TSRMP
What is TSRMP?
Telecommunications Security Risk Management Program
A specialised risk management program required under the TSRMP Rules 2025 for responsible entities operating critical telecommunications assets. Adds requirements beyond the general CIRMP Rules.
How it differs from a CIRMP
The TSRMP Rules largely mirror the CIRMP Rules but add requirements reflecting the risk profile of telecommunications infrastructure. Satisfying the general CIRMP requirements alone is not sufficient for a telecommunications asset.
An entity operating assets across multiple classes can maintain a single program covering all of them, provided it meets the TSRMP requirements for the telecommunications components, or maintain separate programs.
Who it applies to
Carrier assets, and relevant carriage service provider assets that meet the prescribed threshold. Below those thresholds the TSRMP Rules do not apply, though other obligations under the Act still do.
Read more
- What Your TSRMP Needs to Contain for Telco Assets
Telecommunications assets have specific requirements under the SOCI Act TSRMP framework. What the risk management program needs to cover and where most entities leave gaps.
See also
- CIRMP Critical Infrastructure Risk Management Program The risk management program that responsible entities must establish and maintain under the SOCI Act.
- SOCI Security of Critical Infrastructure Act 2018 Australian federal legislation, often searched for as the Security of Critical Infrastructure Act, that imposes positive security obligations on entities responsible for critical infrastructure assets across 11 sectors.
- Responsible Entity Under the SOCI Act, the entity that has operational responsibility for a critical infrastructure asset.
O/IT Cyber advises Australian critical infrastructure operators on risk management programs, framework nomination and OT security. Talk to us.