Skip to main content

💼 5 Information security capability - Assessing sufficiency of capability

  • ID: /frameworks/apra-cpg-234/05

Description​

Empty...

Similar​

  • Internal
    • ID: dec-b-a7d7eb42

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlagsCompliance
💼 15 In discharging its responsibility for information security, an APRA-regulated entity would typically assess the sufficiency of its information security capability. This could include reviewing the adequacy of resourcing, including funding and staffing, timely access to necessary skill sets and the comprehensiveness of the control environment — preventative, detective and responsive.no data
💼 16 The current threat landscape has necessitated information security capabilities that extend beyond information technology general controls to more specialised information security capabilities.92730no data
 💼 16a vulnerability and threat management;1010no data
 💼 16b situational awareness and intelligence;67no data
 💼 16c information security operations and administration;44no data
 💼 16d secure design, architecture and consultation;11no data
 💼 16e security testing, including penetration testing;99no data
 💼 16f information security reporting and analytics;911no data
 💼 16g incident detection and response, including recovery, notification and communication;22no data
 💼 16h information security investigation, including preservation of evidence and forensic analysis;no data
 💼 16i information security assurance.no data