Australian Energy Sector Cyber Security Framework (AESCSF)
Evidence request list. 32 controls, 32 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
Asset, Change and Configuration Management
Maintain an inventory of IT and OT assets important to the delivery of the energy function.
- IT and OT asset inventory
- Criticality of assets recorded
- Inventory maintenance
- Incomplete inventory
- OT assets omitted
- Inventory stale
Establish and maintain secure configuration baselines for assets.
- Configuration baselines
- Configuration monitoring
- Deviation management
- No baselines
- Configuration drift unmanaged
Manage changes to assets through a controlled change-management process.
- Change management procedure
- Change records and approvals
- Security review of changes
- No change control
- Changes unapproved
- Security not assessed for changes
Australian Privacy Management
Manage personal information in accordance with the Australian Privacy Principles and the Privacy Act 1988.
- Privacy management framework
- APP compliance
- Personal information handling controls
- No privacy management
- APP obligations unmet
Detect, manage and notify privacy/data breaches affecting personal information.
- Privacy breach response procedure
- Notification to OAIC where required
- Breach records
- No breach procedure
- Notifiable breaches not reported
Cyber Security Program Management
Establish, resource and maintain an enterprise cyber security program.
- Cyber security program charter
- Resourcing and funding
- Program oversight
- No formal program
- Program under-resourced
Provide governance and strategic direction for cyber security, with board/executive oversight.
- Cyber security strategy
- Board/executive oversight
- Policies and standards
- No strategy
- No executive oversight
Establish and maintain a cyber security architecture for IT and OT environments.
- Documented security architecture
- OT/IT segmentation
- Architecture review
- No security architecture
- No IT/OT segmentation
Event and Incident Response, Continuity of Operations
Establish and maintain a cyber incident response plan covering IT and OT.
- Documented incident response plan
- Roles and escalation
- Plan covers OT
- No IR plan
- OT not covered
- Roles undefined
Detect, analyse, contain and eradicate cyber incidents.
- Incident handling procedures
- Containment/eradication evidence
- Incident records
- Incidents not handled systematically
- No containment procedures
Maintain continuity and recover operations after a cyber incident, including for OT-dependent energy functions.
- Business continuity / disaster recovery plans
- Recovery testing
- OT recovery capability
- No continuity/recovery plan
- Recovery untested
- OT recovery not addressed
Report cyber incidents to AEMO, the ACSC and (where applicable) under the SOCI Act.
- Incident reporting procedure
- Records of reports to AEMO/ACSC
- SOCI Act reporting where applicable
- Incidents not reported
- SOCI reporting obligations missed
Identity and Access Management
Establish and maintain identities for personnel and devices accessing IT and OT.
- Identity lifecycle management
- Unique identities
- Device identity where applicable
- Shared identities
- No identity lifecycle
Control and limit access to IT and OT, including privileged access, on a least-privilege basis.
- Role-based / least-privilege access
- Privileged access management
- Access reviews
- Excessive access
- Privileged access unmanaged
- No access reviews
Require multi-factor authentication for remote and privileged access to IT and OT.
- MFA on remote/privileged access
- Coverage of OT where feasible
- No MFA
- MFA gaps on privileged/remote access
Information Sharing and Communications
Share and receive cyber security information with AEMO, the ACSC and sector peers.
- Participation in sector information sharing
- Records of shared/received intelligence
- No information sharing
- Sector intelligence not used
Communicate with internal and external stakeholders, including during cyber incidents.
- Stakeholder communication plan
- Incident communication procedures
- No communication plan
- Stakeholders uninformed during incidents
Risk Management
Establish and maintain a cyber security risk management strategy and program covering both IT and operational technology (OT).
- Documented cyber risk management strategy/program
- Coverage of IT and OT
- Governance of the program
- No risk strategy
- OT risk excluded
- Program not governed
Identify, analyse and prioritise cyber security risks to the organisation's IT and OT assets and critical functions.
- Risk register
- Risk assessment methodology
- Prioritised risks to critical functions
- Risks not assessed
- No prioritisation
- Critical functions not considered
Treat identified risks to within risk tolerance and monitor residual risk over time.
- Risk treatment plans
- Residual risk acceptance
- Risk monitoring
- Risks untreated
- No residual-risk acceptance
- Risk not monitored
Situational Awareness
Log and monitor security-relevant events across IT and OT.
- Logging coverage of IT and OT
- Monitoring/alerting
- Log retention
- Inadequate logging
- OT not monitored
- No alerting
Detect anomalies and cyber events that may indicate compromise.
- Anomaly detection capability
- Baseline of normal activity
- Event triage
- No anomaly detection
- No behavioural baseline
Establish a common operating picture of the cyber security state to support decisions.
- Consolidated cyber status reporting
- Situational awareness shared with decision-makers
- No consolidated view
- Decision-makers lack awareness
Supply Chain and External Dependencies Management
Manage cyber security risks arising from suppliers and the supply chain.
- Supplier cyber risk assessment
- Contractual security requirements
- Ongoing supplier oversight
- Suppliers not assessed
- No contractual security terms
Identify and assess external dependencies (including third-party and shared services) important to energy delivery.
- Dependency register
- Risk assessment of external dependencies
- Dependencies not identified
- Dependency risk unassessed
Manage and monitor external dependencies to maintain resilience of critical functions.
- Monitoring of critical dependencies
- Contingency for dependency failure
- No contingency for dependency loss
- Dependencies unmonitored
Threat and Vulnerability Management
Identify, assess and remediate vulnerabilities in IT and OT in a timely, risk-based manner.
- Vulnerability identification/assessment
- Remediation tracking
- Risk-based prioritisation
- No vulnerability management
- Remediation not tracked
- OT vulnerabilities ignored
Collect and use cyber threat intelligence relevant to the energy sector.
- Threat intelligence sources
- Use of intelligence in defence
- Sector-specific threat awareness
- No threat intelligence
- Intelligence not operationalised
Apply security patches and remediations to IT and OT, balancing operational constraints.
- Patch management process
- Patch cadence and records
- OT patching with operational controls
- Patching not timely
- OT patching unmanaged
Workforce Management
Define cyber security roles and ensure the workforce has the capacity to perform them.
- Defined cyber roles and responsibilities
- Workforce capacity planning
- Roles undefined
- Insufficient capacity
Provide cyber security training and awareness to the workforce, including OT personnel.
- Training records
- Awareness programme
- OT-specific training
- No training
- OT personnel untrained
Apply personnel security controls (screening, onboarding and offboarding) for access to IT and OT.
- Screening for sensitive roles
- Onboarding/offboarding access controls
- No screening
- Access not removed on exit
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Australian Energy Sector Cyber Security Framework (AESCSF) framework page.