and are knowable today. The enhanced cyber security obligations attach only to a System of National Significance and arrive by private declaration. Conflating them is a common and consequential error.
Read more
- Three Things Called "Enhanced" in Your SOCI Obligations
The regime now has three obligation layers and two of them are called enhanced. They apply to different populations, are triggered differently, and demand different things. Which ones you can look up today, and which one arrives privately.
See also
- CSIRP Cyber Security Incident Response Plan A documented plan for responding to a cyber security incident.
- PSO Positive Security Obligation The requirement under Part 2A of the SOCI Act for responsible entities to adopt and maintain a critical infrastructure risk management program.
- SOCI Security of Critical Infrastructure Act 2018 Australian federal legislation, often searched for as the Security of Critical Infrastructure Act, that imposes positive security obligations on entities responsible for critical infrastructure assets across 11 sectors.
O/IT Cyber advises Australian critical infrastructure operators on risk management programs, framework nomination and OT security. Talk to us.