General Information & Client Service
  • Americas: +1.212.553.1653
  • Asia: +852.3551.3077
  • China: +86.10.6319.6580
  • EMEA: +44.20.7772.5454
  • Japan: +81.3.5408.4100
Media Relations
  • New York: +1.212.553.0376
  • London: +44.20.7772.5456
  • Hong Kong: +852.3758.1350
  • Tokyo: +813.5408.4110
  • Sydney: +61.2.9270.8141
  • Mexico City: +001.888.779.5833
  • Buenos Aires: +0800.666.3506
  • São Paulo: +0800.891.2518
November 07, 2018

APRA has released the final version of its prudential standard focused on information security management. The new Prudential Standard CPS 234 Information Security will shore up APRA-regulated entities’ resilience against information security incidents (including cyber-attacks) and their ability to respond swiftly and effectively in the event of a breach. Following extensive consultation with the industry, APRA also published a Response to Submissions paper outlining the final form of the standard. This Prudential Standard commences on July 01, 2019.

Where an APRA-regulated entity’s information assets are managed by a third party, the requirements in this Prudential Standard will apply in relation to those information assets from the earlier of the next renewal date of the contract with the third party or July 01, 2020. This prudential standard will apply to APRA-regulated entities, including authorized deposit-taking institutions, general insurers, life insurers, private health insurers, licensees of registrable superannuation entities (RSE licensees), and authorized or registered non-operating holding companies. CPS 234 requires APRA-regulated entities to:

  • Clearly define information-security related roles and responsibilities
  • Maintain an information security capability commensurate with the size and extent of threats to their information assets
  • Implement controls to protect information assets and undertake regular testing and assurance of the effectiveness of controls
  • Promptly notify APRA of material information security incidents

APRA first released a discussion paper in March outlining the intended requirements of the new prudential standard. Industry was supportive of the intent and direction of CPS 234. APRA agreed to make several amendments, including clarifying requirements for information assets managed by third parties and modifying the timeframes for notifying APRA of information security incidents and material information security control weaknesses. To help entities fulfill their requirements, APRA will shortly update the Prudential Practice Guide CPG 234 on Management of Information and Information Technology. 

 

Related Links

Effective Date: July 01, 2019/July 01, 2020

Keywords: Asia Pacific, Australia, Banking, Insurance, CPS 234, Cyber Risk, Regtech, Prudential Standard, APRA

Related Articles
News

FASB Issues Minor Improvements to Financial Instruments Standards

FASB issued an Accounting Standards Update (ASU No. 2019-04) that clarifies and improves areas of guidance related to the recently issued standards on credit losses (Topic 326), derivatives and hedging (Topic 815), and recognition and measurement of financial instruments (Topic 825).

April 25, 2019 WebPage Regulatory News
News

APRA Grants License to New Authorized Deposit-Taking Institution

APRA announced that it has granted Judo Bank Pty Ltd a license to operate as an authorized deposit-taking institution without restrictions, under the Banking Act 1959.

April 24, 2019 WebPage Regulatory News
News

BoE Report on Evaluation of Approach to Concurrent Stress Testing

BoE published a report on the evaluation, by the Independent Evaluation Office (IEO), of the effectiveness of the approach of BoE to concurrent stress testing.

April 24, 2019 WebPage Regulatory News
News

FDIC Consults on Approach to Resolution Planning for IDIs

FDIC approved an Advance Notice of Proposed Rulemaking (ANPR) and is seeking comment on ways to tailor and improve its rule requiring certain insured depository institutions (IDIs) to submit resolution plans.

April 22, 2019 WebPage Regulatory News
News

FDIC Specifies Submission Timeline for FFIEC 031, 041, and 051 Reports

FDIC published the financial institution letters (FIL-21-2019 and FIL-22-2019) that offer guidance on submission of Call Reports FFIEC 051, FFIEC 041, and FFIEC 031 for the first quarter of 2019.

April 19, 2019 WebPage Regulatory News
News

US Agencies Propose to Revise Call Reports FFIEC 031, 041, and 051

US Agencies (FDIC, FED, and OCC) proposed to revise and extend, for three years, the Call Reports FFIEC 031, FFIEC 041, and FFIEC 051.

April 19, 2019 WebPage Regulatory News
News

US Agencies Propose to Amend Rule on Supplementary Leverage Ratio

US Agencies (FDIC, FED, and OCC) are proposing to revise the capital requirements for supplementary leverage ratio, as required by the Economic Growth, Regulatory Relief, and Consumer Protection (EGRRCP) Act.

April 18, 2019 WebPage Regulatory News
News

EIOPA Held InsurTech Roundtable on Use of Cloud Computing by Insurers

EIOPA had, on April 11, 2019, hosted its Fourth InsurTech Roundtable on the use of cloud computing by insurance undertakings.

April 17, 2019 WebPage Regulatory News
News

EP Resolution on Proposal for Sovereign Bond Backed Securities

The European Parliament (EP) published adopted text on the proposal for a regulation of the European Parliament and of the Council on sovereign bond-backed securities (SBBS).

April 16, 2019 WebPage Regulatory News
News

HKMA Decides to Maintain Countercyclical Capital Buffer at 2.5%

HKMA announced that, in accordance with the Banking (Capital) Rules, the countercyclical capital buffer (CCyB) ratio for Hong Kong remains at 2.5%.

April 16, 2019 WebPage Regulatory News
RESULTS 1 - 10 OF 2957