SOCI Act Compliance Document
Identifies substantive Security of Critical Infrastructure Act, CIRMP, and AESCSF compliance assessments. Topic phrases are retained for discovery; enforcement requires obligation status, compliance findings, maturity ratings, control gaps, risk-management-program content, or remediation actions, and high confidence additionally requires a critical-asset/responsible-entity context and an adverse finding.
- Type
- regex
- Engine
- boost_regex
- Confidence
- medium
- Confidence justification
- Medium confidence requires substantive compliance results rather than a public legislative or framework reference. High confidence adds asset/entity scope and an adverse result.
- Jurisdictions
- au
- Regulations
- Criminal Code 1899 (Qld), SOCI Act 2018 (Cth)
- Frameworks
- QGISCF
- Data categories
- security, government, infrastructure
- Scope
- narrow
- Risk rating
- 9
- Platform compatibility
- Purview: Compatible, GCP DLP: Compatible, Macie: Compatible, Zscaler: Compatible, Palo Alto: Degraded, Netskope: Unsupported
Pattern
(?is)\b(?:SOCI\s+Act\s+(?:compliance\s+)?(?:assessment|report|review)|Security\s+of\s+Critical\s+Infrastructure\s+(?:compliance\s+assessment|risk\s+management\s+program|resilience\s+assessment)|CIRMP\s+(?:assessment|review|report)|AESCSF\s+(?:assessment|compliance\s+report))\b
Should match
SOCI Act compliance assessment— Low-tier probe - compliance topic without assessment resultsSOCI Act compliance assessment: obligation status, maturity rating, risk management program, compliance findings, and remediation actions— Medium-tier probe - substantive results without adverse critical-asset contextSOCI Act compliance assessment for responsible entity NorthGrid and critical asset CA-104: compliance finding is non-compliant, material control gap, residual risk high, remediation overdue— High-tier probe - asset/entity context with adverse compliance results
Should not match
Social media compliance report— Non-match 1The society meeting was productive— Unrelated social usageThe public website summarises the SOCI Act and its obligations.— Public legislative overview without an assessment recordTraining example: SOCI Act compliance assessment for critical asset CA-104 with non-compliance and overdue remediation— Explicit training content must not enforce
Known false positives
- Public legislation, regulatory guidance, conference material, and framework documentation discuss SOCI, CIRMP, AESCSF, obligations, maturity, and resilience without containing an entity's compliance results. Mitigation: Keep topic-only matches discovery-only and require obligation status, findings, maturity ratings, program content, control gaps, or remediation actions for enforcement.
- Training assessments can contain realistic asset IDs, responsible entities, control gaps, maturity ratings, and non-compliance outcomes. Mitigation: Reject explicit template, demo, tutorial, sample-data, and training-example framing from enforcing tiers.