# 10 Meaning of permitted cyber security purpose

Each of the following is a ***permitted cyber security purpose*** for a cyber security incident:

- (a) the performance of the functions of a Commonwealth body (to the extent that it is not a Commonwealth enforcement body) relating to responding to, mitigating or resolving the cyber security incident;
- (b) the performance of the functions of a State body relating to responding to, mitigating or resolving the cyber security incident;
- (c) the performance of the functions of the National Cyber Security Coordinator under Part 4 relating to the cyber security incident;
- (d) informing and advising the Minister, and other Ministers of the Commonwealth, about the cyber security incident;
- (e) preventing or mitigating material risks that the cyber security incident has seriously prejudiced, is seriously prejudicing, or could reasonably be expected to prejudice:
  - (i) the social or economic stability of Australia or its people; or
  - (ii) the defence of Australia; or
  - (iii) national security;
- (f) preventing or mitigating material risks to a critical infrastructure asset;
- (g) the performance of the functions of an intelligence agency;
- (h) the performance of the functions of a Commonwealth enforcement body.

Note 1: There are some limitations in relation to civil or regulatory functions against entities that have provided information in relation to the incident: see subsections 38(2) and 39(3).

Note 2: Certain information must not be disclosed to a State body under Parts of this Act unless a Minister of the State or Territory has consented to those Parts applying to the State body: see section 11.
