Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Clear out junk files and repair common Windows errors3Fix the driver behind crashes, sound loss and screen glitchesSome links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
CPS 234 compliance is an ongoing information-security operating model—not a certification or a one-off checklist. APRA-regulated entities must maintain security capability proportionate to their risks, identify and classify information assets, implement and test controls, oversee third parties, and notify APRA when defined thresholds are met. This guide sets out a practical way to build that program and the evidence to demonstrate it.
As of 23 September 2026, APRA lists CPS 234 as in force. CPS 230 Operational Risk Management has also been in force since 1 July 2026, making operational resilience and service-provider management important context for CPS 234 work. APRA’s CPS 234 page and its current prudential-standards listing are the authoritative starting points.
What CPS 234 requires—and who it applies to
Prudential Standard CPS 234 Information Security is an enforceable APRA standard that commenced on 1 July 2019. It applies to APRA-regulated entities across industries including authorised deposit-taking institutions (ADIs), insurers, private health insurers and registrable superannuation entity (RSE) licensees. Check the entity’s regulatory status and the standard’s scope rather than assuming that every company in a banking, insurance or superannuation group is independently regulated.
A technology supplier is not automatically an APRA-regulated entity because it serves a regulated customer. However, the regulated entity’s obligations extend to information assets managed by related parties and third parties. Hosting, processing or administering data elsewhere does not transfer the entity’s accountability: it must assess supplier capability and evaluate the design and testing of controls protecting its assets. CPS 234
#1 Best Overall
APRA’s CPG 234 offers implementation guidance and examples; it is not itself an enforceable standard or an exhaustive checklist. CPS 234 does not prescribe one technology stack, certification or control framework. An entity chooses an approach suited to its risks and must be able to demonstrate that it works.
Turn the obligations into accountable governance
The Board retains ultimate responsibility for information security. Senior management and the entity’s governance arrangements must ensure responsibilities for decisions, approvals, oversight, operations and other security functions are clearly defined. A capable security team is not enough if the Board receives reporting that obscures material risks or fails to support oversight.
Assign named owners and decision rights before building the control program. A practical accountability matrix should identify who is accountable, responsible, consulted and informed for each key obligation.
- Board: ultimate accountability, oversight and review of material risks and performance.
- Senior management and committees: strategy execution, resourcing, escalation and decisions within delegated authority.
- CISO or equivalent: security program coordination, standards, risk advice and consolidated reporting.
- Information-asset owners: business context, classification, risk decisions and confirmation that controls meet business needs.
- Technology and operations teams: implementation and operation of technical controls, change processes and recovery capabilities.
- Risk and compliance: challenge, obligation mapping, monitoring and escalation.
- Internal audit: independent review of control design and operating effectiveness.
- Procurement and third-party-risk teams: supplier due diligence, contract terms and ongoing oversight.
- Related parties and external providers: agreed security controls, evidence and cooperation under the entity’s oversight.
Produce a CPS 234 accountability matrix, relevant board and committee terms of reference, named owners for critical assets, escalation paths for deficiencies and a decision-rights matrix for exceptions and risk acceptance. Board reporting should show critical assets, material risks, control-test outcomes, open weaknesses and remediation, incidents, third-party exposure and trends over time—not just technical activity counts.
Build a complete information-asset and supplier inventory
CPS 234’s information-asset concept includes information and information technology, such as software, hardware and data in physical or digital form. An inventory limited to production servers will miss important exposures. Include business information, the systems that use it, supporting infrastructure and assets managed by suppliers. CPS 234
Reconcile discovery sources such as configuration-management data, identity systems, procurement and finance records, data governance, cloud accounts and vendor registers. Include customer and member data; transaction, policy, claims and payment platforms; identity providers; data warehouses; endpoints; networks; SaaS; source-code repositories; secrets and cryptographic keys; backups and disaster-recovery environments; test systems; APIs; paper records; and managed-service environments.
For each asset, record enough to support classification, risk decisions, control selection and testing:
- Unique identifier, asset name, business owner and technical owner.
- Business process supported, data types and confidentiality or sensitivity rating.
- Integrity requirements, availability needs, criticality and recovery objectives.
- Dependencies, hosting location and geography, and related-party or third-party involvement.
- Authentication method and key preventive, detective and recovery controls.
- Last risk assessment and control test, known weaknesses, and planned changes or decommissioning date.
Map data flows and service dependencies, including fourth parties where relevant. That gives the entity a way to see not only where data resides but also which identity, network, supplier and recovery services could affect a critical business process.
Classify assets by sensitivity, criticality and impact
CPS 234 requires classification based on the potential effect of an information-security incident on the entity or the interests of depositors, policyholders, beneficiaries or other customers. Classification should be more useful than a label such as “confidential”: it must help determine the protection and testing an asset needs. CPS 234
- Sensitivity: consequences if confidentiality or integrity is lost.
- Criticality: consequences of loss or degradation of availability or service operation.
- Business impact: financial, operational, legal, customer, prudential and reputational effects.
- Threat exposure: internet exposure, privileged access, supplier dependency, concentration risk and relevant threat activity.
The following four-level scheme is an implementation example, not an APRA-prescribed classification model:
| Example level | Illustrative asset | Expected treatment |
|---|---|---|
| Critical | Core transaction, payment, claims or member-benefit system | Strong preventive, detective, recovery and resilience controls, with independent assurance |
| High | Sensitive customer-data platform or identity service | Enhanced access, monitoring, encryption, vulnerability management and testing |
| Moderate | Internal business system with limited sensitive data | Baseline controls and risk-based testing |
| Low | Non-sensitive support information | Proportionate baseline protection and lifecycle controls |
Document why an asset received its rating, who approved it and what the rating means for controls, recovery and test frequency. Revisit classification when business use, data, threats, dependencies or impact changes.
Free tools Windows power users keep installed
One-click scans. No signup required.
Assess gaps and set risk-based control requirements
Map CPS 234 obligations to the entity’s existing controls, policies and evidence. Use CPG 234 as guidance, not as a universal list of mandatory technical settings. Where relevant, account for CPS 230’s operational-resilience and service-provider obligations as a related but distinct prudential standard; neither standard replaces the other. CPG 234 · APRA standards listing
For every gap, record the affected assets, risk and impact, existing evidence, accountable owner, treatment decision and target date. Prioritize critical assets, exposed services, privileged access, identity infrastructure, backups and recovery, high-risk unpatched systems, monitoring gaps, unassessed suppliers and weaknesses that may not be remediated promptly.
CPS 234 requires controls proportionate to threats and vulnerabilities, asset criticality and sensitivity, lifecycle stage and potential consequences of an incident. That means the same control need not be implemented identically for every asset. Document the rationale for stronger controls, alternative treatment or accepted residual risk.
Rank #3
Identity, access and data protection
Use strong authentication, least privilege, role-based access, segregation of duties, joiner-mover-leaver processes, access recertification, service-account governance, emergency-access controls and secure remote access. Consider role, location, access duration, device status and connection method when making access decisions, as discussed in CPG 234. Protect data with appropriate encryption in transit and at rest, key management, data-loss controls, retention and secure destruction, access logging, and masking of production data used in development or testing.
Recommended Free Tools
Vulnerability, endpoint, network and cloud security
Maintain asset discovery and vulnerability scanning, risk-based remediation deadlines, emergency patch procedures, exception approvals and plans for unsupported systems. Use secure configuration baselines, endpoint detection, network segmentation, firewall and gateway controls, cloud identity and logging, administrative-session monitoring, protected backups and security monitoring. External attack-surface monitoring can help identify exposed assets that are missing from internal records.
Secure software and change
Include security in requirements, design, selection, configuration, testing, implementation and decommissioning. For internally developed and acquired software, consider threat modelling, architecture review, code review, dependency analysis, secret scanning, pre-release security testing, change control, secure defaults and vulnerability disclosure and patch processes. Review SaaS configuration and integrations rather than assuming the provider’s baseline covers the entity’s responsibilities. CPG 234 discusses security across the software lifecycle and vendor-provided software. CPG 234
Logging, detection, backup and recovery
Centralize relevant logs, synchronize time, define alert triage and detection coverage, and preserve evidence during incidents. Set recovery requirements for important assets and verify that backups are protected and usable through restore tests. APRA has separately highlighted security and adequacy of backups in its letter to all entities.
Prepare incident response and meet notification deadlines
The entity must maintain mechanisms to detect and respond to information-security incidents in a timely manner. It must have plans for incidents that could plausibly occur and review and test those plans annually. Build procedures that cover preparation, detection and triage, containment, eradication, recovery, regulatory and stakeholder notification, evidence preservation, post-incident review and corrective-action tracking. CPS 234
CPS 234 has two distinct APRA notification triggers. In both cases, notify as soon as possible, subject to the applicable maximum timeframe:
| What must be assessed | When CPS 234 notification is required | Latest deadline |
|---|---|---|
| Information-security incident | The incident materially affected, or had the potential to materially affect, the entity or relevant customer interests, or was notified to another regulator | As soon as possible and no later than 72 hours after becoming aware |
| Material information-security control weakness | The weakness is material and the entity expects it cannot be remediated in a timely manner | As soon as possible and no later than 10 business days after becoming aware |
These are not blanket deadlines for every cyber event or every control failure. Set materiality criteria, escalation roles, legal and risk review, APRA contacts, decision logs and out-of-hours coverage before an event occurs. Escalate uncertain cases promptly rather than waiting for perfect information. CPG 234 says APRA expects notification as soon as possible even when incident details or the intended response are incomplete. It also states that a CPS 232 notification is taken to be a CPS 234 notification when an information-security incident also triggers CPS 232 notification criteria. CPG 234
Test controls systematically and obtain independent assurance
Controls must be tested for effectiveness through a systematic program. Testing should reflect the rate of change in threats and vulnerabilities, asset criticality and sensitivity, potential incident consequences, exposure to untrusted environments, and materiality and frequency of asset changes. Testing must be performed by appropriately skilled, functionally independent specialists. CPS 234
There is no single frequency that suits every control or asset. The calendar below is an example operating model, not a universal APRA schedule; adjust it to the entity’s risks and change profile.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →| Example cadence | Possible activities |
|---|---|
| Continuous or daily | Security monitoring, endpoint status, backup status and privileged-event review |
| Monthly | Vulnerability remediation, failed-control review and access exceptions |
| Quarterly | Privileged-access review, supplier-risk review and control-owner attestations |
| Six-monthly | Phishing exercises, restore tests and targeted technical testing |
| Annually | Incident-response exercise, appropriate penetration testing, control-program review and internal-audit coverage |
| After material change | Reassess controls, dependencies, testing scope and residual risk |
Separate routine control operation from independent testing and assurance. Internal audit must review design and operating effectiveness, including controls maintained by related parties and third parties; assurance personnel must be appropriately skilled. External assurance, penetration tests, vendor attestations and certifications can contribute evidence, but assess their scope, period, exceptions, complementary user controls and relevance to the entity’s assets. A SOC 2 report, ISO 27001 certificate or cloud-provider attestation does not by itself establish CPS 234 compliance.
Make third-party and cloud risk auditable
The regulated entity remains accountable when another party hosts, processes or administers its information assets. Due diligence and ongoing oversight should establish whether the provider’s capability and controls are sufficient for the asset’s risk, and whether available testing evidence actually covers the entity’s use of the service. CPS 234
Assess supplier governance and accountability; data location; access and privileged access; encryption; logging; vulnerability management; secure development; incident notification; continuity and recovery; subcontractors; concentration risk; exit and portability; secure deletion; audit and assurance rights; testing evidence; regulatory cooperation; and material-change notification.
Contracts should make security obligations operational. Specify minimum controls, incident-notification periods short enough to support the entity’s own obligations, cooperation with APRA and internal audit, access to assurance reports, testing or inspection rights, subcontractor notification or approval, data-location commitments, recovery objectives, vulnerability and patch obligations, termination assistance and secure deletion. APRA’s cloud outsourcing information paper discusses cloud services in the context of multiple prudential standards and guidance.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Keep evidence that proves operation, not just intent
A policy shows what should happen; operating evidence shows whether it did. Maintain evidence that a control ran, was reviewed, produced an outcome and led to remediation when it failed. A usable evidence register can include:
Best Value
- Board minutes, security reporting, security strategy, policies and standards.
- Asset register, classification methodology, data-flow and dependency maps, and risk assessments.
- Control library, named control owners, access-review records and training acknowledgements.
- Vulnerability reports, patch records, exceptions, change records and remediation plans.
- Incident plans, exercises, incident tickets, decision logs and APRA notification records.
- Control-test plans and results, penetration-test reports, internal-audit reports and follow-up.
- Supplier assessments, contracts, assurance reports and shared-responsibility records.
- Backup and recovery test results, risk-acceptance decisions and evidence of corrective action.
Use one evidence and remediation workflow where practical, but retain traceability from obligation to asset, control, test, issue, decision and closure. A dashboard that says “pass” without showing scope, date, exceptions or follow-up is weak assurance.
Implement the program in phases
Phase 1: Confirm scope and ownership
Document applicability, name an executive sponsor and program manager, identify the Board or committee owner, create an accountability matrix and establish an obligations register. The phase is complete when each obligation has a named accountable owner.
Phase 2: Establish assets, data flows and suppliers
Build the information-asset inventory, classification method, supplier and fourth-party view, data-flow map and critical-service dependency map. Complete this phase when the entity can identify its critical and sensitive assets and the parties managing them.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Phase 3: Assess gaps and risk
Map controls to CPS 234, relevant CPG 234 guidance, CPS 230 obligations where applicable, the entity’s chosen framework and internal policies. Give each gap a risk rating, owner, target date and treatment decision.
Phase 4: Remediate priority weaknesses
Address high-impact gaps first, especially those involving critical assets, exposed services, privileged access, identity, backups, unpatched high-risk systems, monitoring, supplier assurance and notification ambiguity. Remediate, formally accept or escalate high-risk gaps.
Phase 5: Operationalize and test
Make access, vulnerability management, secure change, incident response, supplier oversight, backup testing, exception handling and evidence collection repeatable. Build a risk-based test plan, use appropriately skilled independent testers and give internal audit sufficient scope to review control effectiveness.
Phase 6: Report and improve
Report control effectiveness, material weaknesses, incidents, threat changes, testing coverage, supplier exposure, remediation and accepted risks to the Board. Embed the program into normal governance, risk, change and audit cycles, and reassess controls after material changes.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteChoose tools for the problem they solve
Tooling can reduce administrative effort, but no platform determines on its own whether controls are proportionate, an incident is materially significant, residual risk is acceptable or the Board has discharged its oversight duties.
- Internal spreadsheets and existing systems: may suit a mature team with reliable evidence sources and bespoke requirements; the trade-off is more manual handling and risk of fragmented, stale ownership.
- Compliance-automation or GRC platform: can centralize evidence and control tracking, support integrations and recurring workflows; assess implementation effort, subscription cost, lock-in and whether it tests real resilience rather than configuration alone.
- Specialist assessment: can provide an independent gap view or remediation roadmap; a one-off report can go stale, so verify assessor competence, independence, scope and follow-through.
- Cloud-provider mappings: can support understanding of provider controls and shared responsibilities, but do not establish that the entity’s configuration, processes, testing and governance are sufficient.
- Security testing or managed services: may fill technical testing or detection-and-response capability gaps, but must feed into the entity’s own control ownership, escalation and assurance processes.
Google Cloud and Microsoft publish CPS 234-related compliance material. These are vendor resources, not APRA approvals or substitutes for entity-specific assessment: Google Cloud CPS 234 information and Microsoft’s APRA compliance mapping.
Common implementation failures and how to correct them
- Preparing only for an annual review: assign control owners and collect dated operating evidence throughout the year.
- Focusing only on technical controls: map obligations across governance, people, process, suppliers, technology and evidence.
- Accepting a supplier certificate at face value: assess scope, date, exceptions, complementary controls and relevance to the services used.
- Working from an incomplete asset list: reconcile cloud, SaaS, backups, test environments, APIs, service accounts and supplier records.
- Debating reportability during an incident: define materiality, escalation, decision ownership, notification contacts and after-hours coverage in advance.
- Confusing policy with effectiveness: require test results, exceptions, dated evidence and tracked remediation.
- Letting automation make risk decisions: use tools to gather evidence, while retaining human judgment over classification, materiality, residual risk and acceptance.
- Skipping reassessment after change: trigger control review and testing after migrations, major releases, acquisitions or supplier changes.
For director-level oversight, APRA also publishes a guide for directors.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

