Skip to content

Evidence request lists

Cyber Security Act 2024 (Australia)

Evidence request list. 17 controls, 17 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Cyber Security Act 2024: Coordination and Limited Use

AUCSA-LU-INTERACT
Interaction with other reporting requirements

The Act clarifies how its information-sharing and limited-use provisions interact with other Commonwealth requirements, so the obligations operate alongside other incident reporting duties.

Artefacts an auditor will ask for
  • Mapping of overlapping incident-reporting duties (SOCI, Privacy Act, sector regulators)
Where this commonly fails
  • Treating the Act's reporting as a substitute for other mandatory reports
AUCSA-LU-LIMITED
Limited use obligation on shared incident information

Information voluntarily provided to the National Cyber Security Coordinator or ASD about a cyber security incident is subject to a limited use obligation restricting how Commonwealth bodies may use and disclose it, so that voluntary cooperation is not used against the providing entity.

Artefacts an auditor will ask for
  • Understanding of the limited-use protections when sharing incident information
  • Internal guidance encouraging cooperation under the limited-use regime
Where this commonly fails
  • Declining to share incident information due to misunderstanding the limited-use protections
AUCSA-LU-SHARE
Voluntary information sharing with the National Cyber Security Coordinator

The Act provides for voluntary sharing of cyber security incident information with the National Cyber Security Coordinator (and ASD) to support coordination of significant cyber security incidents.

Artefacts an auditor will ask for
  • Process for engaging the National Cyber Security Coordinator during significant incidents
  • Records of voluntary information shared
Where this commonly fails
  • No engagement path with the National Cyber Security Coordinator

Cyber Security Act 2024: Cyber Incident Review Board

AUCSA-CIRB-EST
Establishment, functions and powers of the Cyber Incident Review Board

Establishes the Cyber Incident Review Board to conduct no-fault, post-incident reviews of significant cyber security incidents and make recommendations to improve cyber security, and sets out its functions and powers.

Artefacts an auditor will ask for
  • Awareness of the CIRB and its review remit
  • Internal point of contact for CIRB engagement
Where this commonly fails
  • No readiness to engage with a CIRB review
AUCSA-CIRB-INFO
Compulsory information production and protection of review information

The Board may compel the production of information for a review, and information relating to reviews is protected from certain uses and disclosures, including protection of identified persons.

Artefacts an auditor will ask for
  • Procedure to respond to a CIRB information-production notice
  • Handling of protected review information
Where this commonly fails
  • Inability to produce information requested by the Board
AUCSA-CIRB-REVIEW
Conduct of no-fault post-incident reviews

The Board may cause reviews of significant cyber security incidents to be conducted on a no-fault basis to identify lessons learned, without attributing liability.

Artefacts an auditor will ask for
  • Participation in CIRB reviews where applicable
  • Post-incident lessons-learned process aligned to review findings
Where this commonly fails
  • No internal post-incident review capability
AUCSA-CIRB-RPT
Board reports and recommendations

The Board publishes reports and recommendations from its reviews to improve cyber security across the economy.

Artefacts an auditor will ask for
  • Tracking of CIRB recommendations relevant to the entity
  • Action on applicable Board recommendations
Where this commonly fails
  • Ignoring published CIRB recommendations relevant to the entity's sector

Cyber Security Act 2024: Preliminary and Objects

AUCSA-P1-OBJ
Objects and application of the Act

Sets the objects of the Act: to improve Australia's cyber security through mandatory security standards for smart devices, ransomware payment reporting, coordination and limited use of incident information, and a Cyber Incident Review Board; and defines key terms and the entities to which each Part applies.

Artefacts an auditor will ask for
  • Determination of which Parts of the Act apply to the entity (smart-device manufacturer/supplier, reporting business entity, etc.)
  • Register of obligations owned per Part
Where this commonly fails
  • Assuming the Act does not apply without a per-Part scoping analysis

Cyber Security Act 2024: Ransomware Reporting Obligations

AUCSA-RAN-CONTENT
Content of a ransomware payment report

The ransomware payment report must contain the prescribed information, including details of the incident, the demand, the payment made and the entity to which it was made.

Artefacts an auditor will ask for
  • Report template capturing all prescribed content fields
  • Evidence the report content matches the incident record
Where this commonly fails
  • Incomplete report content
  • Inconsistent incident and report details
AUCSA-RAN-PROT
Limited use and protection of ransomware report information

Information in a ransomware payment report is subject to restrictions on how it may be used and disclosed, limiting its use against the reporting entity and supporting candid reporting.

Artefacts an auditor will ask for
  • Awareness of the limited-use protections attaching to ransomware reports
Where this commonly fails
  • Withholding a report due to misunderstanding the protections
AUCSA-RAN-RPT
Ransomware and cyber-extortion payment reporting obligation

A reporting business entity that makes, or whose entity makes on its behalf, a ransomware or cyber-extortion payment in response to a cyber security incident must report the payment to the designated Commonwealth body within 72 hours of making the payment or becoming aware it was made.

Artefacts an auditor will ask for
  • Ransomware-payment reporting procedure with the 72-hour deadline
  • Determination of reporting-business-entity status (turnover threshold)
  • Log of any payments and the reports made
Where this commonly fails
  • No process to report a ransomware payment within 72 hours
  • Unaware of reporting-business-entity status
  • Paying without an internal authorisation and reporting workflow

Cyber Security Act 2024: Regulatory Powers and Interactions

AUCSA-INT-SOCI
Interaction with the SOCI Act and other laws

The Act operates alongside the Security of Critical Infrastructure Act 2018 (as amended by the 2024 package) and other Commonwealth laws; entities subject to both must meet each set of obligations.

Artefacts an auditor will ask for
  • Combined obligation map across the Cyber Security Act, SOCI Act/CIRMP and the Privacy Act
  • Single register reconciling overlapping incident-reporting duties
Where this commonly fails
  • Treating SOCI/CIRMP compliance as satisfying the Cyber Security Act, or vice versa
AUCSA-REG-MON
Monitoring, investigation and infringement notices

The Act applies the Regulatory Powers (Standard Provisions) Act monitoring and investigation powers, and provides for infringement notices for certain contraventions.

Artefacts an auditor will ask for
  • Readiness to support monitoring/investigation activity
  • Records demonstrating compliance with each obligation
Where this commonly fails
  • No retained evidence of compliance for regulator inspection
AUCSA-REG-PEN
Civil penalty provisions and enforceable undertakings

The Act creates civil penalty provisions and provides for enforceable undertakings for contraventions of its obligations.

Artefacts an auditor will ask for
  • Risk assessment of civil-penalty exposure under the Act
  • Compliance evidence available in the event of regulatory action
Where this commonly fails
  • Underestimating civil-penalty exposure

Cyber Security Act 2024: Security Standards for Smart Devices

AUCSA-IOT-COC
Statement of compliance for connectable products

A manufacturer must provide a statement of compliance for relevant connectable products in the manner and form required, attesting that the product meets the applicable security standard.

Artefacts an auditor will ask for
  • Statements of compliance issued for each in-scope product
  • Records supporting the compliance attestation
Where this commonly fails
  • Missing or inaccurate statement of compliance
  • Statement not in the required form
AUCSA-IOT-ENF
Compliance, stop and recall notices for smart devices

The Secretary may issue compliance notices, stop notices and recall notices for non-compliant connectable products; the entity must respond, and may seek internal review of such decisions.

Artefacts an auditor will ask for
  • Procedure to respond to compliance/stop/recall notices
  • Records of any notices received and remediation
Where this commonly fails
  • No process to action a compliance or stop notice
  • Continuing supply after a stop notice
AUCSA-IOT-STD
Security standards for relevant connectable products

Manufacturers and suppliers of relevant connectable (smart/IoT) products must ensure the products comply with the mandatory security standards made under the Act before they are supplied in Australia.

Artefacts an auditor will ask for
  • Mapping of products to the applicable security standards
  • Design/test evidence that products meet the mandatory standards
Where this commonly fails
  • Supplying connectable products that do not meet the security standards
  • No assessment of which products are in scope
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.