APRA CPS 220 Risk Management
Documentation

APRA CPS 220 Risk Management CPS220-P35: Required Content of Risk Management Policies and Procedures

The policies and procedures the risk management strategy is required to list must include the process for identifying and assessing material risks and controls, for validating, approving and using risk measurement models, for establishing, implementing and testing mitigation strategies and control mechanisms, for monitoring, communicating and reporting risk issues including escalation of material events and incidents, for identifying, monitoring and managing potential and actual conflicts of interest, the mechanisms for monitoring and ensuring ongoing compliance with all prudential requirements, the process for ensuring consistency across the framework components, the process for establishing and maintaining contingency arrangements including robust and credible recovery plans where warranted for operating the framework in stressed conditions, and the process for reviewing the framework.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 44 controls across 12 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • NIST-CSF-GV.OC-03 Legal, regulatory, and contractual requirements regarding cybersecurity - including privacy and civil liberties obligations - are understood and managed
  • NIST-CSF-GV.PO-01 Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and enforced
  • NIST-CSF-GV.RM-05 Lines of communication across the organization are established for cybersecurity risks, including risks from suppliers and other third parties
  • NIST-CSF-GV.RM-06 A standardized method for calculating, documenting, categorizing, and prioritizing cybersecurity risks is established and communicated
  • NIST-CSF-ID.IM-04 Incident response plans and other cybersecurity plans that affect operations are established, communicated, maintained, and improved
  • NIST-CSF-ID.RA-04 Potential impacts and likelihoods of threats exploiting vulnerabilities are identified and recorded
  • NIST-CSF-ID.RA-06 Risk responses are chosen, prioritized, planned, tracked, and communicated
  • NIST-CSF-ID.RA-09 The authenticity and integrity of hardware and software are assessed prior to acquisition and use

NIST SP 800-53 Rev 5 · 7 controls

SOC 2 · 5 controls

  • SOC2-CC1.1 CC1.1 Commitment to integrity and ethical values (COSO principle 1)
  • SOC2-CC3.2 CC3.2 Identifying and analysing risks to objectives (COSO principle 7)
  • SOC2-CC5.1 CC5.1 Selecting control activities that mitigate risk (COSO principle 10)
  • SOC2-CC5.3 CC5.3 Deploying controls through policies and procedures (COSO principle 12)
  • SOC2-CC9.1 CC9.1 Mitigating risks of business disruption

C5 (Germany) · 3 controls

HIPAA Security Rule · 3 controls

NIST SP 800-66 Rev 2 · 3 controls

FedRAMP High · 2 controls

  • CA-5 Plan of Action and Milestones
  • CP-2 Contingency Plan

FedRAMP Moderate · 2 controls

  • CA-5 Plan of Action and Milestones
  • CP-2 Contingency Plan

NIST SP 800-161 Rev 1 · 2 controls

  • 28 Para 28 Design, implement and embed internal controls

CMMC 2.0 · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Documentation

Query this from an agent

The graph holds this control, the 44 it maps to, and the evidence behind each claim, over MCP and REST.