Jump to navigation Jump to search
The Australian Prudential Regulation Authority's (APRA) Information Security Standard CPS 234 institutes requirements around information asset identification and classification, information security roles and responsibilities, implementation and testing of information security controls, incident management, internal audit, and breach notification.
- It makes clear that the Board is ultimately responsible for information security.
- It calls for protective measures to be commensurate with the size of the organisation and the threats faced.
- It includes requirements around management of third party (supplier) risk management.