APRA CPS 234
Australian Prudential Regulation Authority Information Security Standard
APRA CPS 234 is a compliance framework from Australia with 10 domains and 24 controls that map to 223 other frameworks. The largest domains are Testing Control Effectiveness (4 controls), Incident Management (3 controls), Internal Audit (3 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (10)
APRA Notification
Implementation of Controls
Incident Management
| Code | Title |
|---|---|
| CPS234-32 | Annual Review and Testing of Response Plans |
| CPS234-P24 | Information Security Response Plans |
| CPS234-P25 | Response Plan Content and Escalation Mechanisms |
Information Asset Identification and Classification
| Code | Title |
|---|---|
| CPS234-20 | Information Asset Classification |
Information Security Capability
| Code | Title |
|---|---|
| CPS234-15 | Information Security Capability |
| CPS234-P17 | Active Maintenance of Capability Against Change |
Internal Audit
| Code | Title |
|---|---|
| CPS234-25 | Internal Audit Review of Information Security Controls |
| CPS234-27 | Internal Audit Assessment of Third Party Control Assurance |
| CPS234-P33 | Skill of Personnel Providing Control Assurance |
Policy Framework
| Code | Title |
|---|---|
| CPS234-19 | Information Security Policy Framework |
| CPS234-P19 | Policy Direction to All Responsible Parties |
Roles and Responsibilities
Testing Control Effectiveness
| Code | Title |
|---|---|
| CPS234-22 | Systematic Control Testing Program |
| CPS234-28 | Escalation of Unremediated Testing Deficiencies |
| CPS234-P30 | Independence and Skill of Testing Personnel |
| CPS234-P31 | Annual Review of Testing Program Sufficiency |
Third Party Arrangements
| Code | Title |
|---|---|
| CPS234-16 | Assessment of Related Party and Third Party Capability |
| CPS234-P22 | Evaluation of Third Party Control Design |
| CPS234-P28 | Assessment of Reliance on Third Party Control Testing |
Your Compliance Coverage
If you comply with APRA CPS 234, you already cover:
NIS2 Directive
100%
24 controls mapped
Compare →NIST SP 800-161 Rev 1
100%
24 controls mapped
Compare →FedRAMP High
100%
24 controls mapped
Compare →+ 220 more: FedRAMP Moderate (100%), NIST SP 800-53 Rev 5 MODERATE (100%)
See all 223 mapped frameworks ↓Maps to 223 other frameworks
What is APRA CPS 234 and who does it apply to?
APRA CPS 234 is a compliance framework from Australia with 10 domains and 24 controls. Australian Prudential Regulation Authority Information Security Standard It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does APRA CPS 234 actually require?
APRA CPS 234 has 24 controls organised across 10 domains. The largest domains are Testing Control Effectiveness (4 controls), Incident Management (3 controls), Internal Audit (3 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of APRA CPS 234 do I already cover?
APRA CPS 234 maps to 223 other compliance frameworks. The top mapping partners are NIS2 Directive (100% coverage), NIST SP 800-161 Rev 1 (100% coverage), FedRAMP High (100% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I implement APRA CPS 234?
Start your APRA CPS 234 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about APRA CPS 234 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 24 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.
Get Started Free →Free forever — no credit card required