logo

How to Comply With CPS 234 (Updated for 2023) | UpGuard

ID: f3a580c1-b20b-5a17-a0e0-01a80b545ac0

STIX ID: report--f3a580c1-b20b-5a17-a0e0-01a80b545ac0

Feed Name: UpGuard Blog

Date Published: 2023-12-20

Date Updated: 2026-05-01

...
...

This report explains APRA’s CPS 234 prudential standard for information security, detailing who must comply (banks, insurers, superannuation funds, and related third parties), governance responsibilities, and key requirements including capability building, policy frameworks, asset classification, implementation of controls, incident management, control testing, internal audit, and timely notification to APRA (e.g., within 72 hours for material incidents). It outlines practical control areas (vulnerability/threat management, lifecycle, physical, change, software, data leakage, cryptographic, technology, and third‑party controls) and emphasizes continuous monitoring, assurance, and coordination with vendors. The document also highlights how UpGuard’s tools can support compliance, third‑party risk management, continuous monitoring, and reporting.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.