CPS 234 assessment
A review of your entity against each requirement of the standard, with a rating and the gaps we find.
Independent assessments of your information security against APRA's CPS 234, with clear findings for the board and a plan to close the gaps.
CPS 234 makes the board of every APRA-regulated entity ultimately responsible for information security, so directors need independent evidence that controls are in place and operating effectively. Vectra assesses your entity against each part of the standard, tests how well your controls work, sets out the gaps in plain terms and helps you remediate them. Our team holds the specialist certifications this work needs, and we are based in Australia.
Under its 2020-2024 cyber strategy, APRA required banks, insurers and super trustees to appoint independent auditors to assess them against CPS 234. APRA then published the gaps these tripartite assessments found most often.
We look closely at each of these areas in every assessment.
Critical and sensitive assets not fully identified or classified.
Little assessment of the security of third parties.
Testing programs that are poorly defined or not carried out.
Incident response plans that are not reviewed or tested often enough.
Little internal audit review of security controls.
Material incidents and control weaknesses not reported to APRA on time.
Testing must be independent.
CPS 234 says your controls must be tested by skilled specialists who are functionally independent. Vectra can run that testing for you, or check the testing program you already have.
Each step rests on evidence of what is in place today.
Agree the entities, information assets, third parties and time period in scope, and who will receive the report.
Read your policy framework, roles, asset register, response plans, testing program and internal audit work.
Interview control owners, sample the evidence and test whether key controls are well designed and work as intended.
Check how you assess the security of related parties and third parties that manage your information assets.
Rate each requirement, rank the gaps by risk and write a summary the board can act on.
Help you plan and close the gaps, then check the fixes in a follow-up review.
A review of your entity against each requirement of the standard, with a rating and the gaps we find.
An audit of your controls and the evidence behind them, as APRA would expect to see it.
Testing by skilled specialists who are independent of the teams that run the controls, as the standard requires.
A check of how your service providers protect your information assets, sized to the harm an incident could cause.
The risks we found, the order in which to fix them and help to remediate each gap.
Periodic reviews so your controls keep pace as your business and the threat environment change.
A rating against each CPS 234 requirement, backed by evidence.
A ranked list of gaps, with owners and fixes.
A plain summary for the board and senior management.
A clear view of the security risk held by your third parties.
A remediation plan you can track and test again.
It applies to all APRA-regulated entities. That includes banks and other deposit-taking institutions, general insurers, life insurers, private health insurers, super fund trustees (RSE licensees) and authorised or registered non-operating holding companies. It has been in force since 1 July 2019.
The standard says control testing must be done by specialists who are skilled and functionally independent. Internal audit must also review how well your controls are designed and how well they work. An independent assessment meets these needs and gives the board evidence it can question.
You must tell APRA within 72 hours of becoming aware of a material security incident. You must also tell APRA within 10 business days of finding a material control weakness that you do not expect to fix in a timely way.
Yes. Where a related party or third party manages your information assets, you must assess its security capability. Your internal audit must also review controls kept by those parties. We can assess your key providers as part of the work.
Yes. We map controls across CPS 234, ISO 27001, PCI DSS and the Essential Eight, so one set of evidence can support several reviews.
Speak to us about your cyber governance and compliance requirements.