Skip to main content
Image coming soon

Critical Infrastructure Risk Management Program (CIRMP) Evidence & Implementation Kit

$249.00
Adding to cart… The item has been added
CIRMP Rules 2023 · Critical Infrastructure Risk Management · Evidence & Implementation Kit
Stand up your CIRMP, without translating the Rules into a program yourself.
Every obligation handed to you as an adopt-ready control, across the four hazard vectors, cyber, personnel, supply chain and physical and natural, plus board approval and reporting, with the evidence the regulator examines.
CIRMP-ready in a weekend, not a quarter.

Here is the honest situation. The Critical Infrastructure Risk Management Program Rules require responsible entities for covered critical infrastructure assets to adopt, maintain and comply with a written program that manages the material risks of four hazard vectors: cyber and information security, personnel, supply chain, and physical and natural hazards. The program must align cyber to a recognised framework, be approved by the board, and be reported on annually to the regulator. A responsible entity that manages some hazards but cannot show its program, its cyber framework alignment or its board-approved annual report is exactly where responsible entities fall short.

This Kit removes the guesswork. It is the CIRMP obligations written as adopt-ready controls you personalize in a weekend, with the evidence the regulator examines.

What you get, the moment you buy

18
Obligations as adopt-ready controls. Every obligation, across the four hazard vectors plus board approval and reporting, written so you personalize and apply it.
18
Evidence-they-examine checklists. For each control, exactly what the regulator examines, plus where responsible entities fall short, so you close the gap first.
1
Critical Infrastructure Control Matrix, pre-built. Every obligation in a working spreadsheet, ready to record status, owner and evidence location.
1
Gap & Readiness Assessment. Score each obligation and the workbook returns your readiness as a single percentage, and exactly what to fix next.

Grounded in the Critical Infrastructure Risk Management Program Rules 2023, with the written program, the cyber and information, personnel, supply chain and physical and natural hazard vectors, cyber framework alignment, board approval and the annual report called out. Editable Word and Excel files.

Four hazard vectors, and the board owns all of them
The Rules require managing cyber, personnel, supply chain and physical and natural hazards in one program, aligned cyber to a recognised framework, and approved by the board with an annual report to the regulator. A responsible entity strong on cyber but thin on supply chain or personnel, or with no board-approved report, falls short. This Kit builds a control for every vector plus the governance and reporting, with the evidence the regulator asks for.

What one control looks like

This is confirming responsible entity status, where the Rules begin. All 18 are built to this depth.

CIRMP-1 Confirm responsible entity status SCOPE
Put this control in place

Determine and document whether [your organization name] is a responsible entity for a critical infrastructure asset to which the Critical Infrastructure Risk Management Program Rules apply, and which assets are covered, so that the obligation to have a program is established and the organization can evidence its status assessment.

Regulatory note.

The CIRMP Rules require responsible entities for certain critical infrastructure assets to have a risk management program.

Evidence the regulator examines
  • A status assessment against the Rules
  • The critical infrastructure assets covered
  • Records of the determination
Common finding they raise: A responsible entity for a covered asset has not assessed its CIRMP obligation.

Why this is not another template pack

  • The evidence is the point. An obligation you cannot evidence is exposure, and the annual report is board-approved. This tells you what the regulator examines and where responsible entities fall short, for every obligation.
  • All four hazard vectors built in. The cyber, personnel, supply chain and physical and natural hazard management, plus board approval and reporting, are written into the controls, the substance the Rules require.
  • Built on a mapped compliance corpus, not one person's opinion, from a graph of thousands of controls across standards.
  • It compounds. The CIRMP aligns cyber to recognised frameworks and feeds your wider security and resilience program, so the work carries across.

Who buys this

Responsible entities for critical infrastructure assets and their security, risk, compliance and operations leads. Whether it is a first program or an annual-report tune-up, you save weeks and walk in with the four hazard vectors, governance and reporting structured.

By the end of the weekend you will have
✓  An adopt-ready control for all 18 obligations
✓  A completed critical infrastructure control matrix
✓  The evidence the regulator examines
✓  Your four hazard vectors managed
✓  A readiness percentage and a fix list
✓  The board approval and reporting gaps closed

Common questions

Is it really editable? Yes. Word and Excel files you own and adapt. No portal, no subscription.

Is this legal advice? No. It is an implementation toolkit grounded in the Rules. For a specific matter consult counsel; this gets your controls and evidence in order fast.

Does it cover all four hazard vectors? Yes. Cyber and information, personnel, supply chain and physical and natural hazards are each built as controls.

Does it cover the annual report? Yes. Board approval and the annual report to the regulator are built as controls.

What if it is not for me? A 30-day money-back guarantee.

Do not run a critical asset you cannot show you protect.
Every CIRMP obligation is fast to adopt with the Kit. It is instant, and it is guaranteed.
Add it to your cart and be CIRMP-ready this weekend.

Instant digital download · 30-day money-back guarantee · The Art of Service Pty Ltd, GPO Box 2673, Brisbane QLD 4001 · support@theartofservice.com