In plain English
CPS 234 is the cyber security rulebook for banks, insurers, superannuation funds and private health insurers in Australia. The board owns it, the entity must be able to prove its controls work, its suppliers are in scope, and serious incidents have to be reported to APRA within 72 hours.
Full definition
CPS 234 applies to every entity APRA regulates: authorised deposit-taking institutions, general, life and private health insurers, and registrable superannuation entities, along with the outsourced providers that manage information assets on their behalf. The board is ultimately responsible for information security under the standard.
The standard sets out obligations rather than specific technical controls. An entity must maintain a security capability commensurate with the size and extent of its threats, keep a policy framework, classify information assets by criticality and sensitivity, implement controls that match that classification, test control effectiveness systematically, and have its internal audit review the design and operating effectiveness of those controls. Third parties that hold or process the entity's information are explicitly in scope.
Two notification clocks apply. A material information security incident must be reported to APRA within 72 hours of the entity becoming aware of it. A material control weakness that cannot be remediated in a timely manner must be reported within 10 business days. Guidance on meeting the standard is set out in the companion practice guide, .
