What APRA CPS 234 sets on each scheduled job
Paragraph 35 sets 72 hours for a material incident, paragraph 36 ten business days for a material control weakness, paragraph 32 an annual test of response plans. Tick CPS 234 on the register and every job in these classes carries its row below. A lit cell is a figure the clause states; a row that reads no clock stays that way, because the register never fills a blank the standard left open.
The clock each rule sets
| Consumer class | Clock | Clause |
|---|---|---|
| Security monitoring and log review | ||
| Security alert and monitoring report | no clock | CPS 234 para 30 Detection and Response Mechanismsin a timely way |
| Incident and breach reporting | ||
| Breach notification report pack | 72h | CPS 234 para 35 APRA Notification of Material Incidents within 72 Hoursno later than 72 hours |
| Incident and service report | no clock | CPS 234 para 30 Detection and Response Mechanismsin a timely way |
| Incident response exercise or drill | 8,760h | CPS 234 para 32 Annual Review and Testing of Response Plansreviewed and tested annually |
| Regulator incident notification | 72h | CPS 234 para 35 APRA Notification of Material Incidents within 72 Hoursno later than 72 hours |
| Material control weakness report | no clock | CPS 234 para 36 APRA Notification of Material Control Weakness within 10 Business Days10 business days after becoming aware |
| no clock | CPS 234 para 28 Escalation of Unremediated Testing Deficiencies | |
| Board and management reporting | ||
| Board and committee pack | no clock | CPS 234 para 28 Escalation of Unremediated Testing Deficiencies |
| Risk register and control status report | no clock | CPS 234 para 28 Escalation of Unremediated Testing Deficiencies |
The clauses in full
The entity must have robust mechanisms to detect information security incidents and respond to them in a timely way.
What an assessor asks to see: Detection tooling and monitoring coverage evidence; Incident records showing detection and response times; Defined response timeliness expectations. Where it usually falls short: Detection coverage gaps across classified assets
APRA must be notified as soon as possible and no later than 72 hours after the entity becomes aware of an incident that materially affected or could have materially affected the entity or its customers, or that has been notified to another regulator in any jurisdiction.
What an assessor asks to see: Notification records with awareness and submission timestamps; Materiality assessment criteria and decision records; Register of notifications made to other regulators. Where it usually falls short: Clock started at incident confirmation rather than awareness
Information security response plans must be reviewed and tested annually to confirm they remain effective and fit for purpose.
What an assessor asks to see: Annual review and test records for response plans; Exercise reports and resulting plan updates; Evidence of fitness for purpose conclusions. Where it usually falls short: Plans reviewed but never exercised
APRA must be notified as soon as possible and no later than 10 business days after the entity becomes aware of a material information security control weakness it expects it will not be able to remediate in a timely way.
What an assessor asks to see: Notification records with awareness dates; Weakness register with materiality and remediation feasibility assessments; Evidence linking testing and audit findings to notification decisions. Where it usually falls short: No process connecting the weakness register to the notification duty
Testing results that identify control deficiencies which cannot be remediated in a timely way must be escalated and reported to the Board or senior management.
What an assessor asks to see: Escalation records for unremediated deficiencies; Board or senior management reporting packs; Remediation tracker with timeliness assessment. Where it usually falls short: Deficiencies tracked operationally but never escalated
Requirement text quoted from the standards themselves, published at compliance.theartofservice.com, the same publisher as this register, read against the held text of each standard: our statement of each clause, not the instrument verbatim. Every regime: the index.