Requirement 0028 (Part One: Governance, section 3.6.3 Security Planning, Incidents and Training; applies to All entities; dated 31 October 2024; retained from Release 2025): Significant or externally reportable security incidents and referral obligations are reported to the relevant authority (or authorities) within the applicable timeframe. Table 2 lists reporting to Home Affairs (significant incidents, FOCI risks), ASIO (national security incidents via NITRO, contact reporting), ASD/ACSC (cyber incidents), PM&C (Cabinet material), the Authorised Vetting Agency (incidents involving clearance holders), affected entities, SCEC (couriers, equipment), originating foreign governments, the OAIC (eligible data breaches), the AFP or police (crimes) and the National Situation Room (critical incidents). Where no timeframe is set, report on becoming aware.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.