Skip to content

Evidence request lists

Critical Infrastructure Risk Management Program (CIRMP) Rules 2023

Evidence request list. 11 controls, 11 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

CIRMP: Application and Material Risk

CIRMP-s5
Application to designated critical infrastructure asset classes

The Rules apply to responsible entities for the critical infrastructure asset classes specified in the Rules (including critical electricity, gas, water and sewerage, energy market operator, data storage or processing, financial market infrastructure, food and grocery, hospital, domain name system, broadcasting, and certain transport assets). A responsible entity for a specified asset must adopt and maintain a CIRMP.

Artefacts an auditor will ask for
  • Determination of whether the entity is a responsible entity for a specified critical infrastructure asset class
  • Asset register identifying the in-scope critical infrastructure asset
Where this commonly fails
  • Assuming the Rules do not apply without checking the specified asset classes
  • No identification of the responsible entity for the asset
CIRMP-s6
Identification of material risks

The CIRMP must identify each hazard where there is a material risk that the occurrence of the hazard could have a relevant impact on the critical infrastructure asset. A risk is material where it could materially affect the availability, integrity, reliability or confidentiality of the asset, including through a cascading or supply-chain effect.

Artefacts an auditor will ask for
  • Documented material-risk register mapping hazards to relevant impacts on the asset
  • Methodology defining materiality for availability, integrity, reliability and confidentiality
Where this commonly fails
  • No documented material-risk identification
  • Materiality undefined or applied inconsistently
CIRMP-s7
General requirement - minimise, eliminate and mitigate all hazards

For all hazards, the CIRMP must, so far as reasonably practicable, minimise or eliminate the material risk of the hazard occurring, and mitigate the relevant impact of the hazard on the critical infrastructure asset. The program must be reviewed and kept up to date.

Artefacts an auditor will ask for
  • Risk-treatment plan linking each material risk to minimisation/elimination and impact-mitigation measures
  • Evidence the program is maintained and current
Where this commonly fails
  • Identifying risks without treatment
  • No mitigation for residual impact

CIRMP: Cyber and Information Security Hazards

CIRMP-s8
Cyber and information security hazard management

The CIRMP must establish and maintain a process or system to identify, and as far as reasonably practicable minimise or eliminate, material risks arising from cyber and information security hazards, and to mitigate their relevant impact on the asset.

Artefacts an auditor will ask for
  • Documented cyber and information security risk-management process within the CIRMP
  • Evidence of identification, mitigation and impact-reduction for cyber hazards
Where this commonly fails
  • No cyber-specific process in the CIRMP
  • Cyber hazards not linked to the material-risk register
CIRMP-s8-FW
Adoption of a recognised cyber security framework

Within the period specified by the Rules, the responsible entity must adopt and maintain compliance with one of the recognised cyber security frameworks for the cyber and information security hazard, such as the ACSC Essential Eight (Maturity Level One), ISO/IEC 27001, the NIST Cybersecurity Framework, the AESCSF framework core, or an equivalent recognised framework, and maintain it as the cyber baseline for the asset.

Artefacts an auditor will ask for
  • Evidence of the cyber security framework selected (Essential Eight ML1, ISO 27001, NIST CSF, AESCSF or equivalent)
  • Assessment demonstrating compliance with the chosen framework at the required level
  • Records showing adoption within the regulatory timeframe
Where this commonly fails
  • No recognised framework adopted
  • Framework selected but compliance not demonstrated
  • Essential Eight adopted below Maturity Level One

CIRMP: Governance and Reporting

CIRMP-GOV-ADOPT
Adoption and board approval of the CIRMP

The responsible entity must adopt a CIRMP that complies with the Rules, and the program (and any variation) must be approved by the entity's board, council or other governing body before it takes effect.

Artefacts an auditor will ask for
  • Board/governing-body approval of the CIRMP and of variations
  • Dated, version-controlled CIRMP document
Where this commonly fails
  • CIRMP not approved by the governing body
  • No version control over the program
CIRMP-GOV-REPORT
Annual report to the Commonwealth regulator

The responsible entity must give an annual report on the CIRMP to the relevant Commonwealth regulator within the period after the end of the financial year specified by the Act. The annual report must be approved by the entity's board or governing body and state whether the program was up to date and whether any hazard had a significant relevant impact during the year.

Artefacts an auditor will ask for
  • Board-approved annual CIRMP report submitted to the relevant regulator within the statutory deadline
  • Record of any significant hazards reported
Where this commonly fails
  • Annual report not submitted or late
  • Report not approved by the governing body
CIRMP-GOV-REVIEW
Annual review and currency of the CIRMP

The responsible entity must review the CIRMP on a regular basis and keep it up to date, ensuring it remains appropriate as hazards, the asset and the operating environment change.

Artefacts an auditor will ask for
  • Records of periodic CIRMP reviews and updates
  • Triggers for ad hoc review on material change
Where this commonly fails
  • No regular review of the program
  • Program not updated after material change

CIRMP: Personnel Hazards

CIRMP-s9
Personnel hazard management

The CIRMP must manage material risks arising from personnel, including the risk that a critical worker could, intentionally or unintentionally, compromise the asset. This includes assessing the suitability of personnel with access, conducting background checks (including AusCheck where applicable), and managing access by critical workers.

Artefacts an auditor will ask for
  • Critical-worker identification and suitability assessment records
  • Background-check / AusCheck records where applicable
  • Access management tied to personnel risk
Where this commonly fails
  • No assessment of critical workers
  • Background checks not performed where required
  • Trusted-insider risk not addressed

CIRMP: Physical Security and Natural Hazards

CIRMP-s11
Physical security and natural hazard management

The CIRMP must manage material risks arising from physical security hazards and natural hazards, including controlling physical access to the asset and its critical components, and maintaining resilience and continuity against natural hazards.

Artefacts an auditor will ask for
  • Physical access controls for the asset and critical components
  • Natural-hazard resilience and continuity arrangements
Where this commonly fails
  • Unrestricted physical access to critical components
  • No natural-hazard resilience planning

CIRMP: Supply Chain Hazards

CIRMP-s10
Supply chain hazard management

The CIRMP must identify and, so far as reasonably practicable, minimise or eliminate material risks arising from supply chain hazards, and mitigate their relevant impact, including risks from suppliers, service providers and the misuse of privileged access by a supplier.

Artefacts an auditor will ask for
  • Supply-chain risk assessment for the asset
  • Supplier due-diligence and contractual security requirements
  • Controls over supplier privileged access
Where this commonly fails
  • No supply-chain risk assessment
  • Suppliers not subject to security due diligence
  • Unmanaged supplier privileged access
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Critical Infrastructure Risk Management Program (CIRMP) Rules 2023 framework page.