APRA has responded to the growing threat of cyber attacks by proposing its first prudential standard on information security, known as CPS 234. APRA released a package of measures, titled “Information Security Management: A new cross-industry prudential standard,” for industry consultation. The package is aimed at shoring up the ability of APRA-regulated entities to repel cyber adversaries, or respond swiftly and effectively in the event of a breach. Comment period is open until June 07, 2018.
Key areas where APRA is hoping to lift standards include assurance over the cyber capabilities of third parties such as service providers and enhancing entities’ ability to respond to, and recover from, cyber incidents. APRA proposes to apply this standard authorized deposit-taking institutions, general insurers, life insurers, private health insurers, licensees of registrable superannuation entities (RSE licensees), and authorized or registered non-operating holding companies. APRA intends to finalize the proposed standard toward the end of the year, with a view to implementing CPS 234 from July 01 next year. The proposed new standard, CPS 234, would require regulated entities to:
- Clearly define the information security-related roles and responsibilities of the board, senior management, governing bodies, and individuals
- Maintain information security capability commensurate with the size and extent of threats to information assets and which enables the continued sound operation of the entity
- Implement information security controls to protect its information assets and undertake systematic testing and assurance regarding the effectiveness of those controls
- Have robust mechanisms in place to detect and respond to information security incidents in a timely manner
- Notify APRA of material information security incidents
Comment Due Date: June 07, 2018
Keywords: Asia Pacific, Australia, Banking, Insurance, CPS 234, Cyber Risk, Prudential Standard, APRA
Previous ArticleECB Updates Q&A on AnaCredit Regulation in June 2018
EC published the Implementing Regulation 2021/763 that lays down implementing technical standards for supervisory reporting and public disclosure of the minimum requirement for own funds and eligible liabilities (MREL).
EBA published a report that examines the convergence of prudential supervisory practices in 2020 and offers conclusions of the EBA college monitoring activity.
APRA announced the standardization of quarterly reporting due dates for authorized deposit-taking institutions.
The private sector working group of ECB on euro risk-free rates published the recommendations to address events that would trigger fallbacks in the Euro Interbank Offered Rate (EURIBOR)-related contracts, along with the €STR-based EURIBOR fallback rates (rates that could be used if a fallback is triggered).
Bundesbank published a list of "EntryPoints" that are accepted in its reporting system; the list provides taxonomy version and name of the module against each EntryPoint.
EBA published the phase 1 of its reporting framework 3.1, with the technical package covering the new reporting requirements for investment firms (under the implementing technical standards on investment firms reporting).
The Sustainable Finance Taskforce of IOSCO held two roundtables, with global stakeholders, on the IOSCO priorities to enhance the reliability, comparability, and consistency of sustainability-related disclosures and to collect views on the practical implementation of a global system architecture for these disclosures.
Asia Pacific Australia Banking APS 111 Capital Adequacy Regulatory Capital Basel RBNZ APRA
ESMA published the final guidelines on outsourcing to cloud service providers.
EBA published annual data for two key concepts and indicators in the Deposit Guarantee Schemes (DGS) Directive—available financial means and covered deposits.