The Australian Prudential Standard CPS 234 on Information Security requires Australian Prudential Regulation Authority (APRA) regulated entities to maintain strong measures against security incidents, including cyberattacks. Its purpose is to minimise risks to the confidentiality, integrity, and availability of information assets, including those managed by third parties. Compliance demands a clear definition of security roles, a capability proportional to risk, controls based on asset criticality, regular testing of control effectiveness, and prompt notification to APRA of material security incidents.
