APRA CPS 220 Risk Management CPS220-16: Management Information System and Data Framework
The management information system must give the Board, board committees and senior management regular, accurate and timely information on the institution risk profile, and must rest on a robust data framework enabling aggregation of exposures and risk measures across business lines, prompt reporting of limit breaches and forward looking scenario analysis and stress testing, with data quality adequate for timely and accurate measurement, assessment and reporting and sound enough to base decisions on.
Maintained by Gerard Blokdyk·Verified against the published standard ·Control text last updated
What else in your programme already covers this
This control maps to 16 controls across 7 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
NIST-CSF-GV.OV-03 Organizational cybersecurity risk management performance is evaluated and reviewed for adjustments needed
NIST-CSF-GV.RM-05 Lines of communication across the organization are established for cybersecurity risks, including risks from suppliers and other third parties
NIST-CSF-ID.RA-05 Threats, vulnerabilities, likelihoods, and impacts are used to understand inherent risk and inform risk response prioritization
NIST-CSF-ID.RA-06 Risk responses are chosen, prioritized, planned, tracked, and communicated
NIST-CSF-ID.RA-09 The authenticity and integrity of hardware and software are assessed prior to acquisition and use