Meaning of permitted cyber security purpose
10 Meaning of permitted cyber security purpose
Each of the following is a permitted cyber security purpose for a cyber security incident:
the performance of the functions of a Commonwealth body (to the extent that it is not a Commonwealth enforcement body) relating to responding to, mitigating or resolving the cyber security incident;
the performance of the functions of a State body relating to responding to, mitigating or resolving the cyber security incident;
the performance of the functions of the National Cyber Security Coordinator under Part 4 relating to the cyber security incident;
informing and advising the Minister, and other Ministers of the Commonwealth, about the cyber security incident;
preventing or mitigating material risks that the cyber security incident has seriously prejudiced, is seriously prejudicing, or could reasonably be expected to prejudice:
the social or economic stability of Australia or its people; or
the defence of Australia; or
national security;
preventing or mitigating material risks to a critical infrastructure asset;
the performance of the functions of an intelligence agency;
the performance of the functions of a Commonwealth enforcement body.
There are some limitations in relation to civil or regulatory functions against entities that have provided information in relation to the incident: see subsections 38(2) and 39(3).
Certain information must not be disclosed to a State body under Parts of this Act unless a Minister of the State or Territory has consented to those Parts applying to the State body: see section 11.
The statute text is free to read above. View Pro plans to unlock the case-law research tools for each provision.