Protective Security Policy Framework (PSPF) Release 2026
Part One: Governance (sections 1 to 4) – Protective Security Policy Framework (PSPF) Release 2026

Protective Security Policy Framework (PSPF) Release 2026 0028: 0028 Report significant and externally reportable incidents within timeframes

Requirement 0028 (Part One: Governance, section 3.6.3 Security Planning, Incidents and Training; applies to All entities; dated 31 October 2024; retained from Release 2025): Significant or externally reportable security incidents and referral obligations are reported to the relevant authority (or authorities) within the applicable timeframe. Table 2 lists reporting to Home Affairs (significant incidents, FOCI risks), ASIO (national security incidents via NITRO, contact reporting), ASD/ACSC (cyber incidents), PM&C (Cabinet material), the Authorised Vetting Agency (incidents involving clearance holders), affected entities, SCEC (couriers, equipment), originating foreign governments, the OAIC (eligible data breaches), the AFP or police (crimes) and the National Situation Room (critical incidents). Where no timeframe is set, report on becoming aware.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Other controls in Part One: Governance (sections 1 to 4) – Protective Security Policy Framework (PSPF) Release 2026

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.