# APRA Prudential Standard CPS 234 Information Security

Framework id: `apra_cps_234`. Regulatory. Publisher: Australian Prudential Regulation Authority. Version: 2019. Region: Australia. Mapping licence: CC BY-SA 4.0.
Source text: https://www.apra.gov.au/sites/default/files/cps_234_july_2019_for_public_release.pdf

Each line is a clause, the NIST SP 800-53 controls OSA maps to it, and OSA's estimate of how far those controls cover it.
Clause titles and coverage figures are OSA's own summaries and estimates. No line-by-line check against the source text is recorded for this framework, so quote the source, not this card.

## Clauses (11, average coverage 79%)
- Para 15 An APRA-regulated entity must maintain an information security capability commensurate with the size and extent of threats to its information assets: PM-01, PM-03, PM-13, PM-09, PL-09, PL-10, RA-07 (78%)
- Para 16-17 Board must ensure adequate maintenance of information security, senior management implement information security controls: PM-01, PM-02, PS-09 (68%)
- Para 18 Clearly defined information security-related roles and responsibilities: PM-02, PS-01, PS-02, PL-01, PS-09 (88%)
- Para 19-20 Maintain information security capability to manage information security vulnerabilities and threats commensurate with threats: PM-13, AT-02, AT-03, PM-03, RA-05, SI-02, AT-06, RA-07 (82%)
- Para 21 Information asset identification and classification: RA-02, CM-08, PM-05, CM-12, CM-13 (90%)
- Para 22-23 Information security controls must protect information assets commensurate with criticality and sensitivity, and be subject to testing: AC-02, AC-03, AC-06, AC-17, SC-07, SC-08, SC-12, SC-13, SC-28, SI-02, SI-03, SI-04, SI-07, AU-02, AU-03, AU-06, AU-09, AU-12, CA-02, CA-08, SC-45, SI-16 (87%)
- Para 24 Testing by an independent party: CA-02, CA-08 (85%)
- Para 25 Notify APRA of material information security incidents: IR-06, IR-09 (67%)
- Para 26 Notify APRA of material information security control weaknesses: CA-05, IR-06, PM-04, RA-07 (62%)
- Para 27-28 Internal audit review of information security controls: CA-02, PM-06 (80%)
- Para 29-33 Related party and third party arrangements: SA-04, SA-09, SR-01, SR-03, SR-06, SA-21 (78%)

## More
- A pattern's controls with their clauses in this framework: /api/v1/patterns/{id}/crosswalk?framework=apra_cps_234
- Control-to-clause mappings as JSON: /api/v1/frameworks/apra_cps_234?fields=mappings&per_page=100
- Rationale and gaps for each clause, as JSON: https://raw.githubusercontent.com/opensecurityarchitecture/osa-data/main/data/framework-coverage/apra-cps-234.json
- Page for people: /frameworks/apra-cps-234/
