Cyber Security Act 2024 (Australia)
Evidence request list. 17 controls, 17 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
Cyber Security Act 2024: Coordination and Limited Use
The Act clarifies how its information-sharing and limited-use provisions interact with other Commonwealth requirements, so the obligations operate alongside other incident reporting duties.
- Mapping of overlapping incident-reporting duties (SOCI, Privacy Act, sector regulators)
- Treating the Act's reporting as a substitute for other mandatory reports
Information voluntarily provided to the National Cyber Security Coordinator or ASD about a cyber security incident is subject to a limited use obligation restricting how Commonwealth bodies may use and disclose it, so that voluntary cooperation is not used against the providing entity.
- Understanding of the limited-use protections when sharing incident information
- Internal guidance encouraging cooperation under the limited-use regime
- Declining to share incident information due to misunderstanding the limited-use protections
The Act provides for voluntary sharing of cyber security incident information with the National Cyber Security Coordinator (and ASD) to support coordination of significant cyber security incidents.
- Process for engaging the National Cyber Security Coordinator during significant incidents
- Records of voluntary information shared
- No engagement path with the National Cyber Security Coordinator
Cyber Security Act 2024: Cyber Incident Review Board
Establishes the Cyber Incident Review Board to conduct no-fault, post-incident reviews of significant cyber security incidents and make recommendations to improve cyber security, and sets out its functions and powers.
- Awareness of the CIRB and its review remit
- Internal point of contact for CIRB engagement
- No readiness to engage with a CIRB review
The Board may compel the production of information for a review, and information relating to reviews is protected from certain uses and disclosures, including protection of identified persons.
- Procedure to respond to a CIRB information-production notice
- Handling of protected review information
- Inability to produce information requested by the Board
The Board may cause reviews of significant cyber security incidents to be conducted on a no-fault basis to identify lessons learned, without attributing liability.
- Participation in CIRB reviews where applicable
- Post-incident lessons-learned process aligned to review findings
- No internal post-incident review capability
The Board publishes reports and recommendations from its reviews to improve cyber security across the economy.
- Tracking of CIRB recommendations relevant to the entity
- Action on applicable Board recommendations
- Ignoring published CIRB recommendations relevant to the entity's sector
Cyber Security Act 2024: Preliminary and Objects
Sets the objects of the Act: to improve Australia's cyber security through mandatory security standards for smart devices, ransomware payment reporting, coordination and limited use of incident information, and a Cyber Incident Review Board; and defines key terms and the entities to which each Part applies.
- Determination of which Parts of the Act apply to the entity (smart-device manufacturer/supplier, reporting business entity, etc.)
- Register of obligations owned per Part
- Assuming the Act does not apply without a per-Part scoping analysis
Cyber Security Act 2024: Ransomware Reporting Obligations
The ransomware payment report must contain the prescribed information, including details of the incident, the demand, the payment made and the entity to which it was made.
- Report template capturing all prescribed content fields
- Evidence the report content matches the incident record
- Incomplete report content
- Inconsistent incident and report details
Information in a ransomware payment report is subject to restrictions on how it may be used and disclosed, limiting its use against the reporting entity and supporting candid reporting.
- Awareness of the limited-use protections attaching to ransomware reports
- Withholding a report due to misunderstanding the protections
A reporting business entity that makes, or whose entity makes on its behalf, a ransomware or cyber-extortion payment in response to a cyber security incident must report the payment to the designated Commonwealth body within 72 hours of making the payment or becoming aware it was made.
- Ransomware-payment reporting procedure with the 72-hour deadline
- Determination of reporting-business-entity status (turnover threshold)
- Log of any payments and the reports made
- No process to report a ransomware payment within 72 hours
- Unaware of reporting-business-entity status
- Paying without an internal authorisation and reporting workflow
Cyber Security Act 2024: Regulatory Powers and Interactions
The Act operates alongside the Security of Critical Infrastructure Act 2018 (as amended by the 2024 package) and other Commonwealth laws; entities subject to both must meet each set of obligations.
- Combined obligation map across the Cyber Security Act, SOCI Act/CIRMP and the Privacy Act
- Single register reconciling overlapping incident-reporting duties
- Treating SOCI/CIRMP compliance as satisfying the Cyber Security Act, or vice versa
The Act applies the Regulatory Powers (Standard Provisions) Act monitoring and investigation powers, and provides for infringement notices for certain contraventions.
- Readiness to support monitoring/investigation activity
- Records demonstrating compliance with each obligation
- No retained evidence of compliance for regulator inspection
The Act creates civil penalty provisions and provides for enforceable undertakings for contraventions of its obligations.
- Risk assessment of civil-penalty exposure under the Act
- Compliance evidence available in the event of regulatory action
- Underestimating civil-penalty exposure
Cyber Security Act 2024: Security Standards for Smart Devices
A manufacturer must provide a statement of compliance for relevant connectable products in the manner and form required, attesting that the product meets the applicable security standard.
- Statements of compliance issued for each in-scope product
- Records supporting the compliance attestation
- Missing or inaccurate statement of compliance
- Statement not in the required form
The Secretary may issue compliance notices, stop notices and recall notices for non-compliant connectable products; the entity must respond, and may seek internal review of such decisions.
- Procedure to respond to compliance/stop/recall notices
- Records of any notices received and remediation
- No process to action a compliance or stop notice
- Continuing supply after a stop notice
Manufacturers and suppliers of relevant connectable (smart/IoT) products must ensure the products comply with the mandatory security standards made under the Act before they are supplied in Australia.
- Mapping of products to the applicable security standards
- Design/test evidence that products meet the mandatory standards
- Supplying connectable products that do not meet the security standards
- No assessment of which products are in scope
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.