What records should teams keep under the Australia Cyber Security Act 2024?
For smart devices, manufacturers and suppliers must keep the statement of compliance for the five-year period set by the Rules. The statement must identify the product type and batch, the manufacturer, an authorised representative, and any other authorised representatives in Australia, as well as compliance declarations, the defined support period, signatory details, and the place and date of issue. Keeping the product evidence behind the statement is a practical way to support those declarations, but the cited Rules prescribe the five-year period for the statement rather than every supporting record.
For ransomware payment reporting, keep a report file that can show whether the entity was a reporting business entity, when the payment was made or discovered, what information was known or findable by reasonable search or enquiry within the 72-hour reporting period, and what was submitted to the designated Commonwealth body. The Act and ransomware reporting rules do not prescribe a retention period for that report file. Retaining it with the source evidence is an operational recommendation, subject to other applicable legal, security, privacy, and records-management requirements.
- Smart-device evidence: product and batch identifier, manufacturer details, an authorised representative, any other authorised representatives in Australia, compliance declaration, defined support period, signatory, place and date of issue, and the retained statement.
- Ransomware report evidence: reporting-entity analysis, incident timing and awareness timing, infrastructure and customer impact, ransomware or malware variant, exploited vulnerabilities, demand amount or benefit, payment amount or benefit, method of provision, and communications with the extorting entity.
- Overlap evidence: record SOCI status only where the entity is a responsible entity for a Part 2B critical infrastructure asset, and record APRA status only where the organisation is APRA-regulated under CPS 234.
Supports the smart-device statement contents and the five-year retention period for statements of compliance.
Supports the ransomware report content fields and the reasonable-search limit within the 72-hour reporting period.
Supports the Cyber Security Act Part 3 duty to give a ransomware payment report within 72 hours.