APRA CPS 220 Risk Management
Change

APRA CPS 220 Risk Management CPS220-P48: Assessment Following Material Change Outside the Review Cycle

Where a material change to the size, business mix and complexity of operations is identified outside the triennial comprehensive review, the institution must assess at that time whether the framework needs amendment or review to take account of it.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 13 controls across 11 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • NIST-CSF-GV.OV-02 The cybersecurity risk management strategy is reviewed and adjusted to ensure coverage of organizational requirements and risks
  • NIST-CSF-ID.RA-07 Changes and exceptions are managed, assessed for risk impact, recorded, and tracked

C5 (Germany) · 1 control

  • C5-OIS-07 Application of the Risk Management Policy

CMMC 2.0 · 1 control

FedRAMP High · 1 control

  • CM-4 Impact Analyses

FedRAMP Moderate · 1 control

  • CM-4 Impact Analyses

HIPAA Security Rule · 1 control

SOC 2 · 1 control

  • SOC2-CC3.4 CC3.4 Identifying and assessing significant changes (COSO principle 9)

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 13 it maps to, and the evidence behind each claim, over MCP and REST.