Critical Infrastructure Risk Management Program (CIRMP) Rules 2023
Evidence request list. 11 controls, 11 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
CIRMP: Application and Material Risk
The Rules apply to responsible entities for the critical infrastructure asset classes specified in the Rules (including critical electricity, gas, water and sewerage, energy market operator, data storage or processing, financial market infrastructure, food and grocery, hospital, domain name system, broadcasting, and certain transport assets). A responsible entity for a specified asset must adopt and maintain a CIRMP.
- Determination of whether the entity is a responsible entity for a specified critical infrastructure asset class
- Asset register identifying the in-scope critical infrastructure asset
- Assuming the Rules do not apply without checking the specified asset classes
- No identification of the responsible entity for the asset
The CIRMP must identify each hazard where there is a material risk that the occurrence of the hazard could have a relevant impact on the critical infrastructure asset. A risk is material where it could materially affect the availability, integrity, reliability or confidentiality of the asset, including through a cascading or supply-chain effect.
- Documented material-risk register mapping hazards to relevant impacts on the asset
- Methodology defining materiality for availability, integrity, reliability and confidentiality
- No documented material-risk identification
- Materiality undefined or applied inconsistently
For all hazards, the CIRMP must, so far as reasonably practicable, minimise or eliminate the material risk of the hazard occurring, and mitigate the relevant impact of the hazard on the critical infrastructure asset. The program must be reviewed and kept up to date.
- Risk-treatment plan linking each material risk to minimisation/elimination and impact-mitigation measures
- Evidence the program is maintained and current
- Identifying risks without treatment
- No mitigation for residual impact
CIRMP: Cyber and Information Security Hazards
The CIRMP must establish and maintain a process or system to identify, and as far as reasonably practicable minimise or eliminate, material risks arising from cyber and information security hazards, and to mitigate their relevant impact on the asset.
- Documented cyber and information security risk-management process within the CIRMP
- Evidence of identification, mitigation and impact-reduction for cyber hazards
- No cyber-specific process in the CIRMP
- Cyber hazards not linked to the material-risk register
Within the period specified by the Rules, the responsible entity must adopt and maintain compliance with one of the recognised cyber security frameworks for the cyber and information security hazard, such as the ACSC Essential Eight (Maturity Level One), ISO/IEC 27001, the NIST Cybersecurity Framework, the AESCSF framework core, or an equivalent recognised framework, and maintain it as the cyber baseline for the asset.
- Evidence of the cyber security framework selected (Essential Eight ML1, ISO 27001, NIST CSF, AESCSF or equivalent)
- Assessment demonstrating compliance with the chosen framework at the required level
- Records showing adoption within the regulatory timeframe
- No recognised framework adopted
- Framework selected but compliance not demonstrated
- Essential Eight adopted below Maturity Level One
CIRMP: Governance and Reporting
The responsible entity must adopt a CIRMP that complies with the Rules, and the program (and any variation) must be approved by the entity's board, council or other governing body before it takes effect.
- Board/governing-body approval of the CIRMP and of variations
- Dated, version-controlled CIRMP document
- CIRMP not approved by the governing body
- No version control over the program
The responsible entity must give an annual report on the CIRMP to the relevant Commonwealth regulator within the period after the end of the financial year specified by the Act. The annual report must be approved by the entity's board or governing body and state whether the program was up to date and whether any hazard had a significant relevant impact during the year.
- Board-approved annual CIRMP report submitted to the relevant regulator within the statutory deadline
- Record of any significant hazards reported
- Annual report not submitted or late
- Report not approved by the governing body
The responsible entity must review the CIRMP on a regular basis and keep it up to date, ensuring it remains appropriate as hazards, the asset and the operating environment change.
- Records of periodic CIRMP reviews and updates
- Triggers for ad hoc review on material change
- No regular review of the program
- Program not updated after material change
CIRMP: Personnel Hazards
The CIRMP must manage material risks arising from personnel, including the risk that a critical worker could, intentionally or unintentionally, compromise the asset. This includes assessing the suitability of personnel with access, conducting background checks (including AusCheck where applicable), and managing access by critical workers.
- Critical-worker identification and suitability assessment records
- Background-check / AusCheck records where applicable
- Access management tied to personnel risk
- No assessment of critical workers
- Background checks not performed where required
- Trusted-insider risk not addressed
CIRMP: Physical Security and Natural Hazards
The CIRMP must manage material risks arising from physical security hazards and natural hazards, including controlling physical access to the asset and its critical components, and maintaining resilience and continuity against natural hazards.
- Physical access controls for the asset and critical components
- Natural-hazard resilience and continuity arrangements
- Unrestricted physical access to critical components
- No natural-hazard resilience planning
CIRMP: Supply Chain Hazards
The CIRMP must identify and, so far as reasonably practicable, minimise or eliminate material risks arising from supply chain hazards, and mitigate their relevant impact, including risks from suppliers, service providers and the misuse of privileged access by a supplier.
- Supply-chain risk assessment for the asset
- Supplier due-diligence and contractual security requirements
- Controls over supplier privileged access
- No supply-chain risk assessment
- Suppliers not subject to security due diligence
- Unmanaged supplier privileged access
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Critical Infrastructure Risk Management Program (CIRMP) Rules 2023 framework page.