1. CPS 234 came into force on 1 July 2019. The standard applies to all APRA regulated entities which includes banks, general insurers, life insurers, private health insurers and superannuation funds.
2. The APRA ‘Cyber Security Strategy’ aims to increase board and executive management focus on information security risks, with internal audit seen as the ‘eyes and ears’ of a board into their organisation’s information security operations and practices.
3. Internal audit is required to evaluate information security controls, whether a service is provided in-house or by a related party or third party supplier.