APRA CPS 234
What is APRA CPS 234?
Australian Prudential Regulation Authority Information Security Standard. It comprises 35 controls organised across 17 domains, and applies in Australia.
How APRA CPS 234 maps to other frameworks
All 35 controls, each one mapped to the equivalent requirement in other standards, with the evidence that carries across and the mappings that were judged and rejected shown alongside. No account needed to look.
See the control mappings →The 17 domains APRA CPS 234 groups its controls into
Frameworks that share controls with APRA CPS 234
Each of these has at least one control mapped to a control in APRA CPS 234. The number is how many APRA CPS 234 controls are shared, counted from the mapping graph.
Implementation guides for frameworks that overlap APRA CPS 234
Where APRA CPS 234 overlaps with the standards you already hold
Where to get trained on APRA CPS 234
4 courses in the catalogue cover APRA CPS 234 directly. Each is self-paced, includes the downloadable toolkit and the implementation playbook, and carries a certificate of completion.
What APRA CPS 234 means in your sector
What APRA CPS 234 means for your job
Questions people ask about APRA CPS 234
What is APRA CPS 234?
How many controls does APRA CPS 234 have?
Where does APRA CPS 234 apply?
What frameworks does APRA CPS 234 map to?
How do I get started with APRA CPS 234 compliance?
Query APRA CPS 234 programmatically
APRA CPS 234, its 35 controls and every mapping into other standards are available over a REST endpoint and an MCP server, so an agent can read them directly. The free tier is 10 calls a day and needs no signup.
APRA CPS 234 API reference and MCP config →What APRA CPS 234 requires, control by control
Each page carries the requirement text for one APRA CPS 234 control and what an assessor expects to see as evidence.
- CPS-234-PARA-13 Board Responsibility for Information Security
- CPS-234-PARA-14 Definition of Information Security Roles and Responsibilities
- CPS-234-PARA-15 Information Security Capability
- CPS-234-PARA-16 Assessment of Related Party and Third Party Capability
- CPS-234-PARA-17 Active Maintenance of Capability Against Change
- CPS-234-PARA-18 Information Security Policy Framework
- CPS-234-PARA-19 Policy Direction to All Responsible Parties
- CPS-234-PARA-20 Information Asset Classification
- CPS-234-PARA-21 Implementation of Information Security Controls
- CPS-234-PARA-22 Evaluation of Third Party Control Design
How much of another standard APRA CPS 234 already covers
Each crosswalk is judged control by control, and the mappings that were rejected are kept alongside the ones that held.
- APRA CPS 234 to APRA CPS 230 Operational Risk Management crosswalk
- APRA CPS 234 to C5 (Germany) crosswalk
- APRA CPS 234 to CIS Controls v8 crosswalk
- APRA CPS 234 to Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 crosswalk
- APRA CPS 234 to FedRAMP Moderate crosswalk
- APRA CPS 234 to HIPAA Security Rule crosswalk
- APRA CPS 234 to ISO 27001:2022 crosswalk
- APRA CPS 234 to ISO 27002:2022 crosswalk
How ready are you for APRA CPS 234?
Answer 25 questions and get a professional readiness report with gap analysis, maturity scores, and prioritised action items. Results in 5 minutes.