APRA CPS 234 information security assessed on real evidence

Tier-A breadth

36 catalogued controls across 10 areas, assessed deterministically against your uploaded and connector-collected evidence — honest coverage against the full catalogue, consultant-grade reporting from one run.

Book a demo on APRA CPS 234 (Information Security) → Open the sample-evidence demo

Applies to: Banks & APRA-regulated · Insurers & APRA-regulated · Superannuation & RSE licensees · GRC consultants & practices · Third-party & supplier risk · APRA CPS 230 & CPS 234

Coverage areas

Application & interpretationAPRA notificationIdentification & classificationImplementation of controlsIncident managementInformation security capabilityInternal auditPolicy frameworkRoles and responsibilitiesTesting control effectiveness

Generated from the live catalogue at build time — control identifiers and CyberSentien's own labels; no standard text is reproduced.

Honest coverage

Verdicts against the FULL catalogue — controls without evidence read “manual assessment required”, never a fabricated pass.

Evidence lineage

Every report carries a run id and SHA-256 integrity anchor; sections trace to the controls and evidence they rest on.

One assessment, every report

The same run renders the APRA CPS 234 (Information Security) report, executive brief and board pack — no drift between audiences.

See APRA CPS 234 (Information Security) on the real engine

Run it against synthetic sample documents now, or bring your own evidence in a gated demo week.

Request the demo →

Frequently asked

What is CPS 234?

CPS 234 is APRA's information security standard requiring regulated entities to maintain security capability proportionate to threats, classify information assets, test controls, and notify APRA of material incidents within 72 hours.

Does CyberSentien do the CPS 234 tripartite audit?

No. The formal CPS 234 assurance is an ASAE 3150 engagement performed by an independent assurance practitioner. CyberSentien prepares evidence-based readiness so that engagement is defensible.

Does ISO 27001 certification make me CPS 234 compliant?

No. ISO 27001 certification does not equal CPS 234 compliance — CPS 234 has specific APRA obligations (notification timing, board accountability, control testing) that must be evidenced separately.

When must I notify APRA of an incident under CPS 234?

Within 72 hours of becoming aware of a material information security incident, and within 10 business days of identifying a material control weakness.

Related

APRA CPS 230 (operational resilience) · Third-party risk (TPRM) · CPS 230 & 234 for banks