Safeware Glasswall APAC Partner Book a demo

Explore

What is CDRZero TrustThe detection gapCapabilitiesUse cases

Products

ProductsIntegrationFile support

Compliance

Compliance hub
Country guidesSingaporeAustraliaJapanSouth KoreaIndiaIndonesiaMalaysiaThailandVietnamPhilippinesTaiwanNew ZealandMongoliaAPAC overview

More

Trust & certificationsAboutDocumentation Book a demo

Regulatory landscape ยท Oceania

Australia: file security and audit obligations

Australia combines a broad critical-infrastructure statute with the most prescriptive technical baseline in the region: the SOCI Act sets the obligations, the Essential Eight and the ISM set the controls, and the PSPF governs government information handling.

At a glance

How Australia regulates file security

  • 01

    Regime

    Critical infrastructure statute across 22 asset classes, plus a government control baseline

  • 02

    File security

    Essential Eight application hardening and macro control; ISM content validation and conversion

  • 03

    Audit and evidence

    Mandatory incident reporting and risk management program evidence

Overview

The regulatory picture

Australia is the APAC market where a file-security control is most likely to be specified by name rather than by outcome, because the Australian Signals Directorate publishes the control set and much of government and critical infrastructure is assessed against it.

The Security of Critical Infrastructure Act 2018 (SOCI Act) is the statutory anchor. Successive amendments in 2021, 2022 and 2024 expanded it to 22 asset classes and introduced mandatory cyber incident reporting, Critical Infrastructure Risk Management Programs, enhanced obligations for systems of national significance, and government assistance powers. A 2024 amendment clarified that the Act reaches data storage systems forming part of a primary critical infrastructure asset, which pulls document repositories and file stores squarely into scope. The first independent review of the Act was delivered on 31 January 2026, and further reforms to the Ministerial Directions powers and the risk management program rules went out for consultation on 25 March 2026.

The Essential Eight and the Information Security Manual (ISM) are where file handling becomes concrete. Two of the eight mitigation strategies, user application hardening and configuring Microsoft Office macro settings, are directly about untrusted document content. The ISM's content validation and content conversion controls describe rebuilding files to a known-good state, which is CDR by another name. The PSPF governs how Australian Government entities handle and transfer official information, including between security domains.

Separately, the Cyber Security Act 2024 introduced ransomware payment reporting, which commenced 30 May 2025, and mandatory security standards for smart devices supplied to critical infrastructure operators, effective 4 March 2026. The Privacy Act 1988 reform program continues, with the Notifiable Data Breaches scheme already in force.

The landscape

Instruments that reach file security and audit

InstrumentAuthorityStatusRelevance
Security of Critical Infrastructure Act 2018 (as amended)CISCIn forceDirect
Essential Eight Maturity ModelASD/ACSCIn forceDirect
Information Security Manual (ISM)ASD/ACSCIn forceDirect
Protective Security Policy Framework (PSPF)Attorney-General's DepartmentIn forceDirect
Privacy Act 1988 and Notifiable Data Breaches schemeOAICIn forceIndirect

CISC

Security of Critical Infrastructure Act 2018 (as amended)

Covers 22 asset classes across critical sectors. Imposes asset registration, mandatory cyber incident reporting, a Critical Infrastructure Risk Management Program, and enhanced obligations for systems of national significance. A 2024 amendment clarified that data storage systems forming part of a primary asset are in scope.

Why it matters for file security. The data-storage clarification matters most. Document repositories and file shares attached to a critical asset inherit the risk management program obligations, which means the way untrusted files enter those stores becomes a registrable, reportable control rather than an IT preference.

How Glasswall addresses it. A Critical Infrastructure Risk Management Program has to describe how each material risk is mitigated, and file-borne compromise of a data storage system is one of the easier ones to describe concretely: untrusted files are rebuilt to a known-good state before they reach the store. The per-file verdict record supports the incident reporting obligation by giving you a processing history to reconstruct from when a report is required on a statutory clock.

Content Disarm and ReconstructionPer-file verdict recordStorage Monitor + SM AuditGlasswall Halo / Glasswall Meteor

Source: CISC

ASD/ACSC

Essential Eight Maturity Model

ASD's baseline of eight mitigation strategies with four maturity levels. Mandatory for non-corporate Commonwealth entities and widely adopted as a contractual baseline across state government and critical infrastructure.

Why it matters for file security. Two of the eight are file-content controls. User application hardening covers blocking active content in documents and browsers; configuring Microsoft Office macro settings covers the macro surface specifically. Both are commonly assessed by asking what happens to a document arriving from outside the organisation.

How Glasswall addresses it. CDR strips and rebuilds active content before a document reaches the desktop, which reinforces the user application hardening and Office macro strategies at the boundary rather than relying only on endpoint configuration holding. Macro intelligence inspects embedded macros and active content where an organisation has a business reason to retain some macro capability, so the control does not have to be all or nothing.

Content Disarm and ReconstructionMacro intelligenceEmail CDR RelayGlasswall Halo / Glasswall Meteor

Source: ASD/ACSC

ASD/ACSC

Information Security Manual (ISM)

ASD's control catalogue for systems handling Australian Government information, updated quarterly. Includes controls on content filtering, content validation, content conversion and gateway/cross-domain architecture.

Why it matters for file security. The content validation and content conversion controls describe rebuilding files to a known-good standard, the mechanism CDR implements. The gateway and cross-domain sections govern how content moves between security domains, which is where deterministic rebuild is effectively assumed rather than optional.

How Glasswall addresses it. Meteor deploys on-premises and in air-gapped environments, rebuilding content as it moves between security domains, which is the deployment pattern the ISM's gateway and cross-domain controls describe. Safeware prepares the trust-boundary mapping, architecture documentation and control-responsibility matrix an assessor expects. The architecture is built to be assessable; IRAP is an assessment process and we do not claim to have completed one.

Content Disarm and ReconstructionCross-domain and air-gapped transferPer-file verdict recordGlasswall Meteor

Source: ASD/ACSC

Attorney-General's Department

Protective Security Policy Framework (PSPF)

Governs how Australian Government entities protect people, information and assets, including classification, handling and transfer of official information.

Why it matters for file security. PSPF information-handling requirements bear directly on moving documents between classified and unclassified domains, and on what must be recorded when that happens.

How Glasswall addresses it. Cross-domain transfer rebuilds content moving between classified and unclassified domains, with a verdict record for each file transferred so the handling can be evidenced. We document where the deployment sits relative to PROTECTED-aligned environments without asserting an approval we do not hold.

Cross-domain and air-gapped transferContent Disarm and ReconstructionPer-file verdict recordGlasswall Meteor

Source: Attorney-General's Department

OAIC

Privacy Act 1988 and Notifiable Data Breaches scheme

Australian Privacy Principle 11 requires reasonable steps to protect personal information. The NDB scheme requires notification of eligible data breaches. A multi-tranche reform program continues to progress.

Why it matters for file security. Documents are the usual uncontrolled carrier of personal information. Reducing personal data held in loose files lowers both APP 11 exposure and the population of files capable of producing an eligible breach.

How Glasswall addresses it. Find & Redact removes named data patterns from documents before they are stored or shared, supporting the APP 11 reasonable-steps test. Storage Monitor applies the same treatment to files already at rest in Microsoft 365 and records what was processed per tenant.

Find & RedactStorage Monitor + SM AuditGlasswall Halo

Source: OAIC

Latest developments

What has changed in Australia

Most recent first.

  1. ConsultationMedium impact

    Consultation opens on SOCI Act Ministerial Directions and risk management reforms

    Following the first independent review of the SOCI Act delivered on 31 January 2026, the Government opened consultation on amendments to the Ministerial Directions powers under Part 3 and to the Critical Infrastructure Risk Management Program Rules.

    Why it matters for file security. Changes to the risk management program rules are the part to watch: they determine what an entity must document about how material risks, including file-borne compromise of data storage systems, are actually mitigated.

    How Glasswall addresses it

    Entities revisiting their risk management program during this consultation should expect to describe file-handling mitigations more explicitly than before. A deterministic rebuild control plus a per-file verdict record is materially easier to write into a program document than a detection-tuning posture.

    Content Disarm and ReconstructionPer-file verdict recordGlasswall Halo / Glasswall Meteor

    • cii
    • energy
    • telco
    • transport
    • banking
    • healthcare

    Source: Minister for Home Affairs

  2. In forceContext

    Mandatory smart device security standards take effect

    Security standards for smart devices supplied to critical infrastructure operators commenced under the Cyber Security Act 2024.

    Why it matters for file security. Indirect for file security, but relevant to supply-chain assurance: device firmware and configuration bundles are files, and their provenance is increasingly expected to be verifiable.

    How Glasswall addresses it

    Signature Verify checks file signatures against a managed site list on a any-deny-wins basis, which is the relevant control where firmware or configuration bundles arrive from a supplier and provenance has to be established before use.

    Signature VerifyGlasswall Halo

    • cii
    • manufacturing
    • energy

    Source: ACSC

  3. GuidanceMedium impact

    First independent review of the SOCI Act delivered

    The first independent review of the Security of Critical Infrastructure Act was delivered to Government, forming the basis for the reform consultation opened in March 2026.

    Why it matters for file security. Sets the direction for the next round of obligations on critical infrastructure entities, including how prescriptively risk management programs must describe technical controls.

    • cii

    Source: CISC

  4. In forceMedium impact

    Ransomware payment reporting obligations commence

    Ransomware payment reporting rules under the Cyber Security Act 2024 commenced, requiring in-scope entities to report ransomware payments to Government.

    Why it matters for file security. Ransomware overwhelmingly enters through file-borne delivery. A reporting obligation raises the cost of a successful document-delivered intrusion from an incident to a disclosure event.

    How Glasswall addresses it

    Rebuilding inbound documents removes the active content that ransomware delivery chains rely on, without needing to recognise the specific payload first. That matters more once a successful intrusion carries a statutory reporting consequence rather than just a recovery cost.

    Content Disarm and ReconstructionEmail CDR RelayMacro intelligenceGlasswall Halo / Glasswall Meteor

    • cii
    • banking
    • healthcare
    • education
    • manufacturing

    Source: ACSC

Scope

About this page

This page is a working reference for organisations operating in Australia.

It is not legal advice. Regulatory obligations depend on how an organisation is designated, which sector it operates in and how its systems are architected, take local advice before relying on any of this for a compliance decision. Where we describe how Glasswall relates to an obligation, we are describing a control, not certifying an outcome.

Planning a deployment in Australia?