Addressing the APRA CPS234 Compliance in Australia

How Thales Helps with the APRA Prudential Practice Guideline for CPS234 Compliance

APRA CPS 234 (Information Security) is a mandatory cybersecurity standard by the Australian Prudential Regulation Authority, which is to ensure that regulated entities can withstand cyberattacks and other security threats. In addition, when an obvious data breach or other security incident is discovered, businesses must respond in a timely manner.

APAC

    The Australian Prudential Regulation Authority (APRA) Prudential Practice Guidelines (PPG) CPG234 Information Security is to provide guidance to Boards, senior management, risk management and information security specialists (both management and operational) of APRA-regulated entities with respect to the implementation of Prudential Standard CPS234 Information Security. The multiple audiences reflect the pervasive nature of information security threats and vulnerabilities and the need for sound practices and a solid business understanding to maintain an information security capability in line with those threats and vulnerabilities.

    CPS234 applies to APRA-regulated entities namely:

    • Authorized deposit-taking institutions (ADIs), including foreign ADIs, credit unions, and banks
    • General insurers
    • Life companies and friendly societies
    • Private health insurance companies
    • Non-operating holding companies
    • Superannuation funds
    COMPLIANCE BRIEF

    Addressing APRA CPS234 Compliance in Australia

    Learn how Thales helps regulated entities comply with CPS234 by addressing the 5 guidance areas of the Prudential Practice Guidelines (PPG) CPG234.

    Get the Compliance Brief

    How Thales Helps with CPS234 Compliance

    Thales helps regulated entities comply with CPS234 by addressing the 5 guidance areas of the Prudential Practice Guidelines (PPG) CPG234: Information Security Capability, Policy Framework, Information Asset Identification and Classification, Implementation of Controls, and Incident Management.

    CPS234 Compliance

    CPS234 Compliance Solutions

      Application Security

      Protect applications and APIs at scale in the cloud, on-premises, or in a hybrid model. Our market leading product suite includes Web Application Firewall (WAF), protection against Distributed Denial of Service (DDoS) and malicious BOT attacks, and security for APIs

      Data Security

      Discover and classify sensitive data across hybrid IT and automatically protect it anywhere, whether at rest, in motion, or in use, using encryption tokenization and key management. Thales solutions also identify, evaluate, and prioritize potential risks for accurate risk assessment as well as identify anomalous behavior, and monitor activity to verify compliance, allowing organizations to prioritize where to spend their efforts.

      Identity & Access Management

      Provide seamless, secure and trusted access to applications and digital services for customers, employees and partners. Our solutions limit the access of internal and external users based on their roles and context with granular access policies and Multi-Factor Authentication that help ensure that the right user is granted access to the right resource at the right time.

      Address the CPG234 – Guidance

        How Thales helps:

        • Provide data activity monitoring for structured and unstructured data across cloud and on-prem systems.
        • Enforce separation of duty between your data and external parties as well as your cloud service provider (CSP) by securely storing encryption keys outside of the corresponding cloud.
        • Offer advanced multi-cloud Bring Your Own Encryption (BYOE) solutions to ensure data mobility to efficiently secure data across multiple cloud vendors with centralized and independent encryption key management.
        • Centralize key lifecycle management, including generation, rotation, destruction, import, and export.
        • Enforce access controls, including the use of passphrases or key encryption keys. Private keys stored in the HSM remain encrypted and require proper authentication to access.
        • Enable relationship management with suppliers, partners or any third-party user; with clear delegation of access rights.
        • Minimize privileges by using relationship-based fine-grained authorisation.
        • Manage all users, including the workforce, contractors, third-party users such as customers, suppliers, logistics, and B2B or B2C type users.

        How Thales helps:

        • Limit access to systems and data based on roles and context with policies.
        • Apply contextual security measures based on risk scoring.
        • Enable continuous monitoring to capture and analyze all data store activity, providing detailed audit trails that show who access what data, when, and what was done to the data.
        • Enable the separation of duties between the security administrator and the system administrator inside servers, ensuring the system admins or privileged accounts do not have access to sensitive encryption keys, while the security administrators do not have access to the data.
        • Centralize access policies and enforcement across multiple hybrid environments in a single pane of glass.
        • Offer “least privilege” access rights where minimum sufficient permissions are granted to legitimate users and adhere to a “deny all” access control policy for users by default.
        • Deploy time-bound access that restricts access to a specific period based on the nature of work.
        • Adopt robust user authorisation and authentication based on the criticality of IT assets by defining the right access policies, step-up authentication, and enforcing phishing-resistant authenticators.
        • Manage authentication and access control by supporting Multi-Factor Authentication and Single Sign-On (SSO) and displaying access log reports.

        How Thales helps:

        • Classify and assign specific sensitivity levels for data when you are defining your data stores and your classification profiles for different types of data sets.
        • Identify the current state of compliance and document gaps.
        • Encrypt data at rest on-premises, across clouds, and in big data or container environments.
        • Pseudonymize sensitive data at the source, ensuring that cleartext data is never exposed to unauthorized applications or personnel during processing or storage.
        • Offer advanced multi-cloud Bring Your Own Encryption (BYOE) solutions to ensure data mobility to efficiently secure data across multiple cloud vendors with centralized and independent encryption key management.
        • Provide data activity monitoring for structured and unstructured data across cloud and on-prem systems.
        • Ensure secure deletion by removing keys from CipherTrust Manager, digitally shredding all instances of the data.
        • Enforce access controls, including the use of passphrases or key encryption keys. Private keys stored in the HSM remain encrypted and require proper authentication to access.
        • Protect data in use by leveraging confidential computing.
        • Enable relationship management with suppliers, partners or any third-party user; with clear delegation of access rights.
        • Minimize privileges by using relationship-based fine-grained authorisation.

        How Thales helps:

        • Offer a highly available and distributed security architecture that eliminates single points of failure and protects critical systems from network faults and cyber threats, and supports reliable network service delivery.
        • Safeguard critical network assets from DDoS attacks and Bad Bots while continuing to allow legitimate traffic.
        • Offer a guaranteed SLA of 3 seconds or less for DDoS attacks targeting Layers 3 and 4, and protect organisations against volumetric and protocol-based threats.
        • Block threats such as SQL injection, XSS, and other OWASP Top 10 vulnerabilities – safeguarding web applications from threats.
        • Offer proactive managed rules to ensure organisations have the most up-to-date protection against common attack vector threats.
        • Centralize key lifecycle management tasks including generation, rotation, destruction, import and export.
        • Protect cryptographic keys in a tamper-resistant FIPS 140-3 Level 3 validated environment for securing the key lifecycle.
        • Manage and protect all secrets and sensitive credentials.
        • Offer key rotation to assist in recovery when cryptographic keys are compromised. Keys can be rotated on demand to minimize the impact of any key compromises.

        How Thales helps:

        • Limit access to systems and data based on roles and context with policies.
        • Apply contextual security measures based on risk scoring.
        • Enable continuous monitoring to capture and analyze all data store activity, providing detailed audit trails that show who accesses what data, when, and what was done to the data.
        • Centralize access policies and enforcement to multiple hybrid environments in a single pane of glass.
        • Provide a unified strategy for access control across all user populations.
        • Enable a consistent and policy-driven approach to identification, authentication, and authorisation of all users to their IT assets, data, and services.
        • Manage all users, including the workforce, contractors, third-party users such as customers, suppliers, logistics, and B2B or B2C type users.
        • Offer “least privilege” access rights where minimum sufficient permissions are granted to legitimate users and adhere to a “deny all” access control policy for users by default.

        How Thales helps:

        • Classify and assign specific sensitivity levels for data when you are defining your data stores and your classification profiles for different types of data sets.
        • Enable continuous monitoring to capture and analyze all data store activity, providing detailed audit trails that show who accesses what data, when, and what was done to the data.
        • Enforce granular access control (separated from the OS access control) with transparent encryption for privileged users to prevent misuse or abuse.

        How Thales helps:

        • Secure change management by enabling integration tools for versioning, traceability, and rollback capabilities.

        Solutions:

        Data Security

        Key Management

        Secrets Management

        How Thales helps:

        • Offer advanced API Verification capabilities to strengthen your defenses against potential vulnerabilities.
        • Run assessment tests on data stores such as MySQL or so to scan for known vulnerabilities.
        • Scan your databases with over 1,500 predefined vulnerability tests based on CIS and PCI-DSS benchmarks to help you keep your databases covered for the latest threats.

        Solutions:

        Application Security

        API Security

        Data Security

        Data Activity Monitoring

        How Thales helps:

        • Manage encryption keys and configure security policies centrally, enabling organisations to control and protect sensitive data through separation of duties.
        • Offer transparent encryption and access control for data residing.
        • Encrypt sensitive data once it is created and make sure cleartext data will not be processed or stored by unauthorized applications and personnel.
        • Allow root users to do their job without abusing data by privileged user access controls.
        • Enforce granular privileged-user-access management policies that can be applied by user, process, file type, time of day, and other parameters.
        • Provide complete separation of roles where only authorized users and processes can view unencrypted data.

        How Thales helps:

        • Manage encryption keys, provide granular access control and configure security policies.
        • Enforce granular access control (separated from the OS access control) with transparent encryption for privileged users to prevent misuse or abuse.
        • Manage system and data access rights (access control) by supporting role-based authorisation (Role-Based Access Control (RBAC)) and conditional authorisation (ABAC).
        • Control and manage privileged user accounts with granular access policies, and fine-grained authorisation policies by supporting the enforcement of multi-factor authentication (MFA) for accessing critical systems.
        • Design authorisation and approval procedures (User Journey Orchestration) for privileged user accounts and store and display as a privileged user activity report for detailed auditing.
        • Limit the access of internal and external users based on their roles and context with Identity Platform.
        • Implement physical access to sensitive facilities with SafeNet IDPrime smart cards, which can also augment Passwordless authentication initiatives relying on PKI and FIDO technology.

        How Thales helps:

        • Employ digital Signing for a wide range of applications with Hardware security modules (HSMs) to protect the private keys used for secure electronic signatures.
        • Support B2B and third-party identity access management for connected devices and external parties.
        • Provides authorisation and access-control policies that can be used to govern access from external, browserless, or constrained devices where integrated.

        Solutions:

        Data Security

        Hardware Security Modules

        Identity & Access Management

        Thales OneWelcome Identity Platform

        How Thales helps:

        • Provide data activity monitoring for structured and unstructured data across cloud and on-prem systems.
        • Monitor data access activity over time to set up alerts on activity that can put organisations at risk.
        • Offer advanced multi-cloud Bring Your Own Encryption (BYOE) solutions to ensure data mobility to efficiently secure data across multiple cloud vendors with centralized and independent encryption key management.
        • Retain full control and ownership of the sensitive data by controlling access to encryption keys via Cloud Key Management, negating the risk of data being released to foreign powers with the Hold-Your-Own-Key (HYOK) approach.
        • Enforce access controls, including the use of passphrases or key encryption keys. Private keys stored in the HSM remain encrypted and require proper authentication to access.
        • Enable relationship management with suppliers, partners or any third-party user; with clear delegation of access rights.
        • Minimize privileges by using relationship-based fine-grained authorisation.
        • Manage all users, including the workforce, contractors, third-party users such as customers, suppliers, logistics, and B2B or B2C type users.

        How Thales helps:

        • Detect system threats with Web Application Firewall, API Security and Database Security and stream logs to SIEM system.
        • Monitor API activity, track usage, detect anomalies, and identify potential unauthorized access attempts.
        • Offer advanced API Verification capabilities to strengthen your defenses against potential vulnerabilities.
        • Safeguard critical network assets from DDoS attacks and Bad Bots while continuing to allow legitimate traffic.
        • Run assessment tests on data stores such as MySQL or so to scan for known vulnerabilities.
        • Scan your databases with over 1,500 predefined vulnerability tests based on CIS and PCI-DSS benchmarks to help you keep your databases covered for the latest threats.
        • Eliminate the threat of an unauthorized or compromised user account gaining stealthy access to sensitive data with Security Intelligence logs that produce an auditable trail of permitted and denied access attempts from users and processes.
        • Monitor active processes to detect ransomware – identifying activities such as excessive data access, exfiltration, unauthorized encryption, or malicious impersonation of a user, and alerts/blocks when such an activity is detected.
        • Adjust access permissions based on real-time or near real-time user behavior and contextual factors, and maintain the highest level of security.
        • Monitor user behavior such as admin login from a new location/IP or a wrong system access pattern to alert and prevent attacks.

        How Thales helps:

        • Enforce very granular and least-privileged-user access management policies, enabling protection of data from misuse by privileged users and APT attacks.
        • Encrypt files, while leaving their metadata in the clear, so IT administrators - including hypervisor, cloud, storage, and server administrators - can perform their system administration tasks without being able to gain privileged access to the sensitive data residing on the systems they manage.
        • Encrypt sensitive data once it is created and make sure cleartext data will not be processed or stored by unauthorized applications and personnel.
        • Monitor active processes to detect ransomware – identifying activities such as excessive data access, exfiltration, unauthorized encryption, or malicious impersonation of a user, and alerts/blocks when such an activity is detected.
        • Safeguard the cryptographic keys used to secure applications and sensitive data with HSMs.
        • Offer centralized Administration and Access Control with role-based access controls. Using existing AD and LDAP credentials to authenticate and authorize administrators and key users, and prevent unauthorized password changes and alerts on simultaneous logins by the same user.
        • Offer key rotation that can assist in case of recovery where cryptographic keys are compromised. Keys can be rotated on demand to minimize the impact of any key compromises.

        How Thales helps:

        • Centrally enforce key rotation policies by automating rotation schedules, propagating new key versions, automatically rekeying protected data, and providing role-based access control with full audit logging.
        • Provide role-based access control (RBAC) to keys and policies, ensuring only authorized administrators can define or change rotation policies.
        • Ensure only authorized users can grant or change access rights; enforce consistent authorization policies across environments. 

        How Thales helps:

        • Provide network independent data-in-transit/ motion encryption (Layers 2,3 and 4) ensuring data is secure as it moves from site-to-site, or from on-premises to the cloud and back.
        • Encrypt sensitive data once it is created and make sure cleartext data will not be processed or stored by unauthorized applications.
        • Enforce security-by-design by ensuring sensitive data is protected during system development and modification.
        • Provide developers with accessible data protection tools such as encryption and key management to integrate security early in the development lifecycle and foster DevSecOps practices.
        • Shift Data Security operations to Data Security Admins, enabling better segregation of duties and change control for system modifications.
        • Deploy data protection controls in hybrid and multi-cloud applications to protect DevSecOps.
        • Easily access data security solutions through online marketplaces.
        • Protect and automate access to secrets across DevOps tools.
        • Secure change management by enabling integration tools for versioning, traceability, and rollback capabilities.
        • Safeguard critical network assets from DDoS attacks and Bad Bots while continuing to allow legitimate traffic.
        • Detect and prevent cyber threats with web application firewall, ensuring seamless operations and peace of mind.

        How Thales helps:

        • Provide various encryption options and methods to protect their data stored.
        • Centralize key lifecycle management tasks including generation, rotation, destruction, import and export.
        • Protect the root-of-trust of a cryptographic system within FIPS140-2 Level 3 - a highly secure environment.
        • Provide strong access controls to prevent unauthorized users from accessing sensitive cryptographic material.
        • Employ a three-layer authentication model to control administrative, client, and application access for data stored on the cryptographic engine.
        • Secure data in transit as it moves from site-to-site, or from on-premises to the cloud and back at Layers 2, 3, and/or 4 without slowing down the network.

        How Thales helps:

        • Manage encryption keys centrally, provide granular access control, and configure security policies.
        • Enforce access controls, including the use of passphrases or key encryption keys. Private keys stored in the HSM remain encrypted and require proper authentication to access.
        • Pseudonymize sensitive data at the source, ensuring that cleartext data is never exposed to unauthorized applications or personnel during processing or storage.
        • Record access to the database system and detect login attempts on the database system.
        • Detect and alert administrators if abnormal access attempts are found, and administrators can respond quickly.
        • Detect and pinpoint critical threats to data, prioritizes what matters most, and provides actionable insights.
        • Support the creation of audit trail reports of all accesses for auditing and investigation in the event of any incidents.
        • Offer key management, signing, and encryption services enabling comprehensive protection of files, database fields, big data selections, or data in platform-as-a-service (PaaS) environments.

        How Thales helps:

        • Protects data with data-at-rest encryption, access controls, and data access audit logging.
        • Deliver capabilities for database tokenization and dynamic display security and secures pseudonymizing sensitive assets.
        • Manage encryption keys and configure security policies to control and protect sensitive data with the separation of duties.

        How Thales helps:

        • Create strong separation of duties between privileged administrators and data owners to ensure one administrator does not have complete control over data security activities, encryption keys, or administration.
        • Support two-factor authentication for administrative access for centralized key management.
        • Allow organizations to virtually (or logically) limit access to confidential resources with MFA (including phishing-resistant authentication) and granular access policies.
        • Track identity events and provide analytics reports, including failed login attempts, user profile changes, changes to credentials and devices, consent grants and revocations, changes to group memberships.

        How Thales helps:

        • Offer centralized Administration and Access Control, which unifies key management operations with role-based access controls.
        • Secure applications and sensitive data with HSM to ensure compliance with an additional layer of protection.

        How Thales helps:

        • Identify and authenticate internal and external users to limit access to confidential resources with MFA and granular access policies.
        • Manage the third-party identity efficiently with its delegation management capability and mitigate risks from third parties.
        • Provide an immediate and up-to-date audit trail of all access events to all systems and stream logs to external SIEM systems.
        • Streamline and strengthen key management in cloud and enterprise environments over a diverse set of use cases with robust auditing and reporting.

        Other key data protection and security regulations

        PCI HSM

        Global

        MANDATE | ACTIVE NOW

        The PCI HSM specification defines a set of logical and physical security compliance standards for HSMs specifically for the payments industry. PCI HSM Compliance certification depends on meeting those standards.

        DORA

        Global

        REGULATION | ACTIVE NOW

        DORA aims to strengthen the IT security of financial entities to make sure the financial sector in Europe is resilient in the face of the growing volume and severity of cyber-attacks.

        Data Breach Notification Laws

        Global

        REGULATION | ACTIVE NOW

        Data breach notification requirements following loss of personal information have been enacted by nations around the globe. They vary by jurisdiction but almost universally include a “safe harbor” clause.

        GLBA

        Americas

        REGULATION | ACTIVE NOW

        The Gramm-Leach-Bliley Act (GLBA)--also known as the Financial Services Modernization Act of 1999--requires financial institutions to explain their information-sharing practices to their customers and to safeguard sensitive data.

        Contact a Compliance Specialist

        Contact Us