General Information & Client Service
  • Americas: +1.212.553.1653
  • Asia: +852.3551.3077
  • China: +86.10.6319.6580
  • EMEA: +44.20.7772.5454
  • Japan: +81.3.5408.4100
Media Relations
  • New York: +1.212.553.0376
  • London: +44.20.7772.5456
  • Hong Kong: +852.3758.1350
  • Tokyo: +813.5408.4110
  • Sydney: +61.2.9270.8141
  • Mexico City: +001.888.779.5833
  • Buenos Aires: +0800.666.3506
  • São Paulo: +0800.891.2518
November 07, 2018

APRA has released the final version of its prudential standard focused on information security management. The new Prudential Standard CPS 234 Information Security will shore up APRA-regulated entities’ resilience against information security incidents (including cyber-attacks) and their ability to respond swiftly and effectively in the event of a breach. Following extensive consultation with the industry, APRA also published a Response to Submissions paper outlining the final form of the standard. This Prudential Standard commences on July 01, 2019.

Where an APRA-regulated entity’s information assets are managed by a third party, the requirements in this Prudential Standard will apply in relation to those information assets from the earlier of the next renewal date of the contract with the third party or July 01, 2020. This prudential standard will apply to APRA-regulated entities, including authorized deposit-taking institutions, general insurers, life insurers, private health insurers, licensees of registrable superannuation entities (RSE licensees), and authorized or registered non-operating holding companies. CPS 234 requires APRA-regulated entities to:

  • Clearly define information-security related roles and responsibilities
  • Maintain an information security capability commensurate with the size and extent of threats to their information assets
  • Implement controls to protect information assets and undertake regular testing and assurance of the effectiveness of controls
  • Promptly notify APRA of material information security incidents

APRA first released a discussion paper in March outlining the intended requirements of the new prudential standard. Industry was supportive of the intent and direction of CPS 234. APRA agreed to make several amendments, including clarifying requirements for information assets managed by third parties and modifying the timeframes for notifying APRA of information security incidents and material information security control weaknesses. To help entities fulfill their requirements, APRA will shortly update the Prudential Practice Guide CPG 234 on Management of Information and Information Technology. 

 

Related Links

Effective Date: July 01, 2019/July 01, 2020

Keywords: Asia Pacific, Australia, Banking, Insurance, CPS 234, Cyber Risk, Regtech, Prudential Standard, APRA

Related Insights
News

EBA Single Rulebook Q&A: Third Update for February 2019

EBA published answers to two questions under the Single Rulebook question and answer (Q&A) updates for this week.

February 15, 2019 WebPage Regulatory News
News

FSB Report Examines Financial Stability Implications of Fintech

FSB published a report that assesses fintech-related market developments and their potential implications for financial stability.

February 14, 2019 WebPage Regulatory News
News

US Agencies Amend Regulatory Capital Rule to Allow Phase-In for CECL

US Agencies (FDIC, FED, and OCC) adopted the final rule to address changes to credit loss accounting under the U.S. generally accepted accounting principles; this includes banking organizations’ implementation of the current expected credit losses (CECL) methodology.

February 14, 2019 WebPage Regulatory News
News

FED Issues Correction in Historical Dataset in its 2019 Stress Tests

FED identified an error in the historical dataset used in its 2019 stress tests and issued a correction.

February 13, 2019 WebPage Regulatory News
News

OCC Consults on Company-Run Stress Test Requirements for Banks

OCC proposed amendments to its company-run stress testing requirements for national banks and Federal savings associations, consistent with section 401 of the Economic Growth, Regulatory Relief, and Consumer Protection (EGRRCP) Act.

February 12, 2019 WebPage Regulatory News
News

CFTC Extends Comment Periods for Trade Execution Requirement Proposals

CFTC announced that it is extending comment period for the proposed amendments related to the regulations on swap execution facilities (SEF) and trade execution requirement.

February 12, 2019 WebPage Regulatory News
News

BCBS Updates Instructions for Basel III Monitoring Exercise

BCBS updated instructions for Basel III monitoring for the collection of December 2018 data from the participating banks.

February 12, 2019 WebPage Regulatory News
News

OCC Proposes to Renew Information Collection Under Stress Test Rule

OCC is proposing to renew its information collection titled “Annual Stress Test Rule” (OMB Control No: 1557-0311). Comments must be received on or before March 13, 2019.

February 11, 2019 WebPage Regulatory News
News

OSFI Consults on NSFR Disclosure Requirements for D-SIBs

OSFI proposed the draft guideline on the net stable funding ratio (NSFR) disclosure requirements for domestic systemically important banks (D-SIBs).

February 11, 2019 WebPage Regulatory News
News

EC Amends Its Regulation to Clarify Impairment Requirements for IFRS 9

EC published the EU Regulation 2019/237 that amends Regulation (EC) No 1126/2008 adopting certain international accounting standards, in accordance with Regulation (EC) No 1606/2002 regarding International Accounting Standard (IAS) 28 on Investments in Associates and Joint Ventures.

February 11, 2019 WebPage Regulatory News
RESULTS 1 - 10 OF 2601