IronSights

Compliance & governance

APRA CPG 234CPG 234

APRA's Prudential Practice Guide CPG 234 Information Security, published in June 2019. Non-binding guidance that explains how APRA expects a regulated entity to meet the obligations in the enforceable standard CPS 234.

Also known asCPG 234CPG234Prudential Practice Guide CPG 234

In plain English

CPS 234 says what a bank, insurer or super fund must do. CPG 234 describes how APRA expects it to be done. The guide is not enforceable on its own, but APRA supervisors measure an entity's practices against it.

Full definition

CPG 234 covers the practical side of each obligation: how to structure roles and responsibilities, what a sound information security capability looks like, how to classify assets, the kinds of controls APRA expects for different classifications, how to test controls and how often, and how to manage third-party and related-party arrangements.

Because it is a practice guide rather than a prudential standard, an entity can meet CPS 234 in a different way if it can show the outcome is equivalent. In practice, APRA's tripartite reviews and supervisory findings are framed against CPG 234, so most entities treat it as the working checklist.

Keep learning

More terms in the IronSights Glossary.