Overview of APRA Publications
For those of you who don’t work in financial services, APRA’s publications include Prudential Practice Guides (PPGs) and Prudential Standards (APSs or CPSs). A PPG provides guidance on sound practice in particular areas without being enforceable, while APSs and CPSs are regulatory instruments that are enforceable.
Until now, those in a cyber security team at an Australian financial services company had PPG 234 – Management of security risk in information and information technology (released in 1 February 2010) as their main reference for APRA’s expectations regarding cyber security controls. PPG 234 remains a key document for discussions with APRA despite changes since 2010.
APRA’s Announcement
At the Insurance Council of Australia’s Annual Forum on 7th March 2018, APRA Executive Board Member Geoff Summerhayes stated:
“APRA views cyber risk as an increasingly serious prudential threat to Australian financial institutions. To put it bluntly, it is easy to envisage a scenario in which a cyber breach could potentially damage an entity so badly that it is forced out of business.
“….What I’d like to address today is APRA’s view on the extent to which the defences of the entities we regulate, including insurers, are up to the task of keeping online adversaries at bay, as well as responding rapidly and effectively when – and I use that word intentionally – a breach is detected.”
Summerhayes announced the consultation draft of CPS 234 – Information Security, introducing actual legislative requirements on information security.
Key Elements of CPS 234
There are many similarities to PPG 234, but notable points based on experiences in financial services include:
Roles and Responsibilities
- Board Accountability: “The Board of an APRA-regulated entity (the Board) is ultimately responsible for ensuring that the entity maintains the information security of its information assets in a manner which is commensurate with the size and extent of threats to those assets...”
Information Security Capability
- Maintenance of Capability: “An APRA-regulated entity must actively maintain its information security capability with respect to changes in vulnerabilities and threats...”
Information Asset Identification and Classification
- Classification Requirement: “An APRA-regulated entity must classify its information assets, including those managed by related parties and third parties, by criticality and sensitivity...”
Implementation of Controls
- Timely Control Implementation: “An APRA-regulated entity must have information security controls to protect its information assets... that are implemented in a timely manner.”
- Evaluation of Third-Party Controls: “Where information assets are managed by a related party or third party, an APRA-regulated entity must evaluate the design and operating effectiveness of that party’s information security controls.”
Incident Management
- Detection and Response Mechanisms: “An APRA-regulated entity must have robust mechanisms in place to detect and respond to information security incidents in a timely manner...”
Testing Control Effectiveness
- Escalation of Control Deficiencies: “An APRA-regulated entity must escalate and report to the Board or senior management any testing results that identify information security control deficiencies that cannot be remediated in a timely manner...”
APRA Notification
- Incident Notification: “An APRA-regulated entity must notify APRA as soon as possible, and no later than 24 hours, after experiencing an information security incident.”
Conclusion
CPS 234 is currently a draft, and the final product may differ significantly. Nonetheless, this initiative from APRA represents a positive step forward in raising awareness about significant cyber security risks. Consultation on the draft is open until 7 June 2018, with plans for implementation from 1 July 2019.