Files
hermes-brain/ideas/compliance/apra-cps-234.org
Hermes cc3976fb7f ideas: editorial sweep — atomization, interlinking, restructuring
- Split competitive-analysis-2026-05.org → TOC + 9 competitor files in
  ideas/competitors/. Dropped date from filename. All competitor UUIDs
  generated, TOC keeps original UUID for backlink continuity.
- Deleted passepartout-economics.org archive (replaced by 27-node KB).
- Inlined 5 'See also' blocks into natural prose (compliance-index,
  first-mover-window, revenue-table, orders-of-magnitude-time,
  native-org-knowledge-base).
- Linked 7 orphan compliance pages back to compliance index + finished
  truncated sentences.
- Linked all 14 Agora requirement docs from topic-relevant pages
  (identity→lisp-machine-security, infrastructure→compute-marketplace,
  social-space→growth-strategy, exchange→agora-contracts, etc.).
- Linked ai-industry-impact from investment-thesis, sufficiency-flip,
  verification-appliance, effects-growth-flywheel (up from 1 to 10+ pages).
- Fixed CREATED timestamps to use git commit dates instead of today.
- Made all links absolute from root (no port inheritance).
- Removed stale agora/docs/ duplicate content.
2026-05-24 16:25:55 +00:00

1.2 KiB

APRA CPS 234 (Prudential Standard — Information Security)

APRA CPS 234 (Prudential Standard — Information Security)

Australian Prudential Regulation Authority standard for regulated financial institutions. Requires: clearly defined information security roles and responsibilities, periodic cybersecurity capability assessments, robust control testing, timely remediation of control weaknesses, mandatory notification of material incidents to APRA within 72 hours.

Who must comply: Banks, insurers, superannuation funds regulated by APRA. ~500 entities.

Penalties: APRA can impose capital requirements, license conditions, or license cancellation for non-compliance. Personal liability for board and senior management.

Why it matters: CPS 234's control testing requirement creates demand for continuous verification — exactly what the gate stack and evaluation harness provide. First-mover advantage: CPS 234 is mature (2019) but enforcement is escalating. No vendor provides a deterministic control-testing pipeline.