APRA CPS 234: the evidence behind every control
24 controls. For each, the artefacts auditors ask for, which ones a system already holds, and the first move to stop evidencing it by periodic review.
Roles and Responsibilities
CPS 234 para 13Board Responsibility for Information Security hardCPS 234 para 14Definition of Information Security Roles and Responsibilities hardInformation Security Capability
CPS 234 para 15Information Security Capability hardCPS 234 para 17Active Maintenance of Capability Against Change moderateThird Party Arrangements
CPS 234 para 16Assessment of Related Party and Third Party Capability hardCPS 234 para 22Evaluation of Third Party Control Design hardCPS 234 para 28Assessment of Reliance on Third Party Control Testing hardPolicy Framework
CPS 234 para 18Information Security Policy Framework moderateCPS 234 para 19Policy Direction to All Responsible Parties hardInformation Asset Identification and Classification
Implementation of Controls
CPS 234 para 21Implementation of Information Security Controls hardCPS 234 para 23Detection and Response Mechanisms easyIncident Management
CPS 234 para 24Information Security Response Plans hardCPS 234 para 25Response Plan Content and Escalation Mechanisms hardCPS 234 para 26Annual Review and Testing of Response Plans hardTesting Control Effectiveness
CPS 234 para 27Systematic Control Testing Program hardCPS 234 para 29Escalation of Unremediated Testing Deficiencies hardCPS 234 para 30Independence and Skill of Testing Personnel hardCPS 234 para 31Annual Review of Testing Program Sufficiency hardInternal Audit
CPS 234 para 32Internal Audit Review of Information Security Controls hardCPS 234 para 33Skill of Personnel Providing Control Assurance hardCPS 234 para 34Internal Audit Assessment of Third Party Control Assurance hard