APRA CPS 234 Information Security
Rendered when "APRA CPS 234" is ticked and the customer reaches it. The register cites 4 of its 24 clauses, behind 3 findings: breach-notice clocks that disagree, financial-entity customer with no dora or cps 230 terms shown, audit rights granted, and on the rows it reaches.
Clause text from The Art of Service standards library at compliance.theartofservice.com, read against the held text of each standard and cited to its clause: our close statement of each clause, not the instrument verbatim. Where the UK text is held only as a summary, the EU GDPR article of the same number is quoted and the page says so. Source framework: APRA CPS 234 Information Security. What it expects of an agreement: the CPS 234 regime page.
Clauses cited
4 of 24CPS 234 para 16 Assessment of Related Party and Third Party CapabilityWhere a related party or third party manages information assets, the entity must assess that party information security capability in proportion to the consequences of an incident affecting those assets.
Where it usually falls short: Assessment limited to outsourced material business activities
APRA CPS 234 Information Security in The Art of Service standards library
CPS 234 para 27 Internal Audit Assessment of Third Party Control AssuranceInternal audit must assess the control assurance provided by a related party or third party where an incident affecting the assets could materially affect the entity or its customers and internal audit intends to rely on that assurance.
Where it usually falls short: Third party assurance accepted without assessment
APRA CPS 234 Information Security in The Art of Service standards library
CPS 234 para 35 APRA Notification of Material Incidents within 72 HoursAPRA must be notified as soon as possible and no later than 72 hours after the entity becomes aware of an incident that materially affected or could have materially affected the entity or its customers, or that has been notified to another regulator in any jurisdiction.
Where it usually falls short: Clock started at incident confirmation rather than awareness
APRA CPS 234 Information Security in The Art of Service standards library
CPS 234 P22 Evaluation of Third Party Control DesignWhere a related party or third party manages the entity information assets, the entity must evaluate the design of that party controls protecting those assets.
Where it usually falls short: Reliance on a certificate with no design evaluation
APRA CPS 234 Information Security in The Art of Service standards library
See which clauses your list engages
Paste the list of customer agreements and every row names the clauses behind it. Eight agreements free, no account.
Check my contract list