Home / Rules / APRA CPS 234 Information Security / APRA CPS 234 para 16 (third-party security capability)
APRA CPS 234 para 16 (third-party security capability)
Where a related party or third party manages any of the entity's information assets, the entity assesses that party's information security capability, to a depth that matches the possible consequences of an incident touching those assets. A footnote makes this apply to every such party, not only those supplying outsourced material business activities covered by CPS 231 or SPS 231.
Steps that cite it
Evidence commonly asked for
- Inventory of related and third parties that manage information assets, with tiering by consequence
- Completed security due-diligence questionnaires and assessment reports per party
- Independent assurance reports reviewed (for example SOC 2 Type 2, ISO/IEC 27001 certificate and statement of applicability)
- Assessment methodology showing deeper review for higher-consequence parties
Accepted citation forms are listed on the answer format page.