APRA CPS 234
Third Party Arrangements

APRA CPS 234 CPS234-P28: Assessment of Reliance on Third Party Control Testing

Where the entity relies on a related party or third party testing of controls over its information assets, it must assess whether the nature and frequency of that testing meets the same factors that govern its own testing program.

What else in your programme already covers this

This control maps to 39 controls across 20 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

FedRAMP High · 3 controls

  • CA-2(3) Control Assessments | Leveraging Results from External Organizations. Leverage the results of control assessments performed by [Assignment: organization-defined external organization] on [Assignment: organization-defined system] when the assessment meets [Assignment: organization-defined requirements]
  • SA-9 External System Services
  • SR-6 Supplier Assessments and Reviews (SR-6)

FedRAMP Moderate · 3 controls

  • CA-2(3) Control Assessments | Leveraging Results from External Organizations. Leverage the results of control assessments performed by [Assignment: organization-defined external organization] on [Assignment: organization-defined system] when the assessment meets [Assignment: organization-defined requirements]
  • SA-9 External System Services
  • SR-6 Supplier Assessments and Reviews (SR-6)
  • NIST-CSF-DE.CM-06 External service provider activities and services are monitored to find potentially adverse events
  • NIST-CSF-GV.SC-07 The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationship
  • NIST-CSF-ID.RA-10 Critical suppliers are assessed prior to acquisition

NIST SP 800-161 Rev 1 · 3 controls

NIST SP 800-53 Rev 5 · 3 controls

  • CPS230-46 Ongoing Risk Management of Each Material Arrangement
  • CPS230-47 Monitoring and Senior Management Reporting on Material Arrangements

C5 (Germany) · 2 controls

  • C5-SSO-02 Risk assessment of service providers and suppliers
  • C5-SSO-04 Monitoring of compliance with requirements

CIS Controls v8 · 2 controls

NIS2 Directive · 2 controls

  • Art.21.2.f Policies and procedures to assess the effectiveness of the cybersecurity risk-management measures
  • Art.21.3 Take account of supplier-specific vulnerabilities and of Union coordinated supply chain risk assessments
  • SA-9 External System Services
  • SR-6 Supplier Assessments and Reviews (SR-6)
  • SA-9 External System Services
  • SR-6 Supplier Assessments and Reviews (SR-6)

PCI DSS 4.0 · 2 controls

  • 12.8.4 TPSP compliance monitored
  • 12.9.2 TPSP supports customer requests for compliance info (SP)

HIPAA Security Rule · 1 control

  • 164.308(b)(1) Business Associate Contracts and Other Arrangements (Standard)

ISO 27001:2022 · 1 control

  • 5.22 Monitoring, review and change management of supplier services

ISO 27002:2022 · 1 control

  • 5.22 Monitoring, review and change management of supplier services
  • SA-9 External System Services
  • 164.308(b)(1) Business Associate Contracts and Other Arrangements (Standard)

SOC 2 · 1 control

  • SOC2-CC9.2 Risk mitigation activities include assessment of vendor and business partner controls

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Third Party Arrangements

You are reading one control. How much of APRA CPS 234 have you already done?

APRA CPS 234 CPS234-P28 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of APRA CPS 234 your existing evidence covers. Hold NIST Cybersecurity Framework 2.0 and 19 of 24 APRA CPS 234 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 5 were rejected on the NIST Cybersecurity Framework 2.0 pair alone.

Query this from an agent

The graph holds this control, the 39 it maps to, and the evidence behind each claim, over MCP and REST.