| KC-02 S1 | Does the Privacy Act bind the entity? | Privacy Act s 6D(4)(b) | high |
| KC-02 S2 | What happened to the information? | Privacy Act s 26WE(2) | medium |
| KC-02 S3 | Is it an eligible data breach? | Privacy Act s 26WE(2) or Privacy Act s 26WG | high |
| KC-02 S4 | What must be notified, and when? | Privacy Act s 26WK and Privacy Act s 26WL | high |
| KC-02 S5 | Who is notified, how many, and how? | Privacy Act s 26WL | medium |
| KC-02 S6 | Who acts on the drafts? | DBRP-3 Who lodges or Privacy Act s 26WK | high |
| KC-02 S7 | Which Essential Eight control failed? | Essential Eight, Multi-factor authentication, ISM-1504 (Maturity Level One) | low |
| KC-04 S1 | Is Tallowood a reporting business entity? | Cyber Security Act 2024 s 26 (reporting business entity, ransomware payment) | high |
| KC-04 S2 | Is a ransomware payment report required? | Cyber Security Act 2024 s 26 (reporting business entity, ransomware payment) or Cyber Security Act 2024 s 27(1) (report within 72 hours) | high |
| KC-04 S3 | When is the report due? | Cyber Security Act 2024 s 27(1) (report within 72 hours) | high |
| KC-04 S4 | To whom? | Cyber Security Act 2024 s 27(1) (report within 72 hours) | medium |
| KC-04 S5 | What goes in the report? | Cyber Security Act 2024 s 27(2) and Rules s 7 (report contents) | medium |
| KC-04 S6 | Who lodges? | IRP-6 Who lodges a ransomware payment report or Cyber Security Act 2024 s 27(1) (report within 72 hours) | high |
| KC-04 S7 | Which Essential Eight control failed? | Essential Eight, Regular backups, ISM-1707 (Maturity Level Two) | low |
| KC-05 S1 | CPS 234: notify APRA? | APRA CPS 234 para 35 (notify APRA within 72 hours) | high |
| KC-05 S2 | CPS 230 para 32: a second incident notification? | APRA CPS 230 para 32 (operational risk incident notification) | low |
| KC-05 S3 | CPS 230 para 41: disruption beyond tolerance | APRA CPS 230 para 41 (disruption beyond tolerance, 24 hours) | high |
| KC-05 S4 | Privacy Act: is it an eligible data breach? | Privacy Act s 26WE(2) or Privacy Act s 26WK or Privacy Act s 26WL and Privacy Act s 26WM | high |
| KC-05 S5 | Who lodges with APRA? | ORP-4 Who notifies APRA or APRA CPS 234 para 35 (notify APRA within 72 hours) or APRA CPS 230 para 41 (disruption beyond tolerance, 24 hours) | high |
| KC-05 S6 | The provider afterwards | APRA CPS 234 para 16 (third-party security capability) or APRA CPS 234 para 22 (design of third-party controls) or APRA CPS 230 para 59 (monitoring material arrangements) | medium |