Back to Frameworks

Australian Energy Sector Cyber Security Framework (AESCSF)

Australia
v2024
11 domains
32 controls

The Australian Energy Sector Cyber Security Framework is developed by the Australian Energy Market Operator (AEMO) in collaboration with the Australian Cyber Security Centre. It provides a maturity model approach to cyber security for Australia's energy sector, incorporating elements from NIST CSF, C2M2, and the ASD Essential Eight. Applies to electricity and gas market participants.

Verified

Get the official standard — this page is an AI-assisted companion tool, not a replacement for the authoritative text.

Visit aemo.com.au

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (11)

Asset, Change and Configuration Management

3 controls

Manage IT and OT assets, configurations and changes (Domain ACM).

Controls in the Asset, Change and Configuration Management domain of Australian Energy Sector Cyber Security Framework (AESCSF)3 controls
CodeTitle
AESCSF-ACM-1Asset inventory
AESCSF-ACM-2Configuration management
AESCSF-ACM-3Change management

Australian Privacy Management

2 controls

Manage personal information in line with Australian privacy obligations (Domain APM, AESCSF addition).

Controls in the Australian Privacy Management domain of Australian Energy Sector Cyber Security Framework (AESCSF)2 controls
CodeTitle
AESCSF-APM-1Australian privacy management
AESCSF-APM-2Privacy breach management

Cyber Security Program Management

3 controls

Establish and govern an enterprise cyber security program (Domain CPM).

Controls in the Cyber Security Program Management domain of Australian Energy Sector Cyber Security Framework (AESCSF)3 controls
CodeTitle
AESCSF-CPM-1Cyber security program management
AESCSF-CPM-2Cyber security governance and strategy
AESCSF-CPM-3Cyber security architecture

Event and Incident Response, Continuity of Operations

4 controls

Detect, respond to and recover from incidents and maintain continuity (Domain IR).

Controls in the Event and Incident Response, Continuity of Operations domain of Australian Energy Sector Cyber Security Framework (AESCSF)4 controls
CodeTitle
AESCSF-IR-1Incident response plan
AESCSF-IR-2Incident detection and handling
AESCSF-IR-3Continuity of operations and recovery
AESCSF-IR-4Incident reporting

Identity and Access Management

3 controls

Manage identities and control access to IT and OT (Domain IAM).

Controls in the Identity and Access Management domain of Australian Energy Sector Cyber Security Framework (AESCSF)3 controls
CodeTitle
AESCSF-IAM-1Identity management
AESCSF-IAM-2Access control
AESCSF-IAM-3Multi-factor authentication

Information Sharing and Communications

2 controls

Share cyber security information and communicate with stakeholders (Domain ISC).

Controls in the Information Sharing and Communications domain of Australian Energy Sector Cyber Security Framework (AESCSF)2 controls
CodeTitle
AESCSF-ISC-1Cyber security information sharing
AESCSF-ISC-2Stakeholder communications

Risk Management

3 controls

Establish and manage a cyber security risk management program for IT and OT (Domain RM).

Controls in the Risk Management domain of Australian Energy Sector Cyber Security Framework (AESCSF)3 controls
CodeTitle
AESCSF-RM-1Establish cyber security risk management strategy
AESCSF-RM-2Identify and assess cyber risks
AESCSF-RM-3Manage and treat cyber risks

Situational Awareness

3 controls

Establish situational awareness through logging, monitoring and a common operating picture (Domain SA).

Controls in the Situational Awareness domain of Australian Energy Sector Cyber Security Framework (AESCSF)3 controls
CodeTitle
AESCSF-SA-1Logging and monitoring
AESCSF-SA-2Anomaly and event detection
AESCSF-SA-3Common operating picture

Supply Chain and External Dependencies Management

3 controls

Manage cyber risks from suppliers and external dependencies (Domain EDM).

Controls in the Supply Chain and External Dependencies Management domain of Australian Energy Sector Cyber Security Framework (AESCSF)3 controls
CodeTitle
AESCSF-EDM-1Supply chain risk management
AESCSF-EDM-2External dependency assessment
AESCSF-EDM-3Dependency resilience

Threat and Vulnerability Management

3 controls

Identify and manage threats and vulnerabilities (Domain TVM).

Controls in the Threat and Vulnerability Management domain of Australian Energy Sector Cyber Security Framework (AESCSF)3 controls
CodeTitle
AESCSF-TVM-1Vulnerability management
AESCSF-TVM-2Threat management
AESCSF-TVM-3Patch and remediation management

Workforce Management

3 controls

Manage the cyber security workforce, training and personnel security (Domain WM).

Controls in the Workforce Management domain of Australian Energy Sector Cyber Security Framework (AESCSF)3 controls
CodeTitle
AESCSF-WM-1Cyber security workforce management
AESCSF-WM-2Training and awareness
AESCSF-WM-3Personnel security

Your Compliance Coverage

If you comply with Australian Energy Sector Cyber Security Framework (AESCSF), you already cover:

Maps to 13 other frameworks

32 total controls
NIST Cybersecurity Framework 2.0
19 source controls mapped|19 target controls covered
59%
NIST SP 800-53 Rev 5
9 source controls mapped|10 target controls covered
28%
ISO 27018:2019
3 source controls mapped|3 target controls covered
9%
ISO 27002:2022
3 source controls mapped|3 target controls covered
9%
Australian Privacy Principles (APPs)
2 source controls mapped|2 target controls covered
6%
ISO 27701:2019
2 source controls mapped|2 target controls covered
6%
ACSC Essential Eight
2 source controls mapped|3 target controls covered
6%
ISO 27001:2022
2 source controls mapped|2 target controls covered
6%
ISO 37001:2016
1 source controls mapped|1 target controls covered
3%
ISO 27017:2015
1 source controls mapped|1 target controls covered
3%
ISO 45001:2018
1 source controls mapped|2 target controls covered
3%
ISO 55001:2014
1 source controls mapped|1 target controls covered
3%
ISO 10007:2017
1 source controls mapped|1 target controls covered
3%

Frequently Asked Questions

What is Australian Energy Sector Cyber Security Framework (AESCSF)?

Australian Energy Sector Cyber Security Framework (AESCSF) is a compliance framework from Australia with 11 domains and 32 controls. The Australian Energy Sector Cyber Security Framework is developed by the Australian Energy Market Operator (AEMO) in collaboration with the Australian Cyber Security Centre. It provides a maturity model approach to cyber security for Australia's energy sector, incorporating elements from NIST CSF, C2M2, and the ASD Essential Eight. Applies to electricity and gas market participants. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

How many controls does Australian Energy Sector Cyber Security Framework (AESCSF) have?

Australian Energy Sector Cyber Security Framework (AESCSF) has 32 controls organised across 11 domains. The largest domains are Event and Incident Response, Continuity of Operations (4 controls), Asset, Change and Configuration Management (3 controls), Cyber Security Program Management (3 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

What frameworks does Australian Energy Sector Cyber Security Framework (AESCSF) map to?

Australian Energy Sector Cyber Security Framework (AESCSF) maps to 13 other compliance frameworks. The top mapping partners are NIST Cybersecurity Framework 2.0 (59% coverage), NIST SP 800-53 Rev 5 (28% coverage), ISO 27018:2019 (9% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I get started with Australian Energy Sector Cyber Security Framework (AESCSF) compliance?

Start your Australian Energy Sector Cyber Security Framework (AESCSF) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Australian Energy Sector Cyber Security Framework (AESCSF) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 32 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 718 frameworks.

Get Started Free →

Free forever — no credit card required