The CPS 234 module tracks compliance with APRA Prudential Standard CPS 234 Information Security, which applies to APRA-regulated entities in Australia: authorised deposit-taking institutions including foreign ADIs and authorised banking NOHCs, general insurers including Category C insurers, life companies including friendly societies and EFLICs, private health insurers registered under the PHIPS Act, and RSE licensees in respect of their business operations.

The standard commenced on 1 July 2019. Where your information assets are managed by a third party, it applied from the earlier of the next renewal date of that contract or 1 July 2020.

What Venvera tracks

CPS 234 contains 36 numbered paragraphs. Paragraphs 1 to 12 cover authority, application, interpretation and definitions and create no obligations. Paragraphs 13 to 36 are the operative requirements, and those 24 are what Venvera ships as requirement rows, grouped under the standard's own nine headings.

SectionParagraphsWhat it covers
Roles and responsibilities13 to 14Board ultimate responsibility, and defined roles for the Board, senior management, governing bodies and individuals
Information security capability15 to 17Capability sized against threats, third party capability, and maintaining capability as threats change
Policy framework18 to 19The policy framework, and direction for every party with an obligation
Asset identification and classification20Classification by criticality and sensitivity, reflecting customer impact
Implementation of controls21 to 22Controls sized against four factors, and evaluation of third party control design
Incident management23 to 26Detection and response, response plans, plan content and escalation, annual review and testing
Testing control effectiveness27 to 31Systematic testing programme, third party testing, escalation, independent testers, annual programme review
Internal audit32 to 34Review of control design and operating effectiveness, skilled assurance, assessment of third party assurance
APRA notification35 to 3672 hours for a material incident, 10 business days for a material control weakness

Dashboard

The dashboard shows implementation coverage across the 24 requirements, a breakdown by the nine sections, and the maturity score from the gap assessment if one has been completed. Coverage and maturity answer different questions: coverage says whether a requirement is implemented, maturity says how well the duty is discharged.

i
Requirements are referenced by paragraph number, for example CPS234-27 for paragraph 27. That is how APRA, your internal audit function and a tripartite reviewer all cite the standard, so evidence you produce here matches the language of the review.

Recurring duties

Five obligations land on the compliance calendar with owners, dates and reminders. Each names the paragraph it serves.

Response plan review and test

Annual, paragraph 26. Both a review and a test are required; a plan reviewed but never exercised does not satisfy the paragraph.

Testing programme sufficiency review

Annual, paragraph 31. Reviews the programme itself rather than its results, and is also triggered by a material change to information assets or the business environment.

Internal audit review

Annual, paragraphs 32 to 34. Covers design and operating effectiveness, including controls maintained by related parties and third parties.

Asset classification refresh

Annual, paragraphs 20 and 21, because the control sizing in 21 depends on the classification in 20 staying current.

Third party reassessment

Annual, paragraphs 16, 22 and 28, covering capability, control design and the testing you rely on.