IronSights
←All insights

compliance

CPS 234 requirements: the checklist, paragraph by paragraph

All 24 requirement paragraphs of APRA's CPS 234 Information Security standard as a checklist: the paragraph number, what it requires in plain terms, and the evidence you would need to show a supervisor.

Ryan BallootBy Ryan Balloot, Managing Director29 September 20264 min read
ByRyan Balloot29 September 20264 min read

is short. The whole standard is 36 paragraphs and the requirements run from paragraph 13 to paragraph 36. The catch is that almost every one of those paragraphs is written as an outcome rather than a control, so an entity can read it, nod, and still have nothing an APRA supervisor would accept as evidence.

This page turns those 24 paragraphs into a checklist. Each row gives the paragraph number, what it requires in plain terms, and the evidence you would need to show for it. It is built from the standard itself as published by APRA (July 2019, in force since 1 July 2019) and is not legal advice. The paragraph numbers are there so you can check the wording yourself.

If you want the background first, our CPS 234 explainer covers who it applies to and what APRA found when it looked.

Who it applies to, and two definitions that matter

CPS 234 applies to every APRA-regulated entity: authorised deposit-taking institutions, general insurers, life insurers, private health insurers and registrable superannuation entity licensees, along with their non-operating holding companies where APRA regulates them. The standard's requirements reach beyond the entity's own systems: paragraphs 16, 20, 21, 22, 28, 32 and 34 all explicitly cover information assets managed by related parties and third parties.

Two definitions in paragraph 12 decide how wide the net is. An information asset is information and information technology, including software, hardware and data, in both soft and hard copy. An information security incident is an actual or potential compromise of information security. The word potential is doing a lot of work in both the and the notification paragraphs.

Roles and responsibilities (paragraphs 13 and 14)

ParaWhat CPS 234 requiresEvidence to hold
13The Board is ultimately responsible for the entity's information security, and must ensure it is maintained in a manner commensurate with the size and extent of threats to its information assets.Board minutes and papers showing information security is a standing item; a Board-approved risk appetite for information security; evidence the Board receives and acts on testing and incident reporting.
14Information security roles and responsibilities of the Board, senior management, governing bodies and individuals must be clearly defined, covering decision-making, approval, oversight and operations.A documented responsibilities matrix or charter naming who decides, who approves, who oversees and who operates, including committees and working groups.

Information security capability (paragraphs 15 to 17)

ParaWhat CPS 234 requiresEvidence to hold
15Maintain an information security capability commensurate with the size and extent of threats, sufficient to enable the continued sound operation of the entity.A current threat assessment, and a capability statement mapping resources, skills and controls against it. Headcount, tooling and outsourced arrangements documented.
16Where a related party or third party manages information assets, assess that party's information security capability, commensurate with the potential consequences of an incident affecting those assets.A register of third and related parties holding information assets, each with a documented capability assessment proportionate to the consequences. This applies to all such parties, not only outsourced material business activities.
17Actively maintain the capability as vulnerabilities and threats change, including changes from new information assets or a changed business environment.Evidence the threat assessment and capability are revisited on a schedule and on change: change management records, periodic reviews, board reporting on emerging threats.

Policy framework (paragraphs 18 and 19)

ParaWhat CPS 234 requiresEvidence to hold
18Maintain an information security policy framework commensurate with exposure to vulnerabilities and threats.The policy set, with owners, approval dates and review cycle. Standards and procedures beneath the policies, not only a top-level policy.
19The framework must give direction on the responsibilities of all parties who have an obligation to maintain information security.Policy content that addresses staff, contractors, consultants, related parties, third parties and customers, with the means by which each is made aware of it.

Information asset identification and classification (paragraph 20)

ParaWhat CPS 234 requiresEvidence to hold
20Classify information assets, including those managed by related and third parties, by criticality and sensitivity, reflecting the potential financial and non-financial impact on the entity, depositors, policyholders, beneficiaries or other customers.An information asset register that includes third-party-held assets, with a criticality and a sensitivity rating on each and a documented rating method.

Implementation of controls (paragraphs 21 and 22)

ParaWhat CPS 234 requiresEvidence to hold
21Have information security controls, implemented in a timely manner, commensurate with the vulnerabilities and threats, the criticality and sensitivity of the assets, their life-cycle stage, and the potential consequences of an incident.A control library mapped to asset classifications, with implementation dates. Evidence that controls scale with sensitivity, and that decommissioned assets are handled, since life-cycle runs from design to disposal.
22Where a related or third party manages information assets, evaluate the design of that party's controls that protect those assets.A documented design evaluation for each such party. Reliance on a vendor's reputation or certificate alone is not an evaluation.

Incident management (paragraphs 23 to 26)

ParaWhat CPS 234 requiresEvidence to hold
23Have robust mechanisms to detect and respond to information security incidents in a timely manner.Monitoring and alerting coverage, an on-call arrangement, and incident records showing time from detection to response.
24Maintain response plans for the incidents the entity considers could plausibly occur.Documented scenario-based response plans, with a record of which scenarios were considered plausible and why.
25Response plans must cover all stages from detection to post-incident review, and escalation and reporting to the Board, governing bodies and the individuals responsible for incident management and oversight.Plan content showing each stage, the escalation paths, thresholds and named roles. Post-incident review records for past incidents.
26Review and test the response plans annually to ensure they remain effective and fit for purpose.Dated exercise reports for each plan within the last 12 months, with findings and the changes made as a result.

Testing control effectiveness (paragraphs 27 to 31)

ParaWhat CPS 234 requiresEvidence to hold
27Test control effectiveness through a systematic testing program whose nature and frequency match the rate of change in threats, the criticality and sensitivity of the asset, the consequences of an incident, exposure to environments where the entity cannot enforce its policies, and the materiality and frequency of change to assets.A testing program document that states the frequency for each asset class and explains the frequency against those five factors. Test results and remediation tracking.
28Where reliant on a related or third party's own control testing, assess whether the nature and frequency of that testing is commensurate with the factors in paragraph 27.For each relied-upon party, a documented assessment of their testing scope and frequency against the same five factors.
29Escalate and report to the Board or senior management any testing results that identify control deficiencies which cannot be remediated in a timely manner.Board or executive papers showing the deficiencies reported, and the decisions taken on them.
30Testing must be conducted by appropriately skilled and functionally independent specialists.Tester qualifications and an independence statement: the people testing a control are not the people who operate it.
31Review the sufficiency of the testing program at least annually, or when there is a material change to information assets or the business environment.A dated annual review of the program, and evidence it was revisited after material change.

Internal audit (paragraphs 32 to 34)

ParaWhat CPS 234 requiresEvidence to hold
32Internal audit must review the design and operating effectiveness of information security controls, including those maintained by related and third parties.The internal audit plan and completed audit reports covering information security controls, including third-party controls.
33That assurance must be provided by personnel appropriately skilled in providing it.Skills and experience of the internal audit staff or co-sourced specialists performing the work.
34Where an incident affecting third-party-held assets could materially affect the entity or its customers, and internal audit intends to rely on the third party's assurance, internal audit must assess that assurance.Internal audit's documented assessment of each third-party assurance report it relies on, such as a SOC report, against the entity's own needs.

APRA notification (paragraphs 35 and 36)

ParaWhat CPS 234 requiresEvidence to hold
35Notify APRA as soon as possible and no later than 72 hours after becoming aware of an information security incident that materially affected, or had the potential to materially affect, the entity or its customers, or that has been notified to another regulator in Australia or elsewhere.A notification procedure naming who decides materiality, who notifies, and how they are reached out of hours. A log of notifications made, with the awareness time and the notification time.
36Notify APRA as soon as possible and no later than 10 business days after becoming aware of a material control weakness the entity expects it will not be able to remediate in a timely manner.A register of material control weaknesses with the awareness date, the remediation assessment and the notification date where one was required.

Two clocks, then. Seventy-two hours for a material incident, counted from awareness rather than from understanding, and 10 business days for a material weakness you do not expect to fix in a timely manner. Both are triggered by the word aware, which is why the notification procedure has to exist before anything goes wrong.

Where entities fail

APRA's thematic review of CPS 234 compliance in 2020 and 2021 found the same gaps across most entities reviewed: control testing was not frequent enough, third-party risk was assumed rather than assessed, and incident detection fell below expectation. In checklist terms those are paragraphs 27 and 31, paragraphs 16, 22 and 28, and paragraph 23. If you only have time to evidence a few rows, start with those.

Third-party coverage is the one that catches most entities, because it appears in seven paragraphs and every one of them applies to all related and third parties, not only outsourced material business activities. We cover the practical side in the explainer.

Frequently asked questions

What are the CPS 234 requirements?

Twenty-four requirement paragraphs, numbered 13 to 36, under nine headings: roles and responsibilities, information security capability, policy framework, information asset identification and classification, implementation of controls, incident management, testing control effectiveness, internal audit and APRA notification.

Does CPS 234 require penetration testing?

Not by name. Paragraph 27 requires a systematic testing program whose nature and frequency match the risk factors listed, and paragraph 30 requires skilled, functionally independent testers. is the usual way to meet that for internet-facing and critical assets, and the practice guide discusses it, but the standard itself sets the outcome rather than the method.

What is the CPS 234 notification timeframe?

Seventy-two hours after becoming aware of a material information security incident (paragraph 35), and 10 business days after becoming aware of a material control weakness that will not be remediated in a timely manner (paragraph 36). Both run from awareness.

Does CPS 234 apply to our IT provider or cloud vendor?

CPS 234 binds the APRA-regulated entity, not the vendor. But paragraphs 16, 20, 21, 22, 28, 32 and 34 require the entity to assess, classify, evaluate, test and audit the information assets and controls those vendors manage. In practice the vendor has to be able to evidence its controls to you, or you cannot evidence yours to APRA.

Is CPS 234 the same as CPG 234?

No. CPS 234 is the enforceable prudential standard. CPG 234 is APRA's practice guide, published alongside it in June 2019, which describes how APRA expects the requirements to be met. Supervisors measure practices against the guide, but the obligation is the standard.

Where to start

The rows most entities cannot evidence are the testing and third-party ones, and both are fixed by doing the work rather than writing about it. Our CPS 234 compliance service covers the control testing program, the third-party assessments and the evidence pack, and our penetration testing is scoped to paragraph 27's factors so the report reads the way a supervisor expects.

APRA CPS 234

Know where you stand before APRA asks.

A gap assessment against every obligation in the standard, with a remediation plan your board can read and the independent control testing CPS 234 requires.