(1) If:
(a) the Secretary gives a request under section 35AX that was authorised by a Ministerial authorisation; and
(b) the authorised agency does one or more acts or things in compliance with the request;
the chief executive of the authorised agency must:
(c) prepare a written report that:
(i) sets out details of those acts or things; and
(ii) explains the extent to which doing those acts or things has amounted to an effective response to the cyber security incident to which the Ministerial authorisation relates; and
(d) give a copy of the report to the Defence Minister; and
(e) give a copy of the report to the Minister.
(2) The chief executive of the authorised agency must comply with subsection (1) as soon as practicable after the end of the period specified in the request and, in any event, within 3 months after the end of the period specified in the request.