Critical Infrastructure Design
Identifies substantive critical-infrastructure and essential-service network or control-system designs. Topic phrases are retained for discovery; enforcement requires segmentation, data-flow, trust-boundary, VLAN, DMZ, firewall, or OT-zone design content, and high confidence also requires a populated address, VLAN, port, device, or rule detail.
- Type
- regex
- Engine
- boost_regex
- Confidence
- medium
- Confidence justification
- Medium confidence requires substantive design content in critical-infrastructure, essential-service, or OT scope. High confidence adds deployable network or device values.
- Jurisdictions
- au
- Regulations
- Criminal Code Act 1995 (Cth), SOCI Act 2018 (Cth)
- Frameworks
- CIS Controls, ISO 27001, NIST CSF
- Data categories
- infrastructure, security
- Scope
- narrow
- Risk rating
- 10
- Platform compatibility
- Purview: Compatible, GCP DLP: Compatible, Macie: Compatible, Zscaler: Compatible, Palo Alto: Degraded, Netskope: Unsupported
Pattern
(?is)\b(?:critical\s+infrastructure\s+(?:network\s+)?(?:design|architecture|topology|diagram)|essential\s+service\s+(?:network|system)\s+(?:design|architecture|diagram)|(?:SCADA|ICS|OT)\s+(?:network|system)\s+(?:design|architecture|diagram))\b
Should match
Critical infrastructure network design— Low-tier probe - critical-infrastructure design topic without design contentCritical infrastructure network architecture: VLAN segmentation, DMZ trust boundary, data flow, and zone and conduit model— Medium-tier probe - substantive design without populated live valuesCritical infrastructure network design for a water treatment plant: network segment VLAN 120, firewall rule source IP 10.4.0.0/16 to destination IP 10.8.2.10, TCP port 502— High-tier probe - essential-service design with populated VLAN, rule, address, and port details
Should not match
Infrastructure spending on roads— Non-match 1The network connection was slow— Generic connectivity statementThe public guide explains critical infrastructure resilience principles.— Public policy guidance without a system designTraining example: critical infrastructure network design with VLAN 120 and source IP 10.4.0.0/16— Explicit training content must not enforce
Known false positives
- Public resilience guidance and vendor reference architectures discuss critical infrastructure, essential services, and network segmentation without exposing a real design. Mitigation: Require a critical/essential/OT design topic plus substantive segmentation, data-flow, trust-boundary, or firewall content.
- Training labs can contain realistic addresses, VLANs, ports, and firewall-rule examples. Mitigation: Reject explicit template, demo, tutorial, sample-data, and training-example framing from enforcing tiers.