On this page
- Purpose
- Scope
- Ruling
- Roles and responsibilities
- Definitions
- Appendix 1 – SACSF V1.1 vs SACSF V2.0 Change Log
Download the SACSF Ruling 6 – Implementation of the SACSF V2.0
Purpose
This Ruling provides clear direction to South Australian (SA) Government agencies on the implementation of new and updated requirements in the South Australian Cyber Security Framework (SACSF) V2.0.
Scope
This Ruling does not provide any new policy direction in relation to the SACSF, but instead clearly articulates the implementation requirements and timeframes that agencies must meet when updating their cyber security program from the original SACSF, to the most recent version, SACSF V2.0, approved by Cabinet on 23 June 2025.
Ruling
Using a risk-based approach to implementing the new and updated requirements of the SACSF V2.0, government agencies must have completed the following activities by 23 March 2026:
- Undertaken an analysis of the new and updated requirements that apply to their tier level and identified any requirements that are not currently in place.
- Following that analysis, agencies must have:
Roles and responsibilities
Agency Chief Executive
Accountable for the effective implementation of, and compliance with this Ruling within their agency.
Agency Security Executives
Responsible for ensuring that the Ruling is implemented within the agency and that business processes support the Ruling requirements.
Agency IT Security Advisor
Responsible for providing advice on application of this Ruling, and for providing advice on application of the SACSF V2.0 within the agency environment.
Appendix 1 – SACSF V1.1 vs SACSF V2.0 Change Log
A summary of content changes for the updated SACSF V2.0 from SACSF V1.1 that are directly relevant to implementation are below.
1. Foreword and 2. Introduction
- General updates to text to better describe the SACSF objectives and approach.
- An additional statement that the SACSF must be used in conjunction with the SA Protective Security Framework, and that agencies are responsible for demonstrating alignment.
- The Scope has been updated to REMOVE the statement that the SACSF applies to: Suppliers to the South Australian Government and non-government personnel that provide services to agencies.
- The Scope has been UPDATED to align to the SA Protective Security Framework and now reads: The SACSF applies to South Australian public sector agencies (as defined in section 3(1) of the Public Sector Act 2009 and to any other person or organisation that is generally subject to the direction of a Minister of the Crown; all of which are referred to in this policy as “Agencies”.
- The Disclaimer following the Scope statement has been UPDATED.
3. Implementation Approach
- SACSF Implementation Approach diagram (Figure 1) ADDED.
- 3.1 Cyber Security Governance section defining key roles and responsibilities ADDED.
- 3.2.2 SACSF Tier Selection UPDATED to include complexity of the technology environment as a characteristic.
- 3.3.1 Gap Analysis - new section ADDED.
- 3.3.2 Risk Assessment section UPDATED to include a more comprehensive description of cyber security risk management using the SACSF.
- 3.3.3. Agency Strategy and Roadmap – new section ADDED.
- 3.3.4 Team structure and Responsibilities – new section ADDED.
- Independent certification section REMOVED.
- 3.4 Cyber Security Calendar section has been RENAMED ‘Cyber Security Operations’.
- 3.5 Framework Implementation Guidance RENAMED ’Implementation’. New text and tools ADDED.
- The Functions and Responsibilities section has been RENAMED Team Structure and Responsibilities and has been MOVED from Heading 4 to Appendix C at the end of the SACSF.
4. Framework
- Due to the merging of the following policy statements, 21 policy statements have been reduced to 18:
- Supplier Management and Acquisition of Technology - NEW
- 1.5 - Supplier Management
- 2.9 - Systems and Software Acquisition
- 2.11 - Cloud Computing
- Mobile Device Management & Remote Working - NEW
- 2.12 – Mobile Device Management
- 2.13 – Teleworking
- Supplier Management and Acquisition of Technology - NEW
- The ‘expectations’ associated with each policy statement have been RENAMED ‘requirements’.
- Section 6 Principles and Policy Statements has been REMOVED.
Principle One: Governance
- 1.1 Leadership – NO CHANGE.
- 1.2 Organisational Structure and Staff Responsibilities.
- The Tier Two requirement for cyber security staff to maintain industry recognised certifications has been REMOVED. Instead, staff must have qualifications and maintain ongoing professional education relevant to their role.
- 1.3 Risk Management.
- The Tier One requirement for ‘cyber security risks to be assessed and documented for all projects’ has been changed to ‘for all projects where cyber security risk exists…’.
- 1.4 Policies, Procedures and Compliance.
- A new requirement has been ADDED for a policy governing the safe selection and use of generative AI and Large Language Model Tools.
- 1.5 Supplier Management and Acquisition of Technology.
- The Policy Statement and Requirements have MERGED the following previous policies:
- Supplier Management (previously 1.5)
- System and Software Acquisition (previously 2.9)
- Cloud Computing (previously 2.11)
- The Policy Statement and Requirements have MERGED the following previous policies:
- Policy Statement UPDATED to state ‘Cyber security requirements must be included in all agreements with all suppliers handling data throughout the procurement lifecycle. This applies to all systems, software and services being introduced to the agency, including cloud services. Additionally, prior to any procurement a risk assessment must be performed that evaluates the benefits of the proposed system, software or service while carefully considering any associated risks.’ The rest of the policy statement is the same as the previous Cloud Computing policy statement.
- New requirement for due diligence activities has been ADDED to Tier One.
- New requirement to establish, communicate and document cyber security roles and responsibilities of suppliers in supplier agreements has been ADDED to Tier One.
- The requirement for agencies to obtain independent assurance from suppliers, including cloud suppliers has been MOVED from Tier Four to Tier Three.
1.6 Audit and Assurance – NO CHANGE.
Principle Two: Information
- 2.1 Information Asset Identification and Classification.
- The Policy Statement has been UPDATED to say that ‘Information and data assets supporting critical processes must be identified, recorded and classified’.
- The Tier Two requirement ‘Processes are documented and followed for labelling, storing, handling and disposing of assets in alignment with their classification’ has been MOVED to Tier One.
- Two new requirements have been ADDED to Tier Three for data life cycle management:
- An effective data life cycle management strategy is in place to ensure data is classified, retained, stored, used, archived, disposed of, backed up and monitored securely in compliance with legal and regulatory requirements.
- Data life cycle management practices and processes must be clearly defined and adhered to, to ensure that information assets are managed adequately. Consider the Information Management Strategy and Standards of South Australia for further reference.
- 2.2 Incident Management.
- Tier Two requirement that ‘Cyber security specialists are identified and obtainable for cyber security incident response through an internal capability, or arrangements with third party specialists’ has been UPDATED to ’Cyber security specialists are identified and obtainable for cyber security incident response through an internal capability, or arrangements with third party specialists, or through the South Australian Government Cyber Security Watch Desk’.
- New Tier Three requirement has been ADDED ‘Incident management plans include a set of pre-approved containment actions that agency staff and management can take in the event of a cyber incident’.
- 2.3 Resilience and Service Continuity – NO CHANGE.
- 2.4 Access to Information
- The following Tier Three requirement has been MOVED to Tier one – ‘Multi-factor authentication is required to authenticate users to cloud-based solutions such as Microsoft 365’
- The following Tier Three requirement has been MOVED to Tier two – ‘Certificate based authentication is implemented to identify authorised workstations connected to the agency’s network.’
- The following Tier Two requirement has been REMOVED – ‘Multi-factor authentication (MFA) is required to authenticate all users in positions of trust.’
- New Tier One requirement has been ADDED - ’Where an application supports MFA, it is required for all users’.
- New Tier One requirement has been ADDED - ’MFA is used to authenticate users to online customer services that process, store or communicate sensitive customer data where available. For further guidance on MFA refer to SACSF-G10.0 and SACSF-G17.0.’
- 2.5 Administrative Access – NO CHANGE.
- 2.6 Robust ICT Systems and Operations
- New Tier One requirement has been ADDED onto existing Backups requirement – ‘Backup and restoration processes are tested annually and include verifying the integrity of backups to ensure they are tested against information asset, software, and configuration settings in accordance with data lifecycle management practices. Refer to 2.3 Resilience and Service Continuity- business continuity and periodic testing.’
- New Tier Two requirement has been ADDED – ’Threat intelligence is integrated into event logging and monitoring systems and processes. For further guidance, refer to SACSF Guideline 15.0 – Logging and Monitoring’
- 2.7 Vulnerability Management
- Tier One requirement UPDATED to replace ‘that are assessed as ‘extreme’ with ’that are assessed as critical by the vendor’ – ‘Security vulnerabilities in applications and operating systems that are assessed as critical by the vendor are patched or mitigated within 48 hours of release for all workstations, servers and network devices’.
- New Tier One requirement ADDED on vulnerability remediation aligning to change management – ‘Vulnerability remediation processes align with the Change Management requirements outlined under SACSF Policy Statement 2.6: Robust ICT Systems and Operations. For further guidance, refer to SACSF Guideline 11.0 – Vulnerability management and patching.’
- ADDED a link to SA Government’s Vulnerability Disclosure Policy in Tier One.
- UPDATED existing Tier Two requirement to incorporate use of threat intelligence feeds – ‘Using threat intelligence feeds to monitor new or updated security vulnerabilities in operating systems, software, and ICT equipment used by the agency as well as other elements which may adversely impact the security of a system.’
- New Tier Two requirement for vulnerability scanning has been ADDED – ‘Vulnerability scanning is performed at least on a fortnightly basis to identify vulnerabilities within internet-facing services, including supporting operating systems and network devices’.
- 2.8 Network Communications
- UPDATED existing Tier One requirement to document the agencies internal network architecture to include – ‘…with clearly defined network zones’.
- MOVED existing requirement from Tier Four to Tier Three – “Network segregation is implemented through the agency’s network.’
- 2.9 Secure Software Development
- This policy statement was previously 2.10. Due to the merging of policy statements, it is now 2.9.
- New Tier One requirement – ‘A secure configuration process for web services is established and documented to guide the configuration and hardening of all web services. For further guidance refer to SACSF Standard 4.16 Secure Web Service Standard.’
- New Tier One requirement – ‘Newly commissioned web services must maintain processes to manage the identification and reporting of vulnerabilities in alignment with the SA Government Vulnerability Disclosure Policy.’
- 2.10 Mobile Device Management and Remote Working
- MERGED 2.12 Mobile Device Management and 2.13 Teleworking to become 2.10 – Mobile Device Management and Remote Working.
- Mobile phones CHANGED to mobile devices.
- ADDED requirement to comply with Ruling 3 – TikTok to the Policy Statement.
Principle Three: Personnel
- 3.1 Personnel Security Lifecycle – NO CHANGE.
Principle Four: Physical
- 4.1 Physical Security – NO CHANGE.
Appendix B: Framework Implementation Guidelines
- Previously, 3.7 Framework Implementation Guidance was on page 9 of the SACSF.
- This has been MOVED to Appendix B.
- The list of guidelines has been expanded to include all SACSF guidelines currently available.
Appendix C: Team Structure and Responsibilities
- Previously, this was part of Section 4 Functions and Responsibilities on Page 10 of the SACSF.
- This has been MOVED to Appendix C and RENAMED ‘Team Structure and Responsibilities’.
- No other changes.
Appendix D: Glossary of terms
- Previously, this was Appendix B of the SACSF.
- ADDED Agency Security Executive (ASE) definition.
- ADDED Online Services and Online Customer Services definition.