Control frameworkCompliance & Audit

APRA CPS 234 policy template

Review this template's scope and control areas. Then, open it in the Verdictan console to adapt and test the configuration for your environment.

Map Australian Prudential Regulation Authority CPS 234 controls for regulated financial entities. The template covers security capability, asset classification, testing, incidents, third parties and risk management. Use gateway controls and evidence fields only where they apply.

Use this template as a starting configuration and control map. It does not provide certification, legal advice or a compliance guarantee. Confirm your obligations, adapt the configuration and test every outcome before deployment.

Regions

AU

Source references

3 source references

Control areas

7 mapped control areas

Deployment options

Regulated SaaS, Sovereign region, Financial (cache disabled)

Source frameworks, standards and obligations

APRA Prudential Standard CPS 234 (Information Security)APRA CPG 234 (Guidance)APRA CPS 220 (Risk Management)

Control areas mapped by this template

Access control
Incident response
Vulnerability management
Third-party oversight
Audit logging
Risk management
Testing

Deployment options

Regulated SaaS
Sovereign region
Financial (cache disabled)

Adapt the template in three steps

1

Review the scope

Confirm that the regions, source references, control areas and deployment options fit your use case.

2

Adapt the configuration

Open the template in the Verdictan console. Set its policies, thresholds, routing and review requirements for your environment.

3

Test before deployment

Test each policy outcome. Confirm that allowed, redacted, blocked and reviewed requests behave as expected.