Barrister AI
All legislation
COMMONWEALTHAct
In force
This is the latest official compilation.Check the official source →
s 35

Impacted entity may voluntarily provide information to National Cyber Security Coordinator in relation to a significant cyber security incident

In force
Part 4Coordination of significant cyber security incidents
Division 2Voluntary information sharing with the National Cyber Security Coordinator

35 Impacted entity may voluntarily provide information to National Cyber Security Coordinator in relation to a significant cyber security incident

(1)

This section applies if:

(a)

an incident has occurred, is occurring or is imminent; and

(b)

the incident is a cyber security incident; and

(c)

the incident has had, is having, or could reasonably be expected to have, a direct or indirect impact on an entity (the impacted entity); and

(d)

the impacted entity is:

(i)

carrying on a business in Australia; or

(ii)

a responsible entity for a critical infrastructure asset to which the Security of Critical Infrastructure Act 2018 applies.

(2)

The impacted entity, or another entity acting on behalf of the impacted entity, may provide information about the incident to the National Cyber Security Coordinator if:

(a)

the incident is a significant cyber security incident; or

(b)

the incident could reasonably be expected to be a significant cyber security incident.

Note 1:

For information provided in relation to other kinds of cyber security incidents: see sections 36 and 39.

Note 2:

This subsection constitutes an authorisation for the National Cyber Security Coordinator to collect the information (including sensitive information) for the purposes of the Privacy Act 1988.

(3)

Information about the incident may be provided under subsection (2):

(a)

at any time during the response to the incident; and

(b)

on the impacted entity’s own initiative or in response to a request by the National Cyber Security Coordinator.

Note:

There is no obligation on the impacted entity to provide information in response to a request.

Presumption

(4)

For the purposes of paragraph (1)(b), an incident (other than an incident covered by paragraph 9(2)(a) or (b)) is presumed to be a cyber security incident if:

(a)

the incident was probably effected, is probably being effected or could reasonably be expected to be effected, by means of a telegraphic, telephonic or other like service within the meaning of paragraph 51(v) of the Constitution (including, for example, by means of the internet); or

(b)

the incident has probably impeded or impaired, or is probably impeding or impairing or could reasonably be expected to impede or impair, the ability of a computer to connect to such a service; or

(c)

the incident has probably seriously prejudiced, is probably seriously prejudicing, or could reasonably be expected to prejudice:

(i)

the social or economic stability of Australia or its people; or

(ii)

the defence of Australia; or

(iii)

national security.

Note:

Paragraphs 9(2)(a) and (b) covers incidents involving critical infrastructure assets or the activities of corporations to which paragraph 51(xx) of the Constitution applies.

(5)

However, subsection (4) does not make an entity liable to a civil penalty under this Part if the incident:

(a)

was not in fact effected by means of a telegraphic, telephonic or other like service within the meaning of paragraph 51(v) of the Constitution (including, for example, by means of the internet); or

(b)

did not in fact impede or impair the ability of a computer to connect to such a service; or

(c)

did not in fact seriously prejudice:

(i)

the social or economic stability of Australia or its people; or

(ii)

the defence of Australia; or

(iii)

national security.

Research tools for this sectionPro

The statute text is free to read above. View Pro plans to unlock the case-law research tools for each provision.