Australian Energy Sector Cyber Security Framework (AESCSF)
The Australian Energy Sector Cyber Security Framework is developed by the Australian Energy Market Operator (AEMO) in collaboration with the Australian Cyber Security Centre. It provides a maturity model approach to cyber security for Australia's energy sector, incorporating elements from NIST CSF, C2M2, and the ASD Essential Eight. Applies to electricity and gas market participants.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (7)
Asset, Change, and Configuration Management
Managing the inventory and configuration of IT and OT assets
| Code | Title |
|---|---|
| AESCSF-ACM-1 | Asset Inventory |
| AESCSF-ACM-2 | Configuration Management |
| AESCSF-ACM-3 | Change Management |
Event and Incident Response
Responding to and recovering from cyber security incidents
| Code | Title |
|---|---|
| AESCSF-IR-1 | Incident Response Plan |
| AESCSF-IR-2 | Incident Response Capability |
| AESCSF-IR-3 | Incident Reporting |
| AESCSF-IR-4 | Lessons Learned |
Identity and Access Management
Managing identities and access to IT and OT systems
| Code | Title |
|---|---|
| AESCSF-IAM-1 | Identity Management |
| AESCSF-IAM-2 | Access Control |
| AESCSF-IAM-3 | Multi-Factor Authentication |
Risk Management
Establishing and maintaining a cyber security risk management program
| Code | Title |
|---|---|
| AASB-S2-25a | Risk Identification and Assessment Processes |
| AASB-S2-25b | Opportunity Identification Processes |
| AASB-S2-25c | Integration with Overall Risk Management |
| AESCSF-RM-1 | Cyber Security Risk Management Strategy |
| AESCSF-RM-2 | Risk Assessment Process |
| AESCSF-RM-3 | Risk Response and Mitigation |
| AESCSF-RM-4 | Risk Management Integration |
| CDP-RM-1 | Risk Identification Process |
| CDP-RM-2 | Dependencies and Impacts Assessment |
| CDP-RM-3 | Value Chain Risk Assessment |
| FAA-CS-3.1 | Data-Driven Risk Management |
| FAA-CS-3.2 | Supply Chain Risk Management |
| FAA-CS-3.3 | Vulnerability Assessment |
| GAMP5-1.1 | Risk-Based Approach |
| GAMP5-1.2 | Patient Safety Risk Assessment |
| GAMP5-1.3 | Functional Risk Assessment |
Situational Awareness and Event Management
Monitoring and detecting cyber security events
| Code | Title |
|---|---|
| AESCSF-SA-1 | Logging and Monitoring |
| AESCSF-SA-2 | Anomaly Detection |
| AESCSF-SA-3 | Information Sharing |
Supply Chain and Dependencies
Risks related to third-party components and software supply chain
| Code | Title |
|---|---|
| A03:2025 | Software Supply Chain Failures |
| AESCSF-SC-1 | Supply Chain Risk Management |
| AESCSF-SC-2 | Third-Party Assessment |
| AESCSF-SC-3 | Dependency Mapping |
Threat and Vulnerability Management
Vulnerability management, penetration testing, and DevSecOps
| Code | Title |
|---|---|
| AESCSF-TVM-1 | Vulnerability Assessment |
| AESCSF-TVM-2 | Threat Intelligence |
| AESCSF-TVM-3 | Patch Management |
| CSA-TVM-01 | Vulnerability Management |
| CSA-TVM-02 | Penetration Testing |
| CSA-TVM-03 | Application Security (DevSecOps) |
Maps to 578 other frameworks
Frequently Asked Questions
What is Australian Energy Sector Cyber Security Framework (AESCSF)?
Australian Energy Sector Cyber Security Framework (AESCSF) is a compliance framework from Australia with 7 domains and 39 controls. The Australian Energy Sector Cyber Security Framework is developed by the Australian Energy Market Operator (AEMO) in collaboration with the Australian Cyber Security Centre. It provides a maturity model approach to cyber security for Australia's energy sector, incorporating elements from NIST CSF, C2M2, and the ASD Essential Eight. Applies to electricity and gas market participants. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does Australian Energy Sector Cyber Security Framework (AESCSF) have?
Australian Energy Sector Cyber Security Framework (AESCSF) has 39 controls organised across 7 domains. The largest domains are Risk Management (16 controls), Threat and Vulnerability Management (6 controls), Event and Incident Response (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does Australian Energy Sector Cyber Security Framework (AESCSF) map to?
Australian Energy Sector Cyber Security Framework (AESCSF) maps to 578 other compliance frameworks. The top mapping partners are CSA CCM v4 (62% coverage), TISAX — Trusted Information Security Assessment Exchange (56% coverage), NIST SP 800-82 Rev 3 — Guide to OT Security (56% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with Australian Energy Sector Cyber Security Framework (AESCSF) compliance?
Start your Australian Energy Sector Cyber Security Framework (AESCSF) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Australian Energy Sector Cyber Security Framework (AESCSF) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 39 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 692 frameworks.
Get Started Free →Free forever — no credit card required