APRA CPS 230 Operational Risk Management CPS230-26: Critical Operations Register, Continuity Plan and Activation
The entity must define, identify and maintain a register of its critical operations, take reasonable steps to minimise the likelihood and impact of disruption to them, maintain a credible business continuity plan setting out how it would hold critical operations within tolerance levels through disruption including disaster recovery planning for critical information assets, activate that plan when needed and return to normal operations promptly.
What else in your programme already covers this
This control maps to 112 controls across 51 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
NIST800-PM-8 Critical Infrastructure Plan. Address information security and privacy issues in the development, documentation, and updating of a critical infrastructure and key resources protection plan
CP-2(8) Contingency Plan | Identify Critical Assets. Identify critical system assets supporting [Selection: all; essential] mission and business functions
CP-2(8) Contingency Plan | Identify Critical Assets. Identify critical system assets supporting [Selection: all; essential] mission and business functions
NIST-CSF-GV.OC-04 Critical objectives, capabilities, and services that external stakeholders depend on or expect from the organization are understood and communicated
NIST-CSF-ID.AM-05 Assets are prioritized based on classification, criticality, resources, and impact on the mission
NIST-CSF-ID.IM-04 Incident response plans and other cybersecurity plans that affect operations are established, communicated, maintained, and improved
CP-2(8) Contingency Plan | Identify Critical Assets. Identify critical system assets supporting [Selection: all; essential] mission and business functions
CP-2(8) Contingency Plan | Identify Critical Assets. Identify critical system assets supporting [Selection: all; essential] mission and business functions
You are reading one control. How much of APRA CPS 230 Operational Risk Management have you already done?
APRA CPS 230 Operational Risk Management CPS230-26 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of APRA CPS 230 Operational Risk Management your existing evidence covers. Hold NIST Cybersecurity Framework 2.0 and 30 of 43 APRA CPS 230 Operational Risk Management controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 4 were rejected on the NIST Cybersecurity Framework 2.0 pair alone.