In plain English
CPS 234 says what a bank, insurer or super fund must do. CPG 234 describes how APRA expects it to be done. The guide is not enforceable on its own, but APRA supervisors measure an entity's practices against it.
Full definition
CPG 234 covers the practical side of each obligation: how to structure roles and responsibilities, what a sound information security capability looks like, how to classify assets, the kinds of controls APRA expects for different classifications, how to test controls and how often, and how to manage third-party and related-party arrangements.
Because it is a practice guide rather than a prudential standard, an entity can meet CPS 234 in a different way if it can show the outcome is equivalent. In practice, APRA's tripartite reviews and supervisory findings are framed against CPG 234, so most entities treat it as the working checklist.
