If:
(a) an entity is the responsible entity for one or more critical infrastructure assets; and
(b) the entity has adopted a critical infrastructure risk management program that applies to the entity;
the entity must take all reasonable steps to ensure that the program is up to date.
Civil penalty: 200 penalty units.