The Board must make an annual risk management declaration to APRA satisfying the requirements of Attachment A, signed by the chairperson of the Board and the chairperson of the Board Risk Committee, or for a Category C insurer, foreign ADI or EFLIC by the senior officer outside Australia or two members of the Compliance Committee as relevant.
Maintained by Gerard Blokdyk·Verified against the published standard ·Control text last updated
What else in your programme already covers this
This control maps to 10 controls across 6 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
NIST-CSF-GV.OV-01 Cybersecurity risk management strategy outcomes are reviewed to inform and adjust strategy and direction
NIST-CSF-GV.OV-03 Organizational cybersecurity risk management performance is evaluated and reviewed for adjustments needed
NIST-CSF-GV.RR-01 Organizational leadership is responsible and accountable for cybersecurity risk and fosters a culture that is risk-aware, ethical, and continually improving