APRA CPS 230 Operational Risk Management
Operations

APRA CPS 230 Operational Risk Management CPS230-P25: Information and Technology Capability and Asset Health

The entity must maintain sound information and technology capability to meet current and projected business requirements and to support critical operations and risk management, and in managing technology risk must monitor the age and health of its information assets and meet the information security requirements of CPS 234.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 50 controls across 19 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 27002:2022 · 4 controls

  • 5.30 ICT readiness for business continuity
  • 5.9 Inventory of information and other associated assets
  • 8.6 Capacity management
  • 8.8 Management of technical vulnerabilities
  • NIST-CSF-ID.AM-02 Inventories of software, services, and systems managed by the organization are maintained
  • NIST-CSF-ID.AM-08 Systems, hardware, software, services, and data are managed throughout their life cycles
  • NIST-CSF-PR.IR-04 Adequate resource capacity to ensure availability is maintained
  • NIST-CSF-PR.PS-02 Software is maintained, replaced, and removed commensurate with risk

APRA CPS 234 · 3 controls

  • CPS234-15 Information Security Capability
  • CPS234-20 Information Asset Classification
  • CPS234-P17 Active Maintenance of Capability Against Change
  • AM-3 Ensure security of asset lifecycle management
  • ASBv3-AM-1 Track asset inventory and their risks
  • ASBv3-PV-6 Rapidly and automatically remediate vulnerabilities

C5 (Germany) · 3 controls

FedRAMP High · 3 controls

  • CM-8 System Component Inventory
  • MA-6 Timely Maintenance (MA-6)
  • SA-22 Unsupported System Components (SA-22)

FedRAMP Moderate · 3 controls

  • CM-8 System Component Inventory
  • MA-6 Timely Maintenance (MA-6)
  • SA-22 Unsupported System Components (SA-22)

ISO 27001:2022 · 3 controls

  • 5.30 ICT readiness for business continuity
  • 5.9 Inventory of information and other associated assets
  • 8.6 Capacity management

NIST SP 800-161 Rev 1 · 3 controls

NIST SP 800-53 Rev 5 · 3 controls

  • ANSSI-HYG-34 Define an Update Policy for Information System Components
  • ANSSI-HYG-35 Anticipate the End of Maintenance of Software and Systems

CMMC 2.0 · 2 controls

DORA · 2 controls

HIPAA Security Rule · 2 controls

SOC 2 · 2 controls

  • SOC2-A1.1 A1.1 Managing processing capacity
  • SOC2-CC5.2 CC5.2 General controls over technology (COSO principle 11)

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

You are reading one control. How much of APRA CPS 230 Operational Risk Management have you already done?

APRA CPS 230 Operational Risk Management CPS230-P25 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of APRA CPS 230 Operational Risk Management your existing evidence covers. Hold NIST Cybersecurity Framework 2.0 and 30 of 43 APRA CPS 230 Operational Risk Management controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 4 were rejected on the NIST Cybersecurity Framework 2.0 pair alone.

Query this from an agent

The graph holds this control, the 50 it maps to, and the evidence behind each claim, over MCP and REST.