Who needs to consider these requirements?
Map the rail service to the statutory asset definitions before designing a compliance programme. Clarify which organisation is the responsible entity and which suppliers handle business-critical data or operate supporting systems. An asset may depend on cloud services, remote maintenance and communications infrastructure even when those systems sit outside the physical railway boundary.
Key regulations and frameworks
Security of Critical Infrastructure Act 2018
Law — obligations depend on asset class
CISC's transport guidance identifies obligations that apply to most transport asset classes, including cyber incident reporting, ownership and operational information, and notification to relevant third-party data providers. It specifically identifies critical freight infrastructure and critical freight services for the Critical Infrastructure Risk Management Program obligation. Assess the applicable class and rules instead of assuming that CIRMP applies to every railway asset.
Official source: Security of Critical Infrastructure Act 2018
AS 7770 Rail Cyber Security
Industry standard — check contractual adoption
The Australian Rail Industry Standards Organisation publishes AS 7770 as a rail cyber security standard. It provides a railway-focused reference alongside the statutory framework. A standard's use in a tender, engineering process or contract should be recorded explicitly; publication of the standard does not itself mean that every Australian rail business is subject to a separate statutory certification requirement.
Practical steps for rail teams
Use these engineering and project-planning actions to prepare evidence for the requirements that apply to your organisation.
- Agree the asset classification and responsible entity with the operator, and list the SOCI obligations that follow from that assessment.
- Map business-critical data and operational dependencies across onboard systems, depots and external service providers. Include those suppliers in the incident escalation and continuity arrangements.
- Turn the selected rail standard and contract requirements into testable acceptance evidence. Rehearse a service-affecting incident and establish how its impact will be assessed for regulatory reporting.
Using this guide
This is an introduction to selected frameworks, not a complete legal assessment. Applicability depends on your organisation, systems and contracts. Check the linked official texts and obtain advice for your project before relying on a requirement or deadline.
