Australia · Australian Prudential Regulation Authority (APRA) · CPS 234

APRA Prudential Standard CPS 234

APRA's information-security prudential standard requiring regulated entities to maintain information-security capability commensurate with the threats they face.

What it is

CPS 234 applies to all APRA-regulated entities - banks, insurers, superannuation trustees and other RSE licensees. It imposes five core obligations: clear roles and responsibilities, an information-security capability commensurate with threats, implementation of controls to protect information assets, testing of controls, and notification to APRA of material information-security incidents within 72 hours. Boards are ultimately accountable for information security under the standard.

Who it applies to

All APRA-regulated entities, including ADIs, foreign ADIs, general insurers, life insurers, private health insurers, superannuation trustees and RSE licensees.

Requirements

Roles and responsibilities

Clearly define information-security roles, including those of the board, senior management, governing bodies and individuals.

Information-security capability

Maintain a capability commensurate with the size and extent of threats, and the criticality and sensitivity of information assets.

Policy framework

Maintain an information-security policy framework that directs the behaviour of personnel and third parties.

Implementation of controls

Implement controls that are adequate and appropriate to protect information assets against vulnerabilities and threats.

Testing

Systematically test the effectiveness of controls and apply the results.

Incident notification

Notify APRA within 72 hours of information-security incidents that have or could have a material impact.

Read next

Other places this turns up on the site.

Security, engineered around you.

Talk to an engineer - not a call centre. Most Vectra conversations start with a 30-minute technical briefing and end with a written plan.