NSW Cyber Security Policy (NSW CSP) Compliance
The NSW Cyber Security Policy establishes mandatory requirements for NSW Government agencies to manage cyber security risks and protect government information and systems.
Overview
The NSW Cyber Security Policy establishes a mandatory cybersecurity framework for the NSW public sector. It requires agencies to implement cybersecurity governance, conduct risk assessments, adopt the Essential Eight mitigation strategies, manage incidents, and report annually on their cybersecurity maturity.
The policy recognises that agencies vary significantly in size, capability, and risk profile. It provides a flexible, risk-based approach that allows agencies to prioritise controls and investments based on their specific circumstances while maintaining a consistent baseline across the sector.
Cyber Security NSW provides central coordination, guidance, and support for agencies implementing the policy. This includes threat intelligence sharing, incident coordination, and capability uplift programs designed to help agencies improve their cybersecurity posture.
Annual maturity reporting creates transparency and accountability across the sector. Aggregate reporting enables the NSW Government to identify systemic risks, allocate resources effectively, and track the overall improvement of cybersecurity across the public sector.
Key Areas
- Cybersecurity governance and leadership accountability
- Risk management and system classification
- Adoption of the Essential Eight mitigation strategies
- Cybersecurity incident detection and response
- Annual cybersecurity maturity reporting
- Third-party and supply chain cyber risk management
- Cybersecurity awareness and training
- Development and maintenance of agency cybersecurity plans
Who It's For
- NSW Government departments and agencies
- NSW statutory bodies and state-owned corporations
- IT and cybersecurity teams within the NSW public sector
- Senior executives accountable for cybersecurity in NSW Government organisations
Core Requirements
- Policies and Governance
- Each agency must appoint a senior executive accountable for cybersecurity. Agencies must develop a cybersecurity plan that documents their approach to managing cyber risks, including governance structures, roles, responsibilities, and resource allocation.
- Risk Management
- Agencies must conduct cyber risk assessments for their information systems and classify them according to their criticality and sensitivity. Risk management approaches must be proportionate to the agency's risk profile and aligned with the NSW Government risk management framework.
- Security Controls
- Agencies must implement the Essential Eight mitigation strategies and work toward target maturity levels. Additional controls should be implemented based on risk assessments and the agency's threat environment. Alignment with the ASD ISM is expected for higher-risk systems.
- Incident Response
- Agencies must have cyber incident response plans and procedures. Incidents must be reported to Cyber Security NSW in accordance with mandatory reporting requirements. Agencies must participate in coordinated incident response when required.
- Evidence and Reporting
- Agencies must submit annual cybersecurity maturity reports to Cyber Security NSW. Reports must include Essential Eight maturity levels, risk assessment outcomes, incident summaries, and progress against cybersecurity plans.
Implementation Steps
- Scope and objectives - Identify all information systems and digital services within the agency's scope. Classify systems based on criticality and sensitivity. Set target Essential Eight maturity levels and define the scope of the agency cybersecurity plan.
- Gap assessment - Assess current cybersecurity practices against the CSP requirements, including Essential Eight maturity levels, governance structures, incident response capability, and third-party risk management. Identify areas requiring improvement.
- Control implementation - Implement or uplift controls to address identified gaps. Prioritise Essential Eight strategies, incident response procedures, and governance improvements. Deploy technical controls and establish operational procedures.
- Evidence and documentation - Develop and maintain the agency cybersecurity plan. Document control implementations, risk assessments, incident response procedures, and training records. Prepare evidence for annual maturity reporting to Cyber Security NSW.
- Review and continuous improvement - Conduct annual cybersecurity maturity assessments and report to Cyber Security NSW. Review and update the agency cybersecurity plan based on assessment outcomes, incidents, and changes to the threat environment. Pursue progressive maturity uplift.
Frequently Asked Questions
- Who must comply with the NSW CSP?
- All NSW Government departments, statutory bodies, and agencies are required to comply with the NSW Cyber Security Policy.
- What reporting is required?
- Agencies must submit annual cybersecurity maturity reports to Cyber Security NSW, including Essential Eight maturity assessments and progress against their cybersecurity plans.
- Does the CSP require Essential Eight implementation?
- Yes. The CSP mandates adoption of the Essential Eight mitigation strategies and requires agencies to work toward target maturity levels.
- Who is Cyber Security NSW?
- Cyber Security NSW is the state government body responsible for leading cybersecurity strategy, policy, and incident coordination across the NSW public sector.
- How does the CSP relate to the ASD ISM?
- The CSP aligns with the ASD ISM and the Essential Eight. Agencies managing higher-risk systems are expected to implement ISM controls relevant to their environment.
- Are local councils included?
- The CSP primarily applies to NSW Government departments and agencies. Local councils are encouraged to align with the policy but may have separate governance arrangements.
- What happens if an agency does not comply?
- Non-compliance is reported through annual maturity assessments. Agencies with significant gaps may receive targeted support and oversight from Cyber Security NSW.
Why It Matters
- NSW Government agencies manage vast amounts of sensitive citizen data and deliver essential services including health, education, transport, and justice. A cyber incident affecting these services could have significant consequences for millions of NSW residents.
- The CSP provides a consistent baseline for cybersecurity across a diverse public sector that includes large departments with dedicated security teams and smaller agencies with limited resources. This consistency helps reduce systemic risk across the entire NSW Government.
- By mandating annual reporting and maturity assessments, the CSP creates accountability and visibility at both the agency and whole-of-government level, enabling targeted investment in cybersecurity uplift where it is most needed.
Common Challenges
- Varying levels of cybersecurity maturity and resourcing across NSW Government agencies
- Securing legacy systems that support critical government services but lack modern security features
- Recruiting and retaining cybersecurity professionals in a competitive labour market
- Managing cybersecurity risk across complex ecosystems of third-party vendors and shared services
- Balancing security requirements with digital transformation and citizen service delivery objectives
- Achieving meaningful Essential Eight maturity improvements within constrained budgets