Regulation 8
Cybersecurity risk assessment
Subregulation 1
For the purposes of section 16J(1)(b) of the Act, a designated provider responsible for third‑party‑owned critical information infrastructure must obtain from the owner of the third‑party‑owned critical information structure a legally binding commitment that a cybersecurity risk assessment will be conducted in the following form and manner:
that the assessment will —
identify, as far as is reasonably practicable, every cybersecurity risk to the third‑party‑owned critical information infrastructure;
evaluate the likelihood of the occurrence, and the possible consequences, of the materialisation of each identified cybersecurity risk; and
identify the actions that will be taken in respect of each identified cybersecurity risk by any of the following:
the designated provider of the third‑party‑owned critical information infrastructure;
the owner of the third‑party‑owned critical information infrastructure;
that the report of the assessment will include the following:
the methodology used in the cybersecurity risk assessment;
a description of every identified cybersecurity risk to the third‑party‑owned critical information infrastructure;
the evaluated likelihood and possible consequences of the materialisation of each identified cybersecurity risk;
the identified action that will be taken in respect of each identified cybersecurity risk by the designated provider, or owner, of the third‑party‑owned critical information infrastructure, as the case may be.
Subregulation 2
A designated provider responsible for third‑party‑owned critical information infrastructure must obtain from the owner of the third‑party‑owned critical information structure a legally binding commitment that the first cybersecurity risk assessment of the third‑party‑owned critical information infrastructure will be completed within 6 months after the date of the notice issued under section 16A(1) of the Act or, subject to section 16J(1)(b) of the Act, any longer period that the Commissioner may allow in a particular case.
Subregulation 3
In this regulation, “cybersecurity risk”, in relation to third‑party‑owned critical information infrastructure, means the risk that a vulnerability in the cybersecurity of the third‑party‑owned critical information infrastructure may be exploited by a cybersecurity threat or incident.