The CPS 234 module tracks compliance with APRA Prudential Standard CPS 234 Information Security, which applies to APRA-regulated entities in Australia: authorised deposit-taking institutions including foreign ADIs and authorised banking NOHCs, general insurers including Category C insurers, life companies including friendly societies and EFLICs, private health insurers registered under the PHIPS Act, and RSE licensees in respect of their business operations.
The standard commenced on 1 July 2019. Where your information assets are managed by a third party, it applied from the earlier of the next renewal date of that contract or 1 July 2020.
What Venvera tracks
CPS 234 contains 36 numbered paragraphs. Paragraphs 1 to 12 cover authority, application, interpretation and definitions and create no obligations. Paragraphs 13 to 36 are the operative requirements, and those 24 are what Venvera ships as requirement rows, grouped under the standard's own nine headings.
| Section | Paragraphs | What it covers |
|---|---|---|
| Roles and responsibilities | 13 to 14 | Board ultimate responsibility, and defined roles for the Board, senior management, governing bodies and individuals |
| Information security capability | 15 to 17 | Capability sized against threats, third party capability, and maintaining capability as threats change |
| Policy framework | 18 to 19 | The policy framework, and direction for every party with an obligation |
| Asset identification and classification | 20 | Classification by criticality and sensitivity, reflecting customer impact |
| Implementation of controls | 21 to 22 | Controls sized against four factors, and evaluation of third party control design |
| Incident management | 23 to 26 | Detection and response, response plans, plan content and escalation, annual review and testing |
| Testing control effectiveness | 27 to 31 | Systematic testing programme, third party testing, escalation, independent testers, annual programme review |
| Internal audit | 32 to 34 | Review of control design and operating effectiveness, skilled assurance, assessment of third party assurance |
| APRA notification | 35 to 36 | 72 hours for a material incident, 10 business days for a material control weakness |
Dashboard
The dashboard shows implementation coverage across the 24 requirements, a breakdown by the nine sections, and the maturity score from the gap assessment if one has been completed. Coverage and maturity answer different questions: coverage says whether a requirement is implemented, maturity says how well the duty is discharged.
Recurring duties
Five obligations land on the compliance calendar with owners, dates and reminders. Each names the paragraph it serves.
Annual, paragraph 26. Both a review and a test are required; a plan reviewed but never exercised does not satisfy the paragraph.
Annual, paragraph 31. Reviews the programme itself rather than its results, and is also triggered by a material change to information assets or the business environment.
Annual, paragraphs 32 to 34. Covers design and operating effectiveness, including controls maintained by related parties and third parties.
Annual, paragraphs 20 and 21, because the control sizing in 21 depends on the classification in 20 staying current.
Annual, paragraphs 16, 22 and 28, covering capability, control design and the testing you rely on.