Home / Rules / APRA CPS 234 Information Security / APRA CPS 234 para 22 (design of third-party controls)
APRA CPS 234 para 22 (design of third-party controls)
Where a related or third party manages the entity's information assets, the entity evaluates how that party's security controls protecting those assets are designed. A footnote confirms this reaches every such party, not only CPS 231 or SPS 231 material outsourcing.
Steps that cite it
Evidence commonly asked for
- Control design evaluation reports for each in-scope third or related party
- Reviewed third-party assurance reports with the entity's own analysis of scope, exceptions and complementary user-entity controls
- Contract rights to information, audit and assessment
- Records of design gaps raised with the party and their resolution
Accepted citation forms are listed on the answer format page.