First, it pays to see that APRA CPS 234 is closely aligned with ISO/IEC 27001. Meaning, it’s an achievable and comparative benchmark for information security in APRA regulated entities.
It is not overly prescriptive, so it must be interpreted commensurate to the risk presented to regulated entities of different sizes and natures. That’s where you come in.
This brings us to the greatest opportunity for Service Providers – helping to perform assessments across multiple customers and their third parties within the timeframe given for compliance.
Working backwards from the 1 July 2020 deadline, regulated entities will need to:
1. Report on the overall ‘status of compliance’ to the Board (and to APRA if there are any detected incidents or material weaknesses)
2. Perform an internal audit against the APRA CPS 234 requirements (possibly with expert option)
3. Conduct independent testing of control effectiveness
4. Complete any necessary rework to implement expected requirements (which may require an initial gap analysis / assessment)
That doesn’t leave much time!