Australian Energy Sector Cyber Security Framework (AESCSF)
The Australian Energy Sector Cyber Security Framework is developed by the Australian Energy Market Operator (AEMO) in collaboration with the Australian Cyber Security Centre. It provides a maturity model approach to cyber security for Australia's energy sector, incorporating elements from NIST CSF, C2M2, and the ASD Essential Eight. Applies to electricity and gas market participants.
Get the official standard — this page is an AI-assisted companion tool, not a replacement for the authoritative text.
Visit aemo.com.auFramework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (11)
Asset, Change and Configuration Management
Manage IT and OT assets, configurations and changes (Domain ACM).
| Code | Title |
|---|---|
| AESCSF-ACM-1 | Asset inventory |
| AESCSF-ACM-2 | Configuration management |
| AESCSF-ACM-3 | Change management |
Australian Privacy Management
Manage personal information in line with Australian privacy obligations (Domain APM, AESCSF addition).
| Code | Title |
|---|---|
| AESCSF-APM-1 | Australian privacy management |
| AESCSF-APM-2 | Privacy breach management |
Cyber Security Program Management
Establish and govern an enterprise cyber security program (Domain CPM).
| Code | Title |
|---|---|
| AESCSF-CPM-1 | Cyber security program management |
| AESCSF-CPM-2 | Cyber security governance and strategy |
| AESCSF-CPM-3 | Cyber security architecture |
Event and Incident Response, Continuity of Operations
Detect, respond to and recover from incidents and maintain continuity (Domain IR).
| Code | Title |
|---|---|
| AESCSF-IR-1 | Incident response plan |
| AESCSF-IR-2 | Incident detection and handling |
| AESCSF-IR-3 | Continuity of operations and recovery |
| AESCSF-IR-4 | Incident reporting |
Identity and Access Management
Manage identities and control access to IT and OT (Domain IAM).
| Code | Title |
|---|---|
| AESCSF-IAM-1 | Identity management |
| AESCSF-IAM-2 | Access control |
| AESCSF-IAM-3 | Multi-factor authentication |
Information Sharing and Communications
Share cyber security information and communicate with stakeholders (Domain ISC).
| Code | Title |
|---|---|
| AESCSF-ISC-1 | Cyber security information sharing |
| AESCSF-ISC-2 | Stakeholder communications |
Risk Management
Establish and manage a cyber security risk management program for IT and OT (Domain RM).
| Code | Title |
|---|---|
| AESCSF-RM-1 | Establish cyber security risk management strategy |
| AESCSF-RM-2 | Identify and assess cyber risks |
| AESCSF-RM-3 | Manage and treat cyber risks |
Situational Awareness
Establish situational awareness through logging, monitoring and a common operating picture (Domain SA).
| Code | Title |
|---|---|
| AESCSF-SA-1 | Logging and monitoring |
| AESCSF-SA-2 | Anomaly and event detection |
| AESCSF-SA-3 | Common operating picture |
Supply Chain and External Dependencies Management
Manage cyber risks from suppliers and external dependencies (Domain EDM).
| Code | Title |
|---|---|
| AESCSF-EDM-1 | Supply chain risk management |
| AESCSF-EDM-2 | External dependency assessment |
| AESCSF-EDM-3 | Dependency resilience |
Threat and Vulnerability Management
Identify and manage threats and vulnerabilities (Domain TVM).
| Code | Title |
|---|---|
| AESCSF-TVM-1 | Vulnerability management |
| AESCSF-TVM-2 | Threat management |
| AESCSF-TVM-3 | Patch and remediation management |
Workforce Management
Manage the cyber security workforce, training and personnel security (Domain WM).
| Code | Title |
|---|---|
| AESCSF-WM-1 | Cyber security workforce management |
| AESCSF-WM-2 | Training and awareness |
| AESCSF-WM-3 | Personnel security |
Your Compliance Coverage
If you comply with Australian Energy Sector Cyber Security Framework (AESCSF), you already cover:
NIST Cybersecurity Framework 2.0
59%
19 controls mapped
Compare →NIST SP 800-53 Rev 5
28%
9 controls mapped
Compare →ISO 27018:2019
9%
3 controls mapped
Compare →+ 10 more: ISO 27002:2022 (9%), Australian Privacy Principles (APPs) (6%)
See all 13 mapped frameworks ↓Maps to 13 other frameworks
Frequently Asked Questions
What is Australian Energy Sector Cyber Security Framework (AESCSF)?
Australian Energy Sector Cyber Security Framework (AESCSF) is a compliance framework from Australia with 11 domains and 32 controls. The Australian Energy Sector Cyber Security Framework is developed by the Australian Energy Market Operator (AEMO) in collaboration with the Australian Cyber Security Centre. It provides a maturity model approach to cyber security for Australia's energy sector, incorporating elements from NIST CSF, C2M2, and the ASD Essential Eight. Applies to electricity and gas market participants. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does Australian Energy Sector Cyber Security Framework (AESCSF) have?
Australian Energy Sector Cyber Security Framework (AESCSF) has 32 controls organised across 11 domains. The largest domains are Event and Incident Response, Continuity of Operations (4 controls), Asset, Change and Configuration Management (3 controls), Cyber Security Program Management (3 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does Australian Energy Sector Cyber Security Framework (AESCSF) map to?
Australian Energy Sector Cyber Security Framework (AESCSF) maps to 13 other compliance frameworks. The top mapping partners are NIST Cybersecurity Framework 2.0 (59% coverage), NIST SP 800-53 Rev 5 (28% coverage), ISO 27018:2019 (9% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with Australian Energy Sector Cyber Security Framework (AESCSF) compliance?
Start your Australian Energy Sector Cyber Security Framework (AESCSF) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Australian Energy Sector Cyber Security Framework (AESCSF) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 32 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 718 frameworks.
Get Started Free →Free forever — no credit card required