43% of APRA CPS 234 you already have
FDA Quality Management System Regulation (QMSR) already covers about 43% of APRA CPS 234, leaving
20 of 35 controls as genuinely new work.
Already covered 1
Likely covered 14
New work 20
What is genuinely new work
Nothing in FDA Quality Management System Regulation (QMSR) reaches these. This is the list to scope.
CPS234-01Information security program management
CPS234-02Board and management oversight
CPS234-03Risk appetite and tolerance for IT risk
CPS234-04Security policy framework
CPS234-07Endpoint protection and detection
CPS234-13Board Responsibility for Information Security
CPS234-17Contractual security requirements
CPS234-19Information Security Policy Framework
CPS234-22Control Testing Programme
CPS234-24Customer notification procedures
CPS234-27Audit of Third Party Information Security
CPS234-28Documented Reporting of Material Findings
CPS234-30Incident Response Plans
CPS234-32Incident Response Testing
CPS234-35APRA Notification of Material Incidents
CPS234-36APRA Notification of Control Weaknesses
CPS234-39Encryption of Sensitive Data
CPS234-41Vulnerability Management
CPS234-43Security Awareness Training
Show the 15 you already have
CPS234-05Roles and responsibilities definition
CPS234-06Network security and segmentation
CPS234-08Application security controls
CPS234-09Encryption and key management
CPS234-10Secure configuration standards
CPS234-11Business continuity planning and testing
CPS234-12Disaster recovery procedures
CPS234-14Roles and Responsibilities
CPS234-15Information Security Capability
CPS234-16Capability of Third Parties
CPS234-18Ongoing monitoring and assessment
CPS234-20Information Asset Identification and Classification
CPS234-21Implementation of Controls
CPS234-23Frequency and Methodology of Testing
CPS234-25Internal Audit of Information Security
How this is calculated
Already covered means a mapping runs from a control in FDA Quality Management System Regulation (QMSR) to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition