ServiceNow Response to CPS 234 Regulatory Obligations
Introduction
Due to the increasing cyber-attacks in the Australian financial industry, the Australian Prudential Regulation Authority (APRA) has published the Prudential Standard CPS 234 Information Security (CPS 234) to ensure that APRA regulated entities, such as superannuation funds, banks, and insurance companies, meets the minimum standards for resilience against information security incidents (such as cyber-attacks), and their ability to quickly and swiftly respond in the event of a data breach.
CPS 234 requires APRA-regulated entities to:
- clearly define information security related roles and responsibilities.
- maintain an information security capability commensurate with the size and extent of threats to their information assets.
- implement controls to protect information assets and undertake regular testing and assurance of the effectiveness of controls; and
- promptly notify APRA of material information security incidents.
The aim of CPS 234 is to assist APRA regulated entities to reduce cyber risk and increase their overall cyber security posture, minimize the likelihood and the impact information security incidents, including those managed by third-party service providers, such as ServiceNow.
ServiceNow Response to CPS 234 Regulatory Obligations
ServiceNow’s responses below provides the details of the CPS 234 regulatory obligations, and maps these obligations against ServiceNow’s Platform capabilities, Information security controls and contractual commitments, and includes supporting information to assist ServiceNow customers to comply with their APRA CPS 243 regulatory obligations.
It is important to note ServiceNow is not an APRA-regulated entity. ServiceNow recommends APRA-regulated customers, under the direction of the Board, to closely collaborate and coordinate between various departments within their organisation, such as Information Technology, security, risk management, legal, and compliance, to undertake any activities required to comply with CPS 234 regulatory obligations.
| CPS 234 Key requirements | CPS 234 Provisions | ServiceNow Response |
|---|---|---|
| Roles and responsibilities | 13. The Board of an APRA-regulated entity (Board) is ultimately responsible for the information security of the entity. The Board must ensure that the entity maintains information security in a manner commensurate with the size and extent of threats to its information assets, and which enables the continued sound operation of the entity. | This is a customer's responsibility.Although ServiceNow is not an APRA regulated entity, ServiceNow is a publicly traded company on the New York Exchange, where ServiceNow is required to comply with The U.S. Securities and Exchange Commission (SEC) disclosure requirements such as Cyber Governance, Cyber risk management and strategy and Cyber incident reporting.ServiceNow's security organization is led by ServiceNow's Chief Information Security Officer (CISO), who is also responsible for reporting to ServiceNow's Board. |
https://www.servicenow.com/community/platform-privacy-security-blog/servicenow-response-to-cps-234-regulatory-obligations/ba-p/2652987