Skip to content
Legislation
Skip to legislation

Cyber Security Act 2024 · Version 2024-11-29

Division 2—Reviews

Register source version C2024A00098 · Source observation:

Reading presentation · Verification limits and dated status · No live currency check

Part 5—Cyber Incident Review Board

Read this container only

Division 2—Reviews

Read this container only

46 Board must cause reviews to be conducted

  • (1) The Cyber Incident Review Board may cause a review to be conducted under this section in relation to a cyber security incident, or a series of related cyber security incidents, on written referral by:
  • (a) the Minister; or
  • (b) the National Cyber Security Coordinator; or
  • (c) an entity impacted by the incident or an incident in the series of incidents; or
  • (d) a member of the Board.

Note: Each review is conducted by a particular review panel established for that review in accordance with the terms of reference for the review.

  • (2) A review may only be conducted under this section:
  • (a) if the Board is satisfied that the incident or series of incidents meets the criteria mentioned in subsection (3); and
  • (b) after the incident or series of incidents, and the immediate response, has ended; and
  • (c) if the Minister has approved the terms of reference for the review.
  • (3) For the purposes of paragraph (2)(a), the criteria are:
  • (a) the incident or series of incidents have seriously prejudiced, or could reasonably be expected to seriously prejudice:
    • (i) the social or economic stability of Australia or its people; or
    • (ii) the defence of Australia; or
    • (iii) national security; or
  • (b) the incident or series of incidents involved novel or complex methods or technologies, an understanding of which will significantly improve Australia’s preparedness, resilience, or response to cyber security incidents of a similar nature; or
  • (c) the incident or series of incidents are, or could reasonably be expected to be, of serious concern to the Australian people.
  • (4) Each review is to be conducted by a review panel that consists of:
  • (a) the Chair; and
  • (b) the standing members of the Board that are specified in the terms of reference for the review; and
  • (c) the members of the Expert Panel appointed to assist in the review under section 70.

The terms of reference for the review must specify one or more standing members for the review.

  • (5) The rules may make provision for or in relation to reviews under this Part, including for or in relation to the following:
  • (a) dealing with written referrals made to the Board;
  • (b) prioritisation of referrals for review and reviews conducted;
  • (c) terms of reference for reviews, including their variation;
  • (d) notification of reviews;
  • (e) the timing of when reviews may be conducted;
  • (f) when reviews may be discontinued;
  • (g) how information or submissions may be provided for reviews.

47 Board may discontinue a review

  • (1) The Board may discontinue a review at any time.
  • (2) The Board must, within 28 days of discontinuing a review, publish in any way the Board considers appropriate notice of the review being discontinued.

48 Chair may request information or documents

If the Board reasonably believes that:

  • (a) an entity; or
  • (b) a Commonwealth body or a State body; or
  • (c) an officer or employee of a Commonwealth body or a State body;

has information or documents relevant to a review being conducted under section 46 by a review panel, the Chair may request, by notice in writing, the entity, body, officer or employee to give the Board such information or documents as are specified in the request.

Note 1: There is no requirement to comply with the request.

Note 2: The Chair may require certain entities to give documents under section 49.

49 Chair may require certain entities to produce documents

  • (1) This section applies if:
  • (a) the Board reasonably believes that an entity involved in a cyber security incident that relates to a review being conducted under section 46 by a review panel has a document that is relevant to the review; and
  • (b) the Chair of the Board has requested that the entity provide the document under section 48; and
  • (c) the entity is not:
    • (i) a Commonwealth body or a State body; or
    • (ii) an officer or employee of a Commonwealth body or a State body.
  • (2) The Chair of the Board may, by notice in writing given to the entity, require the entity to:
  • (a) produce any such documents; or
  • (b) make copies of any such documents and to produce those copies;

to the Board within the period (which must not be less than 14 days), and in the manner, specified in the notice.

  • (3) The notice must set out the effect of the following provisions:
  • (a) section 50;
  • (b) Part 6 of this Act (Regulatory powers);
  • (c) sections 137.1 and 137.2 of the Criminal Code (false or misleading information or documents).

Compensation

  • (4) An entity is entitled to be paid by the Commonwealth reasonable compensation for complying with a requirement covered by paragraph (2)(b).

50 Civil penalty—failing to comply with a notice to produce documents

  • (1) An entity is liable to a civil penalty if:
  • (a) the entity is given a notice under subsection 49(2); and
  • (b) the entity fails to comply with the notice.

Civil penalty: 60 penalty units.

  • (2) Subsection (1) does not apply in relation to the production of a document or a copy of a document if the production would, or could reasonably be expected to, prejudice one or more of the following:
  • (a) the security, defence or international relations of the Commonwealth;
  • (b) the capabilities of an intelligence agency;
  • (c) the prevention, detection or investigation of, or the conduct of proceedings relating to, an offence or a contravention of a civil penalty provision;
  • (d) the administration of justice.
  • (3) Subsection 93(2) of the Regulatory Powers Act does not apply in relation to a contravention of subsection (1) of this section.
  • (4) Despite section 96 of the Regulatory Powers Act, in proceedings for a civil penalty order against an entity for a contravention of subsection (1), the entity does not bear an evidential burden in relation to the matters in subsection (2).

Note: This Act does not make the Crown (other than an authority of the Crown) liable to a civil penalty.

51 Draft review reports

  • (1) The Board must prepare a draft report (a draft review report) on a review being conducted under section 46 by a review panel.
  • (2) The draft review report must set out:
  • (a) the preliminary findings of the review; and
  • (b) a summary of the information and material on which those preliminary findings are based; and
  • (c) any recommendations the Board proposes to make; and
  • (d) if the Board proposes to make recommendations—the reasons for those proposed recommendations; and
  • (e) if the terms of reference for the review require particular information to be included in the draft review report—that information; and
  • (f) information (if any) that is prescribed by the rules; and
  • (g) such other information that the Board thinks fit to include in the draft review report.
  • (3) The Board must give the draft review report to the Minister.
  • (4) The Board may give the draft review report, or an extract of the draft review report, to any other Commonwealth body or a State body or entity:
  • (a) if the Board considers it appropriate to give the body or entity an opportunity to make submissions on the draft review report or the extract; or
  • (b) for the purposes of determining whether information proposed to be included in the final review report is sensitive review information.

Note 1: The disclosure of sensitive review information may be prohibited under another Act (for example, the Privacy Act 1988). This section does not authorise disclosure if prohibited under that Act: see subsection (7) of this section.

Note 2: Sensitive review information must be redacted from a final review report that is to be published by the Board: see section 53.

  • (5) If the Board gives a draft review report to the Minister under subsection (3), or a Commonwealth body, State body or entity under subsection (4), the Board must specify a reasonable period within which submissions may be made to the Board on the draft review report.
  • (6) Submissions must be given in the manner and form (if any) prescribed by the rules.
  • (7) However, this section does not authorise the Board to record, use or disclose the information to the extent that it is prohibited or restricted by or under the Privacy Act 1988 or any other Act.

52 Final review reports

  • (1) After a review is completed under section 46 by the review panel, the Board must prepare a report (a final review report) on the review.

Note 1: The Board must redact sensitive review information from a final review report: see section 53.

Note 2: If information is redacted from a final review report, the Board must also prepare a protected review report: see section 54.

  • (2) In preparing the final review report, the Board must consider any submissions received under section 51 in relation to the draft review report.
  • (3) Subject to section 53, the final review report must set out:
  • (a) the findings of the review; and
  • (b) a summary of the information and material on which those findings are based; and
  • (c) any recommendations made by the Board; and
  • (d) if recommendations are made—the reasons for those recommendations; and
  • (e) if the terms of reference for the review require particular information to be included in the review report—that information; and
  • (f) information (if any) that is prescribed by the rules; and
  • (g) such other information that the Board thinks fit to include in the report.
  • (4) The Board must not in the final review report:
  • (a) apportion blame in relation to a cyber security incident that was the subject of the review; or
  • (b) provide the means to determine the liability of any entity in relation to such a cyber security incident; or
  • (c) identify an individual (unless the individual has consented); or
  • (d) allow any adverse inference to be drawn from the fact that an entity is the subject of the review.

However, even though blame or liability may be inferred, or an adverse inference may be made, by a person other than the Board, this does not prevent the Board from including information in the final review report.

  • (5) This section does not otherwise limit what may be included in the final review report.
  • (6) The Board must publish the final review report (excluding any information required to be redacted under section 53). The report may be published in any way the Board considers appropriate.

53 Certain information must be redacted from final review reports

  • (1) Information must be redacted from a final review report if the Chair is satisfied that the information is sensitive review information.

Note: If information is redacted from a final review report, the Board must prepare a protected review report that includes the information, see section 54.

  • (2) Sensitive review information is information the disclosure of which:
  • (a) could prejudice the security, defence or international relations of Australia; or
  • (b) would prejudice relations between the Commonwealth government and the government of a State or Territory; or
  • (c) could reveal, or enable a person to ascertain, the existence or identity of a confidential source of information in relation to the enforcement of the criminal law; or
  • (d) could endanger a person’s life or physical safety; or
  • (e) would prejudice the fair trial of any person or the impartial adjudication of a matter; or
  • (f) would involve disclosing information whose disclosure is prohibited or restricted by or under this Act, another Act or an instrument made under an Act; or
  • (g) would involve unreasonably disclosing information that is confidential or commercially sensitive; or
  • (h) would involve the disclosure of personal information about an individual without their consent.

54 Protected review reports

  • (1) If information must be redacted from a final review report under section 53, the Board must prepare another report (a protected review report) that includes:
  • (a) the redacted information; and
  • (b) the reasons for redacting the information from the final review report.
  • (2) If a protected review report is prepared under this section, the Board must give the Minister, and the Prime Minister, a copy of:
  • (a) the final review report prepared under section 52; and
  • (b) a copy of the protected review report.
  • (3) The Minister may give a copy of the protected review report, or an extract of the protected review report, to any other Commonwealth body, a State body or an entity but only for the purposes of one or more of the following:
  • (a) the performance of the functions of a Commonwealth body relating to responding to, mitigating or resolving a cyber security incident;
  • (b) the performance of the functions of a State body relating to responding to, mitigating or resolving a cyber security incident;
  • (c) informing and advising the Minister, and other Ministers of the Commonwealth, about a cyber security incident;
  • (d) the performance of the functions of an intelligence agency.