APRA CPS 220 Risk Management
Documentation

APRA CPS 220 Risk Management CPS220-P35: Required Content of Risk Management Policies and Procedures

The policies and procedures the risk management strategy is required to list must include the process for identifying and assessing material risks and controls, for validating, approving and using risk measurement models, for establishing, implementing and testing mitigation strategies and control mechanisms, for monitoring, communicating and reporting risk issues including escalation of material events and incidents, for identifying, monitoring and managing potential and actual conflicts of interest, the mechanisms for monitoring and ensuring ongoing compliance with all prudential requirements, the process for ensuring consistency across the framework components, the process for establishing and maintaining contingency arrangements including robust and credible recovery plans where warranted for operating the framework in stressed conditions, and the process for reviewing the framework.

What else in your programme already covers this

This control maps to 49 controls across 14 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • NIST-CSF-GV.OC-03 Legal, regulatory, and contractual requirements regarding cybersecurity - including privacy and civil liberties obligations - are understood and managed
  • NIST-CSF-GV.PO-01 Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and enforced
  • NIST-CSF-GV.RM-05 Lines of communication across the organization are established for cybersecurity risks, including risks from suppliers and other third parties
  • NIST-CSF-GV.RM-06 A standardized method for calculating, documenting, categorizing, and prioritizing cybersecurity risks is established and communicated
  • NIST-CSF-ID.IM-04 Incident response plans and other cybersecurity plans that affect operations are established, communicated, maintained, and improved
  • NIST-CSF-ID.RA-04 Potential impacts and likelihoods of threats exploiting vulnerabilities are identified and recorded
  • NIST-CSF-ID.RA-06 Risk responses are chosen, prioritized, planned, tracked, and communicated
  • NIST-CSF-ID.RA-09 The authenticity and integrity of hardware and software are assessed prior to acquisition and use

NIST SP 800-53 Rev 5 · 7 controls

  • NIST800-CA-1 Policy and procedures for assessment, authorization, and monitoring
  • NIST800-CA-7 Continuous monitoring
  • NIST800-PM-31 Continuous Monitoring Strategy. Develop an organization-wide continuous monitoring strategy and implement continuous monitoring programs that include: Establishing the following organization-wide metrics to be monitored: [organization-defined]; Establishing [organization-defined] and [organization-defined] for control effectiveness; Ongoing monitoring
  • NIST800-PM-9 Risk Management Strategy. Develops a comprehensive strategy to manage: Security risk to organizational operations and assets, individuals, other organizations, and the Nation associated with the operation and use of organizational systems; and Privacy risk
  • NIST800-RA-1 Policy and procedures for risk assessment
  • NIST800-RA-3 Risk assessment
  • NIST800-RA-7 Risk response

SOC 2 · 5 controls

  • SOC2-CC1.1 COSO principle 1: Demonstrates commitment to integrity and ethical values
  • SOC2-CC3.2 COSO principle 7: Identifies risks and analyzes to determine how managed
  • SOC2-CC5.1 COSO principle 10: Selects and develops control activities to mitigate risks
  • SOC2-CC5.3 COSO principle 12: Deploys control activities through policies and procedures
  • SOC2-CC9.1 Identifies, selects and develops risk mitigation activities

C5 (Germany) · 3 controls

HIPAA Security Rule · 3 controls

NIST SP 800-66 Rev 2 · 3 controls

FedRAMP High · 2 controls

  • CA-5 Plan of Action and Milestones
  • CP-2 Contingency Plan

FedRAMP Moderate · 2 controls

  • CA-5 Plan of Action and Milestones
  • CP-2 Contingency Plan

NIST SP 800-161 Rev 1 · 2 controls

  • CA-5 Plan of Action and Milestones
  • CP-2 Contingency Plan
  • CA-5 Plan of Action and Milestones
  • CP-2 Contingency Plan
  • CA-5 Plan of Action and Milestones
  • CP-2 Contingency Plan

CMMC 2.0 · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Documentation

Query this from an agent

The graph holds this control, the 49 it maps to, and the evidence behind each claim, over MCP and REST.