Impacted entity may voluntarily provide information to National Cyber Security Coordinator in relation to a significant cyber security incident
35 Impacted entity may voluntarily provide information to National Cyber Security Coordinator in relation to a significant cyber security incident
This section applies if:
an incident has occurred, is occurring or is imminent; and
the incident is a cyber security incident; and
the incident has had, is having, or could reasonably be expected to have, a direct or indirect impact on an entity (the impacted entity); and
the impacted entity is:
carrying on a business in Australia; or
a responsible entity for a critical infrastructure asset to which the Security of Critical Infrastructure Act 2018 applies.
The impacted entity, or another entity acting on behalf of the impacted entity, may provide information about the incident to the National Cyber Security Coordinator if:
the incident is a significant cyber security incident; or
the incident could reasonably be expected to be a significant cyber security incident.
For information provided in relation to other kinds of cyber security incidents: see sections 36 and 39.
This subsection constitutes an authorisation for the National Cyber Security Coordinator to collect the information (including sensitive information) for the purposes of the Privacy Act 1988.
Information about the incident may be provided under subsection (2):
at any time during the response to the incident; and
on the impacted entity’s own initiative or in response to a request by the National Cyber Security Coordinator.
There is no obligation on the impacted entity to provide information in response to a request.
Presumption
For the purposes of paragraph (1)(b), an incident (other than an incident covered by paragraph 9(2)(a) or (b)) is presumed to be a cyber security incident if:
the incident was probably effected, is probably being effected or could reasonably be expected to be effected, by means of a telegraphic, telephonic or other like service within the meaning of paragraph 51(v) of the Constitution (including, for example, by means of the internet); or
the incident has probably impeded or impaired, or is probably impeding or impairing or could reasonably be expected to impede or impair, the ability of a computer to connect to such a service; or
the incident has probably seriously prejudiced, is probably seriously prejudicing, or could reasonably be expected to prejudice:
the social or economic stability of Australia or its people; or
the defence of Australia; or
national security.
Paragraphs 9(2)(a) and (b) covers incidents involving critical infrastructure assets or the activities of corporations to which paragraph 51(xx) of the Constitution applies.
However, subsection (4) does not make an entity liable to a civil penalty under this Part if the incident:
was not in fact effected by means of a telegraphic, telephonic or other like service within the meaning of paragraph 51(v) of the Constitution (including, for example, by means of the internet); or
did not in fact impede or impair the ability of a computer to connect to such a service; or
did not in fact seriously prejudice:
the social or economic stability of Australia or its people; or
the defence of Australia; or
national security.
The statute text is free to read above. View Pro plans to unlock the case-law research tools for each provision.