Loncat ke konten

Understanding new obligations for SOCI with identity and governance

The Security of Critical Infrastructure Act recently added an Amendment (Enhanced Critical Infrastructure Risk Management Program) to the Rules. If you have read the previous RSA SOCI blog, this amendment sits on top of the existing Critical Infrastructure Risk Management Program Rules (CIRMP). These changes introduce a series of enhanced obligations for high-risk Critical infrastructure (CI) asset classes. These classes include broadcasting, domain name systems, electricity and energy operators, freight infrastructure and services, gas, fuel and water assets.

The new amendments cover a range of controls which must be introduced to help reduce the risk of cyber threats and protect key CI assets. Two sections—Section 8B Credential Compromise Hazards and 8C Lateral Movement Hazards—emphasize the importance of identity and access management (IAM) in keeping high-assurance organizations secure.

Organizations must implement these new controls by June 2028. While that may feel like a long way off, changing or modifying CI and OT environments requires organizations to act now to meet these new regulatory requirements.

Section 8B credential compromise hazards

Protecting CI is likely a key consideration for most of the assets listed and almost all will be operating under an existing Cyber Security Framework (CSF). The new legislation requires CI to adopt a Level Two (L2) maturity posture of either Essential 8, AESCFS, ISO27001, NIST CSF 2.0 or C2M2. Level Two maturity requires phishing resistant authentication.

This control must be applied to:

  • access to internet-connected computers and critical systems.
  • privileged and unprivileged access to critical components.
  • remote access to applications, systems or services.

Organizations should review this requirement closely, even if they believe they already have phishing-resistant MFA that meets L2 CSF requirements. Most identity vendors’ solutions depend on a cloud service, and if that cloud service goes down, users would need to authenticate with MFA protocols that don’t meet the new requirements or would not be able to authenticate at all in an isolated environment.

Cloud-only authentication services are not sufficient to support OT networks—the expanded SOCI requirements specify that organizations need to be able to isolate for up to 90 days, whilst maintaining authentication and other operations without connecting to the cloud for up to three months.

In Australia, cyber resiliency is now considered a legal security requirement, not an SLA target.

Deploy phishing-resistant MFA with RSA

RSA IDP Sovereign Deployment offers phishing resistant authentication across on-premises, air-gapped and semi air-gapped environments. The solution features a hybrid failover capability that keeps phishing-resistant MFA operational for critical infrastructure, even during cloud outages.

Section 8C lateral movement hazards

The expanded SOCI requirements also introduce several key controls CI must implement to reduce the risk of lateral movement.

One new control that will have significant impact on CI is 8C, which requires “ensuring critical systems can continue to be operational for a period of at least three months while other computers are in a state of restoration or recovery.”

This legislates the CI Fortify guideline for isolation. CI Fortify stipulates that affected industries must be able to operate the asset and provide its essential services while isolated. This doesn’t mean cyber security controls are removed in isolation, on the contrary. All controls must still operate as CI operators re-build and recover. The intention of this section addresses resiliency requirements. The requirement asks CI to continue delivering essential services after a breach has occurred.

This will pose an additional challenge for CI to meet 8B Credential Compromise Phishing Resistant Authentication requirements. Typical phishing-resistant deployments rely on cloud-only identity providers, and this is considered a third-party dependency. Sever the cloud authentication link to your isolated OT environment and you’ve locked out the operators. This slows recovery, as rebuilding systems from compromise is exactly when you need the strongest authentication and access controls.

RSA solves this problem with hybrid failover, which allows on-premise, air-gapped, phishing-resistant MFA to continue working through an isolation event and during re-build, providing strong secure authentication and access controls.

The 8C Lateral Movement Hazards section also requires least privilege and access review requirements.

Understanding who has access to what systems, managing roles, and audit compliance is key to meeting this requirement. RSA Governance and Lifecycle supports these requirements and can be deployed on premises for Critical Infrastructure environments.

To learn more about how RSA can support you to meet Section 8B and 8C of the act download the identity capability mapping requirements document.

Pertanyaan yang Sering Diajukan
What is the SOCI enhanced critical infrastructure risk management program?

The Enhanced CIRMP is a 2026 amendment to Australia’s Security of Critical Infrastructure Act that introduces mandatory cybersecurity controls for high-risk critical infrastructure asset classes. Organizations must achieve compliance by June 2028.

Which industries does the SOCI enhanced CIRMP apply to?

The amendment applies to broadcasting, domain name systems, electricity and energy operators, freight infrastructure and services, gas, fuel, and water assets—expanding the existing SOCI framework to higher-risk asset classes.

What does SOCI section 8B require?

Section 8B requires critical infrastructure to deploy phishing-resistant authentication for internet-connected systems, privileged and unprivileged access to critical components, and remote access to applications and services. Organizations must achieve at least Level 2 under a recognized cybersecurity framework such as Essential 8, NIST CSF 2.0, or ISO 27001.

Why is cloud-only MFA not sufficient for SOCI compliance?

SOCI Section 8C requires critical infrastructure to remain operational in full isolation—without cloud connectivity— or up to 90 days. Cloud-only authentication services cannot function during an isolation event, meaning operators would be locked out of the systems they need to recover. SOCI requires authentication to remain operational throughout an isolation and recovery period.

What does SOCI section 8C require to prevent lateral movement?

Section 8C requires critical infrastructure to implement least-privilege access controls, maintain access review processes, and ensure systems can continue operating for at least three months while other infrastructure is in a state of recovery. This effectively legislates the CI Fortify framework for affected organizations.

What is the compliance deadline for SOCI 8B and 8C?

Organizations must implement the new controls by June 2028. Given the complexity of OT environments and the time required to deploy on-premises, air-gapped authentication solutions, organizations should begin planning and implementation now.

What is phishing-resistant MFA and how does it differ from standard MFA?

Phishing-resistant MFA uses cryptographic methods—such as hardware security keys or FIDO2/credentials—that cannot be intercepted or replicated by attackers. Unlike SMS OTP, push notifications, or email links, phishing-resistant MFA cannot be defeated by a man-in-the-middle attack or a social engineering attempt. Essential 8 Level 2 specifically requires phishing-resistant methods for the types covered under Section 8B.

How does RSA help organizations meet SOCI 8B and 8C?

Penyebaran Sovereign RSA ID Plus provides phishing-resistant MFA across on-premises, air-gapped, and semi air-gapped environments, with hybrid failover that keeps authentication operational during cloud outages—meeting the 90-day isolation requirement. Tata Kelola & Siklus Hidup RSA supports the least-privilege and access review requirements under Section 8C, with an on-premises deployment built for critical infrastructure environments.

Cegah Ancaman Sebelum Terjadi

Kata sandi saja tidak cukup. Lihat bagaimana Otentikasi Multi-Faktor RSA mencegah serangan berbasis identitas sebelum terjadi, tanpa menimbulkan kendala bagi pengguna Anda.
Jelajahi Solusi MFA