What APRA CPS 234 means in practice
CPS 234 applies to APRA-regulated entities, but its reach extends well beyond them, because the standard makes regulated entities responsible for information assets managed by third parties. Any technology provider serving a bank, insurer or superannuation fund will be asked to demonstrate controls that satisfy their client's CPS 234 obligations.
The core requirements are clear enough to work against. Boards hold ultimate responsibility for information security, and roles and responsibilities must be clearly defined. Information security capability must be commensurate with the size and extent of threats, and with the criticality and sensitivity of the assets. Information assets must be classified by criticality and sensitivity, including those managed by related parties and third parties. Controls must be implemented, and — this is the part organisations underestimate — systematically tested, with results reviewed by people independent of those who designed or operate them.
Notification obligations are strict. Material information security incidents must be notified to APRA within 72 hours, and material control weaknesses that cannot be remediated in a timely manner within 10 business days. That timeline requires an incident classification process defined in advance, because the clock is not a reasonable moment to be deciding what counts as material.
In a Microsoft environment, the evidence CPS 234 assessors ask for maps onto identity and endpoint telemetry: who holds privileged access and how it is granted, whether multi-factor authentication covers all remote and privileged access, how device compliance is enforced, what logging exists and for how long, and how backups are tested for restoration rather than just monitored for completion.
CPS 230, the operational risk management standard, sits alongside it and broadens the lens to critical operations, service provider management and business continuity. Entities working through one usually find the other draws on the same evidence base, and building the two programmes together avoids duplicating the work.
How we help with this
Related terms
- APRA CPS 230CPS 230 is the APRA prudential standard on operational risk management.
- Information Security Manual (ISM)The Information Security Manual is the Australian Signals Directorate's cyber security framework for government systems.
- Notifiable Data Breaches (NDB) schemeThe Notifiable Data Breaches scheme, under the Privacy Act 1988, requires covered organisations to notify affected individuals and the Office of the Australian Information Commissioner about eligible data breaches — unauthorised access, disclosure or loss of personal information likely to result in serious harm — as soon as practicable..
- Azure Virtual Desktop (AVD)Azure Virtual Desktop is Microsoft's cloud virtual desktop infrastructure service.
