Skip to main content
APRA CPS 234 is the Australian Prudential Regulation Authority’s information security standard. It requires APRA-regulated entities to maintain information security capabilities commensurate with the size and extent of threats to their information assets.

Who needs CPS 234?

Authorized deposit-taking institutions (banks), general insurers, life insurers, private health insurers, and registrable superannuation entities regulated by APRA in Australia.

Key requirements

RequirementDescription
Information Security CapabilityMaintain capability commensurate with threats
Policy FrameworkComprehensive information security policy
Information Asset ManagementClassify and manage information assets
Access ControlsRestrict access based on role and necessity
Incident ManagementDetect, report, and respond to incidents
TestingRegular testing of security controls
Internal AuditAssurance that controls are operating effectively

How DSALTA helps

  • CPS 234 controls mapped to all APRA requirements
  • Asset classification through inventory management
  • Testing and evidence automated from integrations
  • Cross-framework mapping — overlaps with ISO 27001, SOC 2, and DORA

Frequently asked questions

CPS 234 is prescriptive and specific to Australian financial services. ISO 27001 provides a broader ISMS framework. Implementing ISO 27001 covers most CPS 234 requirements.
Notify APRA as soon as possible and no later than 72 hours after becoming aware of a material information security incident or control weakness.