APRA CPS 234 CPS234-P28: Assessment of Reliance on Third Party Control Testing
Where the entity relies on a related party or third party testing of controls over its information assets, it must assess whether the nature and frequency of that testing meets the same factors that govern its own testing program.
What else in your programme already covers this
This control maps to 39 controls across 20 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
CA-2(3) Control Assessments | Leveraging Results from External Organizations. Leverage the results of control assessments performed by [Assignment: organization-defined external organization] on [Assignment: organization-defined system] when the assessment meets [Assignment: organization-defined requirements]
CA-2(3) Control Assessments | Leveraging Results from External Organizations. Leverage the results of control assessments performed by [Assignment: organization-defined external organization] on [Assignment: organization-defined system] when the assessment meets [Assignment: organization-defined requirements]
NIST-CSF-DE.CM-06 External service provider activities and services are monitored to find potentially adverse events
NIST-CSF-GV.SC-07 The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationship
NIST-CSF-ID.RA-10 Critical suppliers are assessed prior to acquisition
You are reading one control. How much of APRA CPS 234 have you already done?
APRA CPS 234 CPS234-P28 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of APRA CPS 234 your existing evidence covers. Hold NIST Cybersecurity Framework 2.0 and 19 of 24 APRA CPS 234 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 5 were rejected on the NIST Cybersecurity Framework 2.0 pair alone.