Skip to content

Evidence request lists

Australian Energy Sector Cyber Security Framework (AESCSF)

Evidence request list. 32 controls, 32 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Asset, Change and Configuration Management

AESCSF-ACM-1
Asset inventory

Maintain an inventory of IT and OT assets important to the delivery of the energy function.

Artefacts an auditor will ask for
  • IT and OT asset inventory
  • Criticality of assets recorded
  • Inventory maintenance
Where this commonly fails
  • Incomplete inventory
  • OT assets omitted
  • Inventory stale
AESCSF-ACM-2
Configuration management

Establish and maintain secure configuration baselines for assets.

Artefacts an auditor will ask for
  • Configuration baselines
  • Configuration monitoring
  • Deviation management
Where this commonly fails
  • No baselines
  • Configuration drift unmanaged
AESCSF-ACM-3
Change management

Manage changes to assets through a controlled change-management process.

Artefacts an auditor will ask for
  • Change management procedure
  • Change records and approvals
  • Security review of changes
Where this commonly fails
  • No change control
  • Changes unapproved
  • Security not assessed for changes

Australian Privacy Management

AESCSF-APM-1
Australian privacy management

Manage personal information in accordance with the Australian Privacy Principles and the Privacy Act 1988.

Artefacts an auditor will ask for
  • Privacy management framework
  • APP compliance
  • Personal information handling controls
Where this commonly fails
  • No privacy management
  • APP obligations unmet
AESCSF-APM-2
Privacy breach management

Detect, manage and notify privacy/data breaches affecting personal information.

Artefacts an auditor will ask for
  • Privacy breach response procedure
  • Notification to OAIC where required
  • Breach records
Where this commonly fails
  • No breach procedure
  • Notifiable breaches not reported

Cyber Security Program Management

AESCSF-CPM-1
Cyber security program management

Establish, resource and maintain an enterprise cyber security program.

Artefacts an auditor will ask for
  • Cyber security program charter
  • Resourcing and funding
  • Program oversight
Where this commonly fails
  • No formal program
  • Program under-resourced
AESCSF-CPM-2
Cyber security governance and strategy

Provide governance and strategic direction for cyber security, with board/executive oversight.

Artefacts an auditor will ask for
  • Cyber security strategy
  • Board/executive oversight
  • Policies and standards
Where this commonly fails
  • No strategy
  • No executive oversight
AESCSF-CPM-3
Cyber security architecture

Establish and maintain a cyber security architecture for IT and OT environments.

Artefacts an auditor will ask for
  • Documented security architecture
  • OT/IT segmentation
  • Architecture review
Where this commonly fails
  • No security architecture
  • No IT/OT segmentation

Event and Incident Response, Continuity of Operations

AESCSF-IR-1
Incident response plan

Establish and maintain a cyber incident response plan covering IT and OT.

Artefacts an auditor will ask for
  • Documented incident response plan
  • Roles and escalation
  • Plan covers OT
Where this commonly fails
  • No IR plan
  • OT not covered
  • Roles undefined
AESCSF-IR-2
Incident detection and handling

Detect, analyse, contain and eradicate cyber incidents.

Artefacts an auditor will ask for
  • Incident handling procedures
  • Containment/eradication evidence
  • Incident records
Where this commonly fails
  • Incidents not handled systematically
  • No containment procedures
AESCSF-IR-3
Continuity of operations and recovery

Maintain continuity and recover operations after a cyber incident, including for OT-dependent energy functions.

Artefacts an auditor will ask for
  • Business continuity / disaster recovery plans
  • Recovery testing
  • OT recovery capability
Where this commonly fails
  • No continuity/recovery plan
  • Recovery untested
  • OT recovery not addressed
AESCSF-IR-4
Incident reporting

Report cyber incidents to AEMO, the ACSC and (where applicable) under the SOCI Act.

Artefacts an auditor will ask for
  • Incident reporting procedure
  • Records of reports to AEMO/ACSC
  • SOCI Act reporting where applicable
Where this commonly fails
  • Incidents not reported
  • SOCI reporting obligations missed

Identity and Access Management

AESCSF-IAM-1
Identity management

Establish and maintain identities for personnel and devices accessing IT and OT.

Artefacts an auditor will ask for
  • Identity lifecycle management
  • Unique identities
  • Device identity where applicable
Where this commonly fails
  • Shared identities
  • No identity lifecycle
AESCSF-IAM-2
Access control

Control and limit access to IT and OT, including privileged access, on a least-privilege basis.

Artefacts an auditor will ask for
  • Role-based / least-privilege access
  • Privileged access management
  • Access reviews
Where this commonly fails
  • Excessive access
  • Privileged access unmanaged
  • No access reviews
AESCSF-IAM-3
Multi-factor authentication

Require multi-factor authentication for remote and privileged access to IT and OT.

Artefacts an auditor will ask for
  • MFA on remote/privileged access
  • Coverage of OT where feasible
Where this commonly fails
  • No MFA
  • MFA gaps on privileged/remote access

Information Sharing and Communications

AESCSF-ISC-1
Cyber security information sharing

Share and receive cyber security information with AEMO, the ACSC and sector peers.

Artefacts an auditor will ask for
  • Participation in sector information sharing
  • Records of shared/received intelligence
Where this commonly fails
  • No information sharing
  • Sector intelligence not used
AESCSF-ISC-2
Stakeholder communications

Communicate with internal and external stakeholders, including during cyber incidents.

Artefacts an auditor will ask for
  • Stakeholder communication plan
  • Incident communication procedures
Where this commonly fails
  • No communication plan
  • Stakeholders uninformed during incidents

Risk Management

AESCSF-RM-1
Establish cyber security risk management strategy

Establish and maintain a cyber security risk management strategy and program covering both IT and operational technology (OT).

Artefacts an auditor will ask for
  • Documented cyber risk management strategy/program
  • Coverage of IT and OT
  • Governance of the program
Where this commonly fails
  • No risk strategy
  • OT risk excluded
  • Program not governed
AESCSF-RM-2
Identify and assess cyber risks

Identify, analyse and prioritise cyber security risks to the organisation's IT and OT assets and critical functions.

Artefacts an auditor will ask for
  • Risk register
  • Risk assessment methodology
  • Prioritised risks to critical functions
Where this commonly fails
  • Risks not assessed
  • No prioritisation
  • Critical functions not considered
AESCSF-RM-3
Manage and treat cyber risks

Treat identified risks to within risk tolerance and monitor residual risk over time.

Artefacts an auditor will ask for
  • Risk treatment plans
  • Residual risk acceptance
  • Risk monitoring
Where this commonly fails
  • Risks untreated
  • No residual-risk acceptance
  • Risk not monitored

Situational Awareness

AESCSF-SA-1
Logging and monitoring

Log and monitor security-relevant events across IT and OT.

Artefacts an auditor will ask for
  • Logging coverage of IT and OT
  • Monitoring/alerting
  • Log retention
Where this commonly fails
  • Inadequate logging
  • OT not monitored
  • No alerting
AESCSF-SA-2
Anomaly and event detection

Detect anomalies and cyber events that may indicate compromise.

Artefacts an auditor will ask for
  • Anomaly detection capability
  • Baseline of normal activity
  • Event triage
Where this commonly fails
  • No anomaly detection
  • No behavioural baseline
AESCSF-SA-3
Common operating picture

Establish a common operating picture of the cyber security state to support decisions.

Artefacts an auditor will ask for
  • Consolidated cyber status reporting
  • Situational awareness shared with decision-makers
Where this commonly fails
  • No consolidated view
  • Decision-makers lack awareness

Supply Chain and External Dependencies Management

AESCSF-EDM-1
Supply chain risk management

Manage cyber security risks arising from suppliers and the supply chain.

Artefacts an auditor will ask for
  • Supplier cyber risk assessment
  • Contractual security requirements
  • Ongoing supplier oversight
Where this commonly fails
  • Suppliers not assessed
  • No contractual security terms
AESCSF-EDM-2
External dependency assessment

Identify and assess external dependencies (including third-party and shared services) important to energy delivery.

Artefacts an auditor will ask for
  • Dependency register
  • Risk assessment of external dependencies
Where this commonly fails
  • Dependencies not identified
  • Dependency risk unassessed
AESCSF-EDM-3
Dependency resilience

Manage and monitor external dependencies to maintain resilience of critical functions.

Artefacts an auditor will ask for
  • Monitoring of critical dependencies
  • Contingency for dependency failure
Where this commonly fails
  • No contingency for dependency loss
  • Dependencies unmonitored

Threat and Vulnerability Management

AESCSF-TVM-1
Vulnerability management

Identify, assess and remediate vulnerabilities in IT and OT in a timely, risk-based manner.

Artefacts an auditor will ask for
  • Vulnerability identification/assessment
  • Remediation tracking
  • Risk-based prioritisation
Where this commonly fails
  • No vulnerability management
  • Remediation not tracked
  • OT vulnerabilities ignored
AESCSF-TVM-2
Threat management

Collect and use cyber threat intelligence relevant to the energy sector.

Artefacts an auditor will ask for
  • Threat intelligence sources
  • Use of intelligence in defence
  • Sector-specific threat awareness
Where this commonly fails
  • No threat intelligence
  • Intelligence not operationalised
AESCSF-TVM-3
Patch and remediation management

Apply security patches and remediations to IT and OT, balancing operational constraints.

Artefacts an auditor will ask for
  • Patch management process
  • Patch cadence and records
  • OT patching with operational controls
Where this commonly fails
  • Patching not timely
  • OT patching unmanaged

Workforce Management

AESCSF-WM-1
Cyber security workforce management

Define cyber security roles and ensure the workforce has the capacity to perform them.

Artefacts an auditor will ask for
  • Defined cyber roles and responsibilities
  • Workforce capacity planning
Where this commonly fails
  • Roles undefined
  • Insufficient capacity
AESCSF-WM-2
Training and awareness

Provide cyber security training and awareness to the workforce, including OT personnel.

Artefacts an auditor will ask for
  • Training records
  • Awareness programme
  • OT-specific training
Where this commonly fails
  • No training
  • OT personnel untrained
AESCSF-WM-3
Personnel security

Apply personnel security controls (screening, onboarding and offboarding) for access to IT and OT.

Artefacts an auditor will ask for
  • Screening for sensitive roles
  • Onboarding/offboarding access controls
Where this commonly fails
  • No screening
  • Access not removed on exit
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Australian Energy Sector Cyber Security Framework (AESCSF) framework page.