CPS 234 Information Security

CPS 234 focuses on control effectiveness rather than a country pin. Residency becomes useful when it reduces an untrusted environment and produces clearer evidence about access, lifecycle, and third parties.

Country
Australia
Rule type
Financial services
Regional pressure
Third-party assurance

Who this reaches

APRA-regulated entities and the information assets they manage directly or through related parties and third parties.

What the rule requires

Entities must maintain information-security capability and controls proportionate to threats and asset sensitivity, test control effectiveness, evaluate relevant third-party controls, and notify APRA of material incidents.

What changes when the email path is regional

Boundry's architecture and planned Region Manifest are structured around the data classes a third-party review asks about: content, metadata, queues, events, logs, support, subprocessors, retention, and exceptions.

What your team still owns

Boundry is not 'CPS 234 certified'. The regulated entity remains responsible for classifying the asset, evaluating Boundry's controls, testing reliance, and governing the complete service chain.

Read the primary sources

This is an engineering and vendor-evaluation guide, not legal advice. Confirm the current rule for your entity, contract, and workload from the primary source.

Turn this rule into an email path you can defend.

Start with one workflow. Classify the data, keep the message minimal, and trace it through the Sydney regional plane.