APRA CPS 234
5 of the 24 clauses of APRA CPS 234 are cited by this register, on Board and committee pack, Breach notification report pack, Incident and service report, Incident response exercise or drill, Material control weakness report, Regulator incident notification, Risk register and control status report, Security alert and monitoring report. Every one below is quoted from the copy we hold, with the hours it states where it states any.
Testing results that identify control deficiencies which cannot be remediated in a timely way must be escalated and reported to the Board or senior management.
What an assessor asks to see: Escalation records for unremediated deficiencies; Board or senior management reporting packs; Remediation tracker with timeliness assessment. Where it usually falls short: Deficiencies tracked operationally but never escalated
The entity must have robust mechanisms to detect information security incidents and respond to them in a timely way.
What an assessor asks to see: Detection tooling and monitoring coverage evidence; Incident records showing detection and response times; Defined response timeliness expectations. Where it usually falls short: Detection coverage gaps across classified assets
Information security response plans must be reviewed and tested annually to confirm they remain effective and fit for purpose.
What an assessor asks to see: Annual review and test records for response plans; Exercise reports and resulting plan updates; Evidence of fitness for purpose conclusions. Where it usually falls short: Plans reviewed but never exercised
APRA must be notified as soon as possible and no later than 72 hours after the entity becomes aware of an incident that materially affected or could have materially affected the entity or its customers, or that has been notified to another regulator in any jurisdiction.
What an assessor asks to see: Notification records with awareness and submission timestamps; Materiality assessment criteria and decision records; Register of notifications made to other regulators. Where it usually falls short: Clock started at incident confirmation rather than awareness
APRA must be notified as soon as possible and no later than 10 business days after the entity becomes aware of a material information security control weakness it expects it will not be able to remediate in a timely way.
What an assessor asks to see: Notification records with awareness dates; Weakness register with materiality and remediation feasibility assessments; Evidence linking testing and audit findings to notification decisions. Where it usually falls short: No process connecting the weakness register to the notification duty
Requirement text quoted from the standards themselves, published at compliance.theartofservice.com, the same publisher as this register, read against the held text of each standard: our statement of each clause, not the instrument verbatim. The whole standard on compliance.theartofservice.com.