If:
(a) an entity is the responsible entity for one or more critical infrastructure assets; and
(b) the entity has adopted a critical infrastructure risk management program that applies to the entity;
the entity must comply with:
(c) the critical infrastructure risk management program; or
(d) if the program has been varied on one or more occasions--the program as varied.
Civil penalty: 200 penalty units.