APRA CPS 220 Risk Management CPS220-P35: Required Content of Risk Management Policies and Procedures
The policies and procedures the risk management strategy is required to list must include the process for identifying and assessing material risks and controls, for validating, approving and using risk measurement models, for establishing, implementing and testing mitigation strategies and control mechanisms, for monitoring, communicating and reporting risk issues including escalation of material events and incidents, for identifying, monitoring and managing potential and actual conflicts of interest, the mechanisms for monitoring and ensuring ongoing compliance with all prudential requirements, the process for ensuring consistency across the framework components, the process for establishing and maintaining contingency arrangements including robust and credible recovery plans where warranted for operating the framework in stressed conditions, and the process for reviewing the framework.
What else in your programme already covers this
This control maps to 49 controls across 14 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
NIST-CSF-GV.OC-03 Legal, regulatory, and contractual requirements regarding cybersecurity - including privacy and civil liberties obligations - are understood and managed
NIST-CSF-GV.PO-01 Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and enforced
NIST-CSF-GV.RM-05 Lines of communication across the organization are established for cybersecurity risks, including risks from suppliers and other third parties
NIST-CSF-GV.RM-06 A standardized method for calculating, documenting, categorizing, and prioritizing cybersecurity risks is established and communicated
NIST-CSF-ID.IM-04 Incident response plans and other cybersecurity plans that affect operations are established, communicated, maintained, and improved
NIST-CSF-ID.RA-04 Potential impacts and likelihoods of threats exploiting vulnerabilities are identified and recorded
NIST-CSF-ID.RA-06 Risk responses are chosen, prioritized, planned, tracked, and communicated
NIST-CSF-ID.RA-09 The authenticity and integrity of hardware and software are assessed prior to acquisition and use
NIST800-PM-31 Continuous Monitoring Strategy. Develop an organization-wide continuous monitoring strategy and implement continuous monitoring programs that include: Establishing the following organization-wide metrics to be monitored: [organization-defined]; Establishing [organization-defined] and [organization-defined] for control effectiveness; Ongoing monitoring
NIST800-PM-9 Risk Management Strategy. Develops a comprehensive strategy to manage: Security risk to organizational operations and assets, individuals, other organizations, and the Nation associated with the operation and use of organizational systems; and Privacy risk
NIST800-RA-1 Policy and procedures for risk assessment