Skip to main content
APRA CPS 234 is the Australian Prudential Regulation Authority’s information security standard. It requires APRA-regulated entities to maintain information security capabilities commensurate with the size and extent of threats to their information assets.

Who needs CPS 234?

Authorized deposit-taking institutions (banks), general insurers, life insurers, private health insurers, and registrable superannuation entities regulated by APRA in Australia.

Key requirements

How DSALTA helps

  • CPS 234 controls mapped to all APRA requirements
  • Asset classification through inventory management
  • Testing and evidence automated from integrations
  • Cross-framework mapping — overlaps with ISO 27001, SOC 2, and DORA
1 of DSALTA’s automated checks contributes evidence to this framework, drawn from 1 integration. Browse them in the Compliance Tests catalog. They are linked through the controls each check satisfies, so a single check usually contributes to several frameworks at once — the count is not a list of checks unique to this one.

Frequently asked questions

CPS 234 is prescriptive and specific to Australian financial services. ISO 27001 provides a broader ISMS framework. Implementing ISO 27001 covers most CPS 234 requirements.
Notify APRA as soon as possible and no later than 72 hours after becoming aware of a material information security incident or control weakness.