Security News

APRA releases IT Security management guide

loop technology has put together a guide on how to align it strategies to the ppg234 apra guide. to download a copy click HERE.

 

Monday, 22 February 2010

APRA releases guidance on the management of security risk in information and information technology

The Australian Prudential Regulation Authority (APRA) has published a prudential practice guide (PPG) on the management of security risk in information and information technology by financial institutions  it supervises.

Last year a draft PPG and discussion paper were released for public consultation with response to the draft being positive.

The final PPG aims to target areas where APRA’s ongoing supervisory activities continue to identify weaknesses. Topics addressed include the importance of an overarching framework, systematic IT asset life-cycle management, effective monitoring processes and robust IT security reporting and assurance mechanisms.

The PPG is designed to provide guidance to senior management, risk management and IT security specialists (management and operational). It does not seek to provide an all-encompassing framework nor to replace or endorse existing industry standards and guidelines.

Prudential Practice Guide PPG 234 Management of Security Risk in Information and Information Technology is available for download here.

The Australian Prudential Regulation Authority (APRA) is the prudential regulator of the financial services industry. It oversees banks, credit unions, building societies, general insurance and reinsurance companies, life insurance, friendly societies, and most members of the superannuation industry. APRA is funded largely by the industries that it supervises. It was established on 1 July 1998. APRA currently supervises institutions holding approximately $3.6 trillion in assets for 22 million Australian depositors, policyholders and superannuation fund members.