APRA finalises cyber security prudential standard

8 November 2018
| By Nicholas Grove |
image
image
expand image

The Australian Prudential Regulation Authority (APRA) has released the final version of its prudential standard focused on information security management.

APRA said the new Prudential Standard CPS 234 Information Security will shore up APRA-regulated entities’ resilience against information security incidents, including cyber-attacks, and their ability to respond swiftly and effectively in the event of a breach.

It said CPS 234 requires regulated entities to: clearly define information-security related roles and responsibilities; maintain an information security capability commensurate with the size and extent of threats to their information assets; implement controls to protect information assets and undertake regular testing and assurance of the effectiveness of controls; and promptly notify APRA of material information security incidents.

APRA first released a discussion paper in March outlining the intended requirements of the new prudential standard. Following extensive consultation with industry, APRA this week published a Response to Submissions paper outlining the final form of the standard.

Industry was supportive of the intent and direction of CPS 234. However, APRA said it agreed to make several amendments, including clarifying requirements for information assets managed by third parties, and modifying the timeframes for notifying APRA of information security incidents and material information security control weaknesses.

APRA executive board member Geoff Summerhayes said cyber adversaries were targeting Australian financial services companies with growing frequency and sophistication.

“A significant information security breach at an APRA-regulated entity is almost certainly a question of when – not if. In a worst-case scenario, a major breach could even force a company out of business,” Summerhayes said.

“As a result, APRA is fast-tracking implementation of this standard, and expects all regulated entities to meet its requirements by 1 July next year.

“By introducing CPS 234, APRA aims to ensure all regulated entities develop and maintain information security capabilities that reflect the importance of the data they hold, and the significance of the threats they face.”

Read more about:

AUTHOR

 

Recommended for you

 

MARKET INSIGHTS

sub-bg sidebar subscription

Never miss the latest news and developments in wealth management industry

JOHN GILLIES

Might be a bit different to i the past where at most there was one man from the industry on the loaded enquiry boards a...

14 hours 44 minutes ago
Simon

Who get's the $10M? Where does the money go?? Might it end up in the CSLR to financially assist duped investors??? ...

5 days 9 hours ago
Squeaky'21

My view is that after 2026 there will be quite a bit less than 10,000 'advisers' (investment advisers) and less than 100...

1 week 5 days ago

AustralianSuper and Australian Retirement Trust have posted the financial results for the 2022–23 financial year for their combined 5.3 million members....

9 months 2 weeks ago

A $34 billion fund has come out on top with a 13.3 per cent return in the last 12 months, beating out mega funds like Australian Retirement Trust and Aware Super. ...

9 months 1 week ago

The verdict in the class action case against AMP Financial Planning has been delivered in the Federal Court by Justice Moshinsky....

9 months 2 weeks ago

TOP PERFORMING FUNDS

ACS FIXED INT - AUSTRALIA/GLOBAL BOND