Fall ResetAmazon USFall reset deals: check better picks before checkoutAmazon US: today's deals, useful picks and quick comparisons.Check DealsPC HealthRecommendedCrashes, freezes, slowdowns? Check your PC nowSpot repairable issues before they interrupt work.Check PCFall ResetAmazon USWork and home upgrades are worth comparing todayAmazon US: today's deals, useful picks and quick comparisons.See Picks×
Skip to content
Blog

An Actionable CPS 234 Implementation Guide for APRA-Regulated Entities

By TheFinanceBase Team12 min read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

CPS 234 compliance is an ongoing information-security operating model—not a certification or a one-off checklist. APRA-regulated entities must maintain security capability proportionate to their risks, identify and classify information assets, implement and test controls, oversee third parties, and notify APRA when defined thresholds are met. This guide sets out a practical way to build that program and the evidence to demonstrate it.

As of 23 September 2026, APRA lists CPS 234 as in force. CPS 230 Operational Risk Management has also been in force since 1 July 2026, making operational resilience and service-provider management important context for CPS 234 work. APRA’s CPS 234 page and its current prudential-standards listing are the authoritative starting points.

What CPS 234 requires—and who it applies to

Prudential Standard CPS 234 Information Security is an enforceable APRA standard that commenced on 1 July 2019. It applies to APRA-regulated entities across industries including authorised deposit-taking institutions (ADIs), insurers, private health insurers and registrable superannuation entity (RSE) licensees. Check the entity’s regulatory status and the standard’s scope rather than assuming that every company in a banking, insurance or superannuation group is independently regulated.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A technology supplier is not automatically an APRA-regulated entity because it serves a regulated customer. However, the regulated entity’s obligations extend to information assets managed by related parties and third parties. Hosting, processing or administering data elsewhere does not transfer the entity’s accountability: it must assess supplier capability and evaluate the design and testing of controls protecting its assets. CPS 234

APRA’s CPG 234 offers implementation guidance and examples; it is not itself an enforceable standard or an exhaustive checklist. CPS 234 does not prescribe one technology stack, certification or control framework. An entity chooses an approach suited to its risks and must be able to demonstrate that it works.

Turn the obligations into accountable governance

The Board retains ultimate responsibility for information security. Senior management and the entity’s governance arrangements must ensure responsibilities for decisions, approvals, oversight, operations and other security functions are clearly defined. A capable security team is not enough if the Board receives reporting that obscures material risks or fails to support oversight.

Assign named owners and decision rights before building the control program. A practical accountability matrix should identify who is accountable, responsible, consulted and informed for each key obligation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Board: ultimate accountability, oversight and review of material risks and performance.
  • Senior management and committees: strategy execution, resourcing, escalation and decisions within delegated authority.
  • CISO or equivalent: security program coordination, standards, risk advice and consolidated reporting.
  • Information-asset owners: business context, classification, risk decisions and confirmation that controls meet business needs.
  • Technology and operations teams: implementation and operation of technical controls, change processes and recovery capabilities.
  • Risk and compliance: challenge, obligation mapping, monitoring and escalation.
  • Internal audit: independent review of control design and operating effectiveness.
  • Procurement and third-party-risk teams: supplier due diligence, contract terms and ongoing oversight.
  • Related parties and external providers: agreed security controls, evidence and cooperation under the entity’s oversight.

Produce a CPS 234 accountability matrix, relevant board and committee terms of reference, named owners for critical assets, escalation paths for deficiencies and a decision-rights matrix for exceptions and risk acceptance. Board reporting should show critical assets, material risks, control-test outcomes, open weaknesses and remediation, incidents, third-party exposure and trends over time—not just technical activity counts.

Build a complete information-asset and supplier inventory

CPS 234’s information-asset concept includes information and information technology, such as software, hardware and data in physical or digital form. An inventory limited to production servers will miss important exposures. Include business information, the systems that use it, supporting infrastructure and assets managed by suppliers. CPS 234

Reconcile discovery sources such as configuration-management data, identity systems, procurement and finance records, data governance, cloud accounts and vendor registers. Include customer and member data; transaction, policy, claims and payment platforms; identity providers; data warehouses; endpoints; networks; SaaS; source-code repositories; secrets and cryptographic keys; backups and disaster-recovery environments; test systems; APIs; paper records; and managed-service environments.

For each asset, record enough to support classification, risk decisions, control selection and testing:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Unique identifier, asset name, business owner and technical owner.
  • Business process supported, data types and confidentiality or sensitivity rating.
  • Integrity requirements, availability needs, criticality and recovery objectives.
  • Dependencies, hosting location and geography, and related-party or third-party involvement.
  • Authentication method and key preventive, detective and recovery controls.
  • Last risk assessment and control test, known weaknesses, and planned changes or decommissioning date.

Map data flows and service dependencies, including fourth parties where relevant. That gives the entity a way to see not only where data resides but also which identity, network, supplier and recovery services could affect a critical business process.

Classify assets by sensitivity, criticality and impact

CPS 234 requires classification based on the potential effect of an information-security incident on the entity or the interests of depositors, policyholders, beneficiaries or other customers. Classification should be more useful than a label such as “confidential”: it must help determine the protection and testing an asset needs. CPS 234

  • Sensitivity: consequences if confidentiality or integrity is lost.
  • Criticality: consequences of loss or degradation of availability or service operation.
  • Business impact: financial, operational, legal, customer, prudential and reputational effects.
  • Threat exposure: internet exposure, privileged access, supplier dependency, concentration risk and relevant threat activity.

The following four-level scheme is an implementation example, not an APRA-prescribed classification model:

Example level Illustrative asset Expected treatment
Critical Core transaction, payment, claims or member-benefit system Strong preventive, detective, recovery and resilience controls, with independent assurance
High Sensitive customer-data platform or identity service Enhanced access, monitoring, encryption, vulnerability management and testing
Moderate Internal business system with limited sensitive data Baseline controls and risk-based testing
Low Non-sensitive support information Proportionate baseline protection and lifecycle controls

Document why an asset received its rating, who approved it and what the rating means for controls, recovery and test frequency. Revisit classification when business use, data, threats, dependencies or impact changes.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Assess gaps and set risk-based control requirements

Map CPS 234 obligations to the entity’s existing controls, policies and evidence. Use CPG 234 as guidance, not as a universal list of mandatory technical settings. Where relevant, account for CPS 230’s operational-resilience and service-provider obligations as a related but distinct prudential standard; neither standard replaces the other. CPG 234 · APRA standards listing

For every gap, record the affected assets, risk and impact, existing evidence, accountable owner, treatment decision and target date. Prioritize critical assets, exposed services, privileged access, identity infrastructure, backups and recovery, high-risk unpatched systems, monitoring gaps, unassessed suppliers and weaknesses that may not be remediated promptly.

CPS 234 requires controls proportionate to threats and vulnerabilities, asset criticality and sensitivity, lifecycle stage and potential consequences of an incident. That means the same control need not be implemented identically for every asset. Document the rationale for stronger controls, alternative treatment or accepted residual risk.

Identity, access and data protection

Use strong authentication, least privilege, role-based access, segregation of duties, joiner-mover-leaver processes, access recertification, service-account governance, emergency-access controls and secure remote access. Consider role, location, access duration, device status and connection method when making access decisions, as discussed in CPG 234. Protect data with appropriate encryption in transit and at rest, key management, data-loss controls, retention and secure destruction, access logging, and masking of production data used in development or testing.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Vulnerability, endpoint, network and cloud security

Maintain asset discovery and vulnerability scanning, risk-based remediation deadlines, emergency patch procedures, exception approvals and plans for unsupported systems. Use secure configuration baselines, endpoint detection, network segmentation, firewall and gateway controls, cloud identity and logging, administrative-session monitoring, protected backups and security monitoring. External attack-surface monitoring can help identify exposed assets that are missing from internal records.

Secure software and change

Include security in requirements, design, selection, configuration, testing, implementation and decommissioning. For internally developed and acquired software, consider threat modelling, architecture review, code review, dependency analysis, secret scanning, pre-release security testing, change control, secure defaults and vulnerability disclosure and patch processes. Review SaaS configuration and integrations rather than assuming the provider’s baseline covers the entity’s responsibilities. CPG 234 discusses security across the software lifecycle and vendor-provided software. CPG 234

Logging, detection, backup and recovery

Centralize relevant logs, synchronize time, define alert triage and detection coverage, and preserve evidence during incidents. Set recovery requirements for important assets and verify that backups are protected and usable through restore tests. APRA has separately highlighted security and adequacy of backups in its letter to all entities.

Prepare incident response and meet notification deadlines

The entity must maintain mechanisms to detect and respond to information-security incidents in a timely manner. It must have plans for incidents that could plausibly occur and review and test those plans annually. Build procedures that cover preparation, detection and triage, containment, eradication, recovery, regulatory and stakeholder notification, evidence preservation, post-incident review and corrective-action tracking. CPS 234

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

CPS 234 has two distinct APRA notification triggers. In both cases, notify as soon as possible, subject to the applicable maximum timeframe:

What must be assessed When CPS 234 notification is required Latest deadline
Information-security incident The incident materially affected, or had the potential to materially affect, the entity or relevant customer interests, or was notified to another regulator As soon as possible and no later than 72 hours after becoming aware
Material information-security control weakness The weakness is material and the entity expects it cannot be remediated in a timely manner As soon as possible and no later than 10 business days after becoming aware

These are not blanket deadlines for every cyber event or every control failure. Set materiality criteria, escalation roles, legal and risk review, APRA contacts, decision logs and out-of-hours coverage before an event occurs. Escalate uncertain cases promptly rather than waiting for perfect information. CPG 234 says APRA expects notification as soon as possible even when incident details or the intended response are incomplete. It also states that a CPS 232 notification is taken to be a CPS 234 notification when an information-security incident also triggers CPS 232 notification criteria. CPG 234

Test controls systematically and obtain independent assurance

Controls must be tested for effectiveness through a systematic program. Testing should reflect the rate of change in threats and vulnerabilities, asset criticality and sensitivity, potential incident consequences, exposure to untrusted environments, and materiality and frequency of asset changes. Testing must be performed by appropriately skilled, functionally independent specialists. CPS 234

There is no single frequency that suits every control or asset. The calendar below is an example operating model, not a universal APRA schedule; adjust it to the entity’s risks and change profile.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Example cadence Possible activities
Continuous or daily Security monitoring, endpoint status, backup status and privileged-event review
Monthly Vulnerability remediation, failed-control review and access exceptions
Quarterly Privileged-access review, supplier-risk review and control-owner attestations
Six-monthly Phishing exercises, restore tests and targeted technical testing
Annually Incident-response exercise, appropriate penetration testing, control-program review and internal-audit coverage
After material change Reassess controls, dependencies, testing scope and residual risk

Separate routine control operation from independent testing and assurance. Internal audit must review design and operating effectiveness, including controls maintained by related parties and third parties; assurance personnel must be appropriately skilled. External assurance, penetration tests, vendor attestations and certifications can contribute evidence, but assess their scope, period, exceptions, complementary user controls and relevance to the entity’s assets. A SOC 2 report, ISO 27001 certificate or cloud-provider attestation does not by itself establish CPS 234 compliance.

Make third-party and cloud risk auditable

The regulated entity remains accountable when another party hosts, processes or administers its information assets. Due diligence and ongoing oversight should establish whether the provider’s capability and controls are sufficient for the asset’s risk, and whether available testing evidence actually covers the entity’s use of the service. CPS 234

Assess supplier governance and accountability; data location; access and privileged access; encryption; logging; vulnerability management; secure development; incident notification; continuity and recovery; subcontractors; concentration risk; exit and portability; secure deletion; audit and assurance rights; testing evidence; regulatory cooperation; and material-change notification.

Contracts should make security obligations operational. Specify minimum controls, incident-notification periods short enough to support the entity’s own obligations, cooperation with APRA and internal audit, access to assurance reports, testing or inspection rights, subcontractor notification or approval, data-location commitments, recovery objectives, vulnerability and patch obligations, termination assistance and secure deletion. APRA’s cloud outsourcing information paper discusses cloud services in the context of multiple prudential standards and guidance.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Keep evidence that proves operation, not just intent

A policy shows what should happen; operating evidence shows whether it did. Maintain evidence that a control ran, was reviewed, produced an outcome and led to remediation when it failed. A usable evidence register can include:

  • Board minutes, security reporting, security strategy, policies and standards.
  • Asset register, classification methodology, data-flow and dependency maps, and risk assessments.
  • Control library, named control owners, access-review records and training acknowledgements.
  • Vulnerability reports, patch records, exceptions, change records and remediation plans.
  • Incident plans, exercises, incident tickets, decision logs and APRA notification records.
  • Control-test plans and results, penetration-test reports, internal-audit reports and follow-up.
  • Supplier assessments, contracts, assurance reports and shared-responsibility records.
  • Backup and recovery test results, risk-acceptance decisions and evidence of corrective action.

Use one evidence and remediation workflow where practical, but retain traceability from obligation to asset, control, test, issue, decision and closure. A dashboard that says “pass” without showing scope, date, exceptions or follow-up is weak assurance.

Implement the program in phases

Phase 1: Confirm scope and ownership

Document applicability, name an executive sponsor and program manager, identify the Board or committee owner, create an accountability matrix and establish an obligations register. The phase is complete when each obligation has a named accountable owner.

Phase 2: Establish assets, data flows and suppliers

Build the information-asset inventory, classification method, supplier and fourth-party view, data-flow map and critical-service dependency map. Complete this phase when the entity can identify its critical and sensitive assets and the parties managing them.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Phase 3: Assess gaps and risk

Map controls to CPS 234, relevant CPG 234 guidance, CPS 230 obligations where applicable, the entity’s chosen framework and internal policies. Give each gap a risk rating, owner, target date and treatment decision.

Phase 4: Remediate priority weaknesses

Address high-impact gaps first, especially those involving critical assets, exposed services, privileged access, identity, backups, unpatched high-risk systems, monitoring, supplier assurance and notification ambiguity. Remediate, formally accept or escalate high-risk gaps.

Phase 5: Operationalize and test

Make access, vulnerability management, secure change, incident response, supplier oversight, backup testing, exception handling and evidence collection repeatable. Build a risk-based test plan, use appropriately skilled independent testers and give internal audit sufficient scope to review control effectiveness.

Phase 6: Report and improve

Report control effectiveness, material weaknesses, incidents, threat changes, testing coverage, supplier exposure, remediation and accepted risks to the Board. Embed the program into normal governance, risk, change and audit cycles, and reassess controls after material changes.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Choose tools for the problem they solve

Tooling can reduce administrative effort, but no platform determines on its own whether controls are proportionate, an incident is materially significant, residual risk is acceptable or the Board has discharged its oversight duties.

  • Internal spreadsheets and existing systems: may suit a mature team with reliable evidence sources and bespoke requirements; the trade-off is more manual handling and risk of fragmented, stale ownership.
  • Compliance-automation or GRC platform: can centralize evidence and control tracking, support integrations and recurring workflows; assess implementation effort, subscription cost, lock-in and whether it tests real resilience rather than configuration alone.
  • Specialist assessment: can provide an independent gap view or remediation roadmap; a one-off report can go stale, so verify assessor competence, independence, scope and follow-through.
  • Cloud-provider mappings: can support understanding of provider controls and shared responsibilities, but do not establish that the entity’s configuration, processes, testing and governance are sufficient.
  • Security testing or managed services: may fill technical testing or detection-and-response capability gaps, but must feed into the entity’s own control ownership, escalation and assurance processes.

Google Cloud and Microsoft publish CPS 234-related compliance material. These are vendor resources, not APRA approvals or substitutes for entity-specific assessment: Google Cloud CPS 234 information and Microsoft’s APRA compliance mapping.

Common implementation failures and how to correct them

  • Preparing only for an annual review: assign control owners and collect dated operating evidence throughout the year.
  • Focusing only on technical controls: map obligations across governance, people, process, suppliers, technology and evidence.
  • Accepting a supplier certificate at face value: assess scope, date, exceptions, complementary controls and relevance to the services used.
  • Working from an incomplete asset list: reconcile cloud, SaaS, backups, test environments, APIs, service accounts and supplier records.
  • Debating reportability during an incident: define materiality, escalation, decision ownership, notification contacts and after-hours coverage in advance.
  • Confusing policy with effectiveness: require test results, exceptions, dated evidence and tracked remediation.
  • Letting automation make risk decisions: use tools to gather evidence, while retaining human judgment over classification, materiality, residual risk and acceptance.
  • Skipping reassessment after change: trigger control review and testing after migrations, major releases, acquisitions or supplier changes.

For director-level oversight, APRA also publishes a guide for directors.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Written by TheFinanceBase Team

The Team behind TheFinanceBase.

Add your note

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Recommended PC Tool
Recommended PC Tool
PC Slower Than It Used to Be?Free scan - under a minute
Crashes, No Sound, or Screen Glitches?Free driver scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.