Back to Frameworks

Cyber Security Act 2024 (Australia)

Australia
v2024
6 domains
17 controls

Australia's first standalone cyber security legislation introducing mandatory security standards for smart devices, ransomware payment reporting, limited use obligations for ASD-shared information, and a Cyber Incident Review Board.

Unverified

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (6)

Cyber Security Act 2024: Coordination and Limited Use

3 controls
Controls in the Cyber Security Act 2024: Coordination and Limited Use domain of Cyber Security Act 2024 (Australia)3 controls
CodeTitle
AUCSA-LU-INTERACTInteraction with other reporting requirements
AUCSA-LU-LIMITEDLimited use obligation on shared incident information
AUCSA-LU-SHAREVoluntary information sharing with the National Cyber Security Coordinator

Cyber Security Act 2024: Cyber Incident Review Board

4 controls
Controls in the Cyber Security Act 2024: Cyber Incident Review Board domain of Cyber Security Act 2024 (Australia)4 controls
CodeTitle
AUCSA-CIRB-ESTEstablishment, functions and powers of the Cyber Incident Review Board
AUCSA-CIRB-INFOCompulsory information production and protection of review information
AUCSA-CIRB-REVIEWConduct of no-fault post-incident reviews
AUCSA-CIRB-RPTBoard reports and recommendations

Cyber Security Act 2024: Preliminary and Objects

1 controls
Controls in the Cyber Security Act 2024: Preliminary and Objects domain of Cyber Security Act 2024 (Australia)1 controls
CodeTitle
AUCSA-P1-OBJObjects and application of the Act

Cyber Security Act 2024: Ransomware Reporting Obligations

3 controls
Controls in the Cyber Security Act 2024: Ransomware Reporting Obligations domain of Cyber Security Act 2024 (Australia)3 controls
CodeTitle
AUCSA-RAN-CONTENTContent of a ransomware payment report
AUCSA-RAN-PROTLimited use and protection of ransomware report information
AUCSA-RAN-RPTRansomware and cyber-extortion payment reporting obligation

Cyber Security Act 2024: Regulatory Powers and Interactions

3 controls
Controls in the Cyber Security Act 2024: Regulatory Powers and Interactions domain of Cyber Security Act 2024 (Australia)3 controls
CodeTitle
AUCSA-INT-SOCIInteraction with the SOCI Act and other laws
AUCSA-REG-MONMonitoring, investigation and infringement notices
AUCSA-REG-PENCivil penalty provisions and enforceable undertakings

Cyber Security Act 2024: Security Standards for Smart Devices

3 controls
Controls in the Cyber Security Act 2024: Security Standards for Smart Devices domain of Cyber Security Act 2024 (Australia)3 controls
CodeTitle
AUCSA-IOT-COCStatement of compliance for connectable products
AUCSA-IOT-ENFCompliance, stop and recall notices for smart devices
AUCSA-IOT-STDSecurity standards for relevant connectable products

Maps to 2 other frameworks

17 total controls
Critical Infrastructure Risk Management Program (CIRMP) Rules 2023
2 source controls mapped|2 target controls covered
12%
NIST Cybersecurity Framework 2.0
2 source controls mapped|2 target controls covered
12%

Frequently Asked Questions

What is Cyber Security Act 2024 (Australia)?

Cyber Security Act 2024 (Australia) is a compliance framework from Australia with 6 domains and 17 controls. Australia's first standalone cyber security legislation introducing mandatory security standards for smart devices, ransomware payment reporting, limited use obligations for ASD-shared information, and a Cyber Incident Review Board. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

How many controls does Cyber Security Act 2024 (Australia) have?

Cyber Security Act 2024 (Australia) has 17 controls organised across 6 domains. The largest domains are Cyber Security Act 2024: Cyber Incident Review Board (4 controls), Cyber Security Act 2024: Coordination and Limited Use (3 controls), Cyber Security Act 2024: Ransomware Reporting Obligations (3 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

What frameworks does Cyber Security Act 2024 (Australia) map to?

Cyber Security Act 2024 (Australia) maps to 2 other compliance frameworks. The top mapping partners are Critical Infrastructure Risk Management Program (CIRMP) Rules 2023 (12% coverage), NIST Cybersecurity Framework 2.0 (12% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I get started with Cyber Security Act 2024 (Australia) compliance?

Start your Cyber Security Act 2024 (Australia) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Cyber Security Act 2024 (Australia) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 17 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 700 frameworks.

Get Started Free →

Free forever — no credit card required