About the AESCSF
The Australian Energy Sector Cyber Security Framework (AESCSF) was developed in 2018 by the Australian Energy Market Operator (AEMO) together with industry and government. It adapts the US Department of Energy's Cybersecurity Capability Maturity Model (C2M2) and draws on the NIST Cybersecurity Framework, with Australian additions such as the Essential Eight and privacy requirements.
AEMO coordinates an annual self-assessment program for electricity and gas market participants. A criticality assessment sets each participant's target security profile: SP-1, SP-2 or SP-3. The profiles are cumulative, so SP-2 includes everything in SP-1, and SP-3 adds more again.
AESCSF Security Profile 1 is also one of the cyber frameworks recognised by the SOCI Act's risk management program rules, which makes the AESCSF a natural choice for energy operators' SOCI Act compliance.
Where OT Makes or Breaks the Assessment
The practices that are hardest to evidence in an energy business are usually the operational technology ones: an accurate inventory of control system assets, configuration and change management for PLCs and RTUs, network architecture and segmentation, remote access, monitoring of OT networks, and incident response that includes the control room. Self-assessments can go wrong in both directions: OT practices scored as achieved because the corporate IT control exists, or scored down because nobody could find the evidence.
With more than 25 years in SCADA and OT across energy, oil and gas and other critical infrastructure, I can interpret each practice in OT terms and tell the difference between a control that exists on paper and one that exists on site.
How I Help
Scoping and target profile
Confirming which parts of the business are in scope (generation, networks, gas, market systems) and that your target security profile reflects your criticality.
Facilitated self-assessment
Workshops that work through the practices with the right people in the room, with each practice interpreted consistently for both IT and OT.
Independent evidence review
A second pair of eyes on the scores and evidence before you submit, so the result is defensible.
Uplift roadmap
Prioritised actions to close the gaps to your target profile, sequenced around outages, projects and budget cycles.
One control set
Mapping AESCSF practices to IEC 62443 and your SOCI Act CIRMP, so the same OT work counts once across all three.
Frequently Asked Questions
Is the AESCSF mandatory?
Participation in AEMO's annual assessment program is voluntary. However, AESCSF Security Profile 1 is one of the frameworks the SOCI Act's CIRMP rules recognise, so energy operators with SOCI obligations commonly use it to meet the cyber framework requirement.
Who is the AESCSF for?
Organisations in the Australian energy sector, principally electricity and gas market participants, network operators and generators. It is designed to work for organisations of different sizes and levels of criticality.
What is the difference between the AESCSF and the Essential Eight?
The Essential Eight is a set of eight technical mitigation strategies for IT networks, assessed by maturity level. The AESCSF is a broader capability maturity framework covering governance, risk, assets, access, threats, monitoring, incident response, third parties, workforce and architecture across both IT and OT, and it references the Essential Eight within it.
Can you complete the AESCSF assessment for us?
The AESCSF is a self-assessment, so the scores should remain yours. I facilitate it, interpret the practices for OT, review the evidence, and build the plan for closing the gaps.
How does the AESCSF relate to IEC 62443?
They answer different questions. The AESCSF measures how mature your cyber security practices are across the organisation; IEC 62443 specifies how to design and secure the control systems themselves. Designing OT to IEC 62443 provides the evidence for many AESCSF practices.
Related Services
- SOCI Act & CIRMP for OTBring SCADA and control systems properly into your critical infrastructure risk management program.
- OT Cybersecurity Risk AssessmentAn IEC 62443-3-2 assessment of your SCADA and control systems, safe for live plant.
- IEC 62443 ConsultingZones and conduits, security levels, CSMS and system requirements, applied to your OT.
- IT & OT/ICS CybersecurityThe full cybersecurity service: management systems, compliance, risk, architecture and training.
Prepare for Your Next AESCSF Assessment
Contact Adam to discuss scope, timing and where OT evidence is likely to be the sticking point.