Skip to main content

Repository → 💼 APRA CPG 234 → 💼 9 Policy framework - Exemption handling

💼 23 An APRA-regulated entity could consider implementing processes that ensure compliance with its information security policy framework and regulatory requirements. This could include an exemption policy defining registration, authorisation and duration requirements. Exemptions are typically administered using a register detailing nature, rationale and expiry date. APRA envisages that an entity would review and assess the adequacy of compensating controls both initially and on an ongoing basis

  • ID: /frameworks/apra-cpg-234/09/23

Description

Empty...

Similar

  • Internal
    • ID: dec-c-9c17564d

Sub Sections

SectionSub SectionsInternal RulesPoliciesFlagsCompliance