Here is the honest situation. The Critical Infrastructure Risk Management Program Rules require responsible entities for covered critical infrastructure assets to adopt, maintain and comply with a written program that manages the material risks of four hazard vectors: cyber and information security, personnel, supply chain, and physical and natural hazards. The program must align cyber to a recognised framework, be approved by the board, and be reported on annually to the regulator. A responsible entity that manages some hazards but cannot show its program, its cyber framework alignment or its board-approved annual report is exactly where responsible entities fall short.
This Kit removes the guesswork. It is the CIRMP obligations written as adopt-ready controls you personalize in a weekend, with the evidence the regulator examines.
What you get, the moment you buy
Grounded in the Critical Infrastructure Risk Management Program Rules 2023, with the written program, the cyber and information, personnel, supply chain and physical and natural hazard vectors, cyber framework alignment, board approval and the annual report called out. Editable Word and Excel files.
What one control looks like
This is confirming responsible entity status, where the Rules begin. All 18 are built to this depth.
Why this is not another template pack
- The evidence is the point. An obligation you cannot evidence is exposure, and the annual report is board-approved. This tells you what the regulator examines and where responsible entities fall short, for every obligation.
- All four hazard vectors built in. The cyber, personnel, supply chain and physical and natural hazard management, plus board approval and reporting, are written into the controls, the substance the Rules require.
- Built on a mapped compliance corpus, not one person's opinion, from a graph of thousands of controls across standards.
- It compounds. The CIRMP aligns cyber to recognised frameworks and feeds your wider security and resilience program, so the work carries across.
Who buys this
Responsible entities for critical infrastructure assets and their security, risk, compliance and operations leads. Whether it is a first program or an annual-report tune-up, you save weeks and walk in with the four hazard vectors, governance and reporting structured.
Common questions
Is it really editable? Yes. Word and Excel files you own and adapt. No portal, no subscription.
Is this legal advice? No. It is an implementation toolkit grounded in the Rules. For a specific matter consult counsel; this gets your controls and evidence in order fast.
Does it cover all four hazard vectors? Yes. Cyber and information, personnel, supply chain and physical and natural hazards are each built as controls.
Does it cover the annual report? Yes. Board approval and the annual report to the regulator are built as controls.
What if it is not for me? A 30-day money-back guarantee.
Instant digital download · 30-day money-back guarantee · The Art of Service Pty Ltd, GPO Box 2673, Brisbane QLD 4001 · support@theartofservice.com