Regulated Customer Contract Checker
Standards ยท CPS 234

APRA CPS 234 Information Security

Rendered when "APRA CPS 234" is ticked and the customer reaches it. The register cites 4 of its 24 clauses, behind 3 findings: breach-notice clocks that disagree, financial-entity customer with no dora or cps 230 terms shown, audit rights granted, and on the rows it reaches.

Clause text from The Art of Service standards library at compliance.theartofservice.com, read against the held text of each standard and cited to its clause: our close statement of each clause, not the instrument verbatim. Where the UK text is held only as a summary, the EU GDPR article of the same number is quoted and the page says so. Source framework: APRA CPS 234 Information Security. What it expects of an agreement: the CPS 234 regime page.

Clauses cited

4 of 24
CPS 234 para 16 Assessment of Related Party and Third Party Capability

Where a related party or third party manages information assets, the entity must assess that party information security capability in proportion to the consequences of an incident affecting those assets.

Evidence an auditor accepts: Third party and related party security capability assessments; Register of parties managing information assets; Consequence rating driving assessment depth
Where it usually falls short: Assessment limited to outsourced material business activities
APRA CPS 234 Information Security in The Art of Service standards library
CPS 234 para 27 Internal Audit Assessment of Third Party Control Assurance

Internal audit must assess the control assurance provided by a related party or third party where an incident affecting the assets could materially affect the entity or its customers and internal audit intends to rely on that assurance.

Evidence an auditor accepts: Reliance decisions recorded with supporting assessment; Assessment of the third party assurance reports relied upon; Materiality determination for each reliance
Where it usually falls short: Third party assurance accepted without assessment
APRA CPS 234 Information Security in The Art of Service standards library
CPS 234 para 35 APRA Notification of Material Incidents within 72 Hours

APRA must be notified as soon as possible and no later than 72 hours after the entity becomes aware of an incident that materially affected or could have materially affected the entity or its customers, or that has been notified to another regulator in any jurisdiction.

Evidence an auditor accepts: Notification records with awareness and submission timestamps; Materiality assessment criteria and decision records; Register of notifications made to other regulators
Where it usually falls short: Clock started at incident confirmation rather than awareness
APRA CPS 234 Information Security in The Art of Service standards library
CPS 234 P22 Evaluation of Third Party Control Design

Where a related party or third party manages the entity information assets, the entity must evaluate the design of that party controls protecting those assets.

Evidence an auditor accepts: Design evaluations of third party control sets; Assurance reports reviewed with entity conclusions recorded; Scope evidence covering all parties managing information assets
Where it usually falls short: Reliance on a certificate with no design evaluation
APRA CPS 234 Information Security in The Art of Service standards library

See which clauses your list engages

Paste the list of customer agreements and every row names the clauses behind it. Eight agreements free, no account.

Check my contract list