APRA CPS 234
Australian prudential standard for information security resilience
ISO 28000
International standard for supply chain security management systems.
Quick Verdict
APRA CPS 234 mandates information security resilience for Australian financial firms with strict notifications, while ISO 28000 offers voluntary supply chain security framework globally. Firms adopt CPS 234 for compliance, ISO 28000 for certification and resilience.
APRA CPS 234
APRA Prudential Standard CPS 234 Information Security
Key Features
- Board ultimate responsibility for information security
- 72-hour APRA notification for material incidents
- Extends to third-party managed information assets
- Asset classification by criticality and sensitivity
- Systematic testing and internal audit assurance
ISO 28000
ISO 28000:2022 Security management systems — Requirements
Key Features
- Risk-based approach aligned with ISO 31000
- PDCA cycle for continual security improvement
- Supply chain-focused operational controls and plans
- Leadership commitment and top management accountability
- Integration with other ISO management systems
Detailed Analysis
A comprehensive look at the specific requirements, scope, and impact of each standard.
APRA CPS 234 Details
What It Is
APRA Prudential Standard CPS 234 (Information Security) is a binding regulation for Australian financial institutions. Effective from 1 July 2019, it mandates resilient information security capabilities against cyber threats, covering confidentiality, integrity, and availability of assets, including those managed by third parties. It adopts a risk-based, assurance-driven approach with board accountability.
Key Components
- Governance: Board oversight, defined roles (paras 13-14).
- Risk management: Asset classification by criticality/sensitivity (para 20).
- Controls: Commensurate protections across asset lifecycle (para 21).
- Testing/assurance: Systematic testing, internal audit (paras 27-34).
- Reporting: 72-hour incident notification, 10-day weakness alerts (paras 35-36). No fixed controls; aligns with ISO 27001/NIST; compliance via evidence, no certification.
Why Organizations Use It
Mandatory for APRA-regulated entities (banks, insurers, super funds). Reduces incident impact, ensures operational continuity, builds customer trust. Mitigates regulatory penalties, enforcement actions; enhances resilience, third-party oversight.
Implementation Overview
Phased: gap analysis, policy framework, asset inventory, controls/testing, incident plans. Applies to all sizes via commensurability; group-wide for heads. Internal audit validates; ongoing maintenance required.
ISO 28000 Details
What It Is
ISO 28000:2022 is an international certification standard for establishing, implementing, and improving a security management system (SMS) focused on supply chain security. It uses a risk-based, PDCA (Plan-Do-Check-Act) approach to manage threats like theft, sabotage, and disruptions.
Key Components
- Clauses 4-10 cover context, leadership, planning, support, operation, evaluation, and improvement.
- Emphasizes risk assessment (aligned with ISO 31000), operational controls, and security plans.
- Built on harmonized ISO structure for integration; no fixed controls, tailored to risks.
- Certification via third-party audits per ISO 28003.
Why Organizations Use It
- Reduces supply chain risks and incidents.
- Meets contractual, regulatory, and insurance needs.
- Enhances resilience, compliance, and partner trust.
- Provides market access and competitive edge.
Implementation Overview
- Phased: gap analysis, risk assessment, controls, training, audits.
- Scalable for all sizes/industries; 6-36 months typical.
- Involves leadership policy, supplier controls, continual reviews.
Key Differences
| Aspect | APRA CPS 234 | ISO 28000 |
|---|---|---|
| Scope | Information security and cyber resilience | Supply chain security management system |
| Industry | Australian financial institutions only | All industries worldwide, sector-agnostic |
| Nature | Mandatory prudential standard, enforceable | Voluntary certification management standard |
| Testing | Systematic independent testing, internal audit | Internal audits, management reviews, certification |
| Penalties | Regulatory enforcement, penalties, directions | No legal penalties, loss of certification |
Scope
Industry
Nature
Testing
Penalties
Frequently Asked Questions
Common questions about APRA CPS 234 and ISO 28000
APRA CPS 234 FAQ
ISO 28000 FAQ
You Might also be Interested in These Articles...

Asset-Backed Issuers and SEC Cybersecurity Rules: Applicability, Disclosures, and Compliance Roadmap
How SEC cybersecurity rules apply to asset-backed issuers (ABS): Form 10-D disclosures, ABS-EE risk management, Inline XBRL tagging, exemptions. Roadmap for tru

SOC 2 Trust Services Criteria in Plain English: Side-by-Side Decoder for Security, Availability, and Beyond
Decode AICPA Trust Services Criteria from auditor jargon to plain English with side-by-side tables, analogies & TL;DRs. CISOs & founders: implement SOC 2 contro

From SOC to AI-Native CDC: Redefining Triage and Response in 2026
Explore the shift from SOCs to AI-Native CDCs. Autonomous agents handle Tier 1 triage in 2026, empowering analysts for complex threats. Discover the future of c
Run Maturity Assessments with GRADUM
Transform your compliance journey with our AI-powered assessment platform
Assess your organization's maturity across multiple standards and regulations including ISO 27001, DORA, NIS2, NIST, GDPR, and hundreds more. Get actionable insights and track your progress with collaborative, AI-powered evaluations.
Check out these other Gradum.io Standards Comparison Pages
WCAG vs GLBA
WCAG vs GLBA: Compare web accessibility standards (POUR principles, AA conformance) with financial privacy rules (Safeguards, NPI protection). Boost compliance, cut risks. Dive in now!
CAA vs IFS Food
Compare CAA vs IFS Food: Navigate Clean Air Act regulations alongside food safety standards for manufacturers. Expert insights on compliance, risks & strategies. Boost efficiency now!
PIPEDA vs ISO 28000
Discover PIPEDA vs ISO 28000: Compare Canada's privacy law with supply chain security standards. Unlock key differences, compliance strategies & integration for resilient ops now!