What APRA CPS 230 means in practice
CPS 230 shifted the regulatory conversation from technology controls to business outcomes. Rather than asking whether a system is secure, it asks whether the entity can keep delivering its critical operations through a disruption, and how long it can be down before the harm becomes unacceptable.
Three obligations do most of the work. First, identifying critical operations — the processes that, if disrupted, would have a material adverse impact on depositors, policyholders, members or financial system stability — and setting explicit tolerance levels for maximum disruption, data loss and minimum service. Second, maintaining a business continuity plan that shows how those tolerances are met, and testing it regularly against severe but plausible scenarios rather than optimistic ones. Third, managing material service providers with a register, due diligence, contractual requirements and ongoing monitoring, including fourth-party dependencies.
Technology providers feel this standard as a documentation burden passed down the chain. Regulated clients need to evidence oversight of their providers, which means concrete answers about resilience, subcontractors, data location, incident notification timelines and exit arrangements.
The technical work that follows is usually about proving recovery rather than building new systems. Tolerance levels expressed as recovery time and recovery point objectives have to be tested against real restore exercises, not vendor capability statements. Dependencies have to be mapped, because a critical operation often relies on an application, an identity platform, a network path and a third party that were each assessed separately and never together.
The standard rewards honesty. An entity that documents a four-hour tolerance it cannot meet has created a finding; one that documents the real position with a remediation plan has demonstrated the risk management the standard is asking for.
How we help with this
Related terms
- APRA CPS 234CPS 234 is the APRA prudential standard on information security.
- Information Security Manual (ISM)The Information Security Manual is the Australian Signals Directorate's cyber security framework for government systems.
- Notifiable Data Breaches (NDB) schemeThe Notifiable Data Breaches scheme, under the Privacy Act 1988, requires covered organisations to notify affected individuals and the Office of the Australian Information Commissioner about eligible data breaches — unauthorised access, disclosure or loss of personal information likely to result in serious harm — as soon as practicable..
- Azure Virtual Desktop (AVD)Azure Virtual Desktop is Microsoft's cloud virtual desktop infrastructure service.
