Case Study: APRA CPS 234 Policy and Standards Uplift
Client: Mid-tier APRA-regulated financial services organisation
Fortian helped the client transform a fragmented, ad hoc set of security policies into a cohesive, risk-based standards suite aligned to APRA CPS 234 and the NIST Cybersecurity Framework 2.0, closing audit findings and establishing a consistent, comprehensive control framework across the information security function.
The Challenge
A mid-tier APRA-regulated financial services client faced a policy and standards environment that had grown without central direction:
- Policies and standards developed in an ad hoc manner over time, with no consistent structure or ownership
- Inconsistent terminology and control language across documents, creating ambiguity for staff and auditors
- Controls that no longer reflected actual operating practice, and were not mapped to an industry standard framework
- Non-alignment with APRA CPS 234 requirements
- Controls applied uniformly rather than to risk, and disconnected from the client's enterprise risk management framework, leaving no clear line of sight between security risk and enterprise risk reporting
- Audit findings citing gaps in policy coverage, consistency and enforceability
Our Approach
Fortian undertook a structured uplift of the client's information security policy and standards suite, aligning it to APRA CPS 234 and to the NIST Cybersecurity Framework 2.0 for comprehensive, industry-benchmarked coverage. Every control was interpreted against regulatory intent, tested against how the client actually operated, and validated with the people accountable for it. The engagement covered:
- Stakeholder Management – Engaged the executive sponsor, CISO and CTO throughout the program to secure buy-in and align the suite with strategic direction, and ran working sessions with security, technology and risk stakeholders to test drafts for practical usability before finalisation
- Policy and Standards Audit – Reviewed the existing suite against CPS 234 and NIST CSF 2.0 and prior audit findings to identify gaps, redundancies and inconsistencies
- House Style and Terminology Framework – Established consistent terminology, a common document structure, and obligation-led control drafting to improve readability and reduce ambiguity for staff and auditors
- Core Policy Development – Drafted an overarching Information Security Policy to anchor the suite and set governance intent
- Standards Development – Developed a set of supporting standards spanning the client's core security domains, mapped to the NIST CSF 2.0 functions and categories to close coverage gaps beyond minimum regulatory requirements
- Control Alignment – Rewrote control language so stated requirements matched actual operating practice, removing controls the client could not evidence and adding those needed to meet its obligations
- Risk-Based Framework – Established a risk-based approach to control application, aligned to the client's enterprise risk management framework, so the rigour of controls was proportionate to risk and reported through existing risk governance channels rather than applied uniformly or in isolation
Delivery Approach
Fortian ran the engagement as a staged program:
- Engaged the executive sponsor, CISO and CTO from the outset and maintained that engagement throughout, keeping the suite aligned with organisational priorities and securing sign-off at each stage
- Commenced with the policy and standards audit to scope the extent of rework required
- Established the house style and terminology framework before drafting began, to ensure consistency and readability across every document
- Developed the overarching Information Security Policy and the risk-based framework first, so subordinate standards could be drafted against a consistent governance intent and controls scaled to risk from the start rather than retrofitted
- Delivered supporting standards across the core security domains in priority order, validated through stakeholder review at each stage
The Outcome
The engagement delivered a cohesive, defensible policy and standards suite:
- A usable, readable suite with practical utility across the client's business, not just a compliance artefact
- Strong executive ownership of the suite, building confidence in its ongoing use
- Closure of the audit findings, with control language that reflects actual operating practice and reduces the risk of future findings
- Controls applied proportionate to risk and connected to the enterprise risk management framework, giving security risk a clear line of sight into enterprise risk reporting
- Comprehensive coverage of the client's security domains, benchmarked against NIST CSF 2.0
- A defensible basis for demonstrating regulatory alignment to APRA and to internal risk committees
Why Fortian
Fortian's deep familiarity with APRA prudential standards and the NIST CSF, a disciplined house style, and close engagement with the client's executive and technology leadership took the client from a fragmented, non-compliant policy environment to a usable, defensible, risk-based suite, closing audit findings and building genuine organisational ownership of the framework.
That outcome came down to judgement, specifically knowing what auditors expect to see, ensuring real and practical alignment between controls and risk, and bringing stakeholders with different priorities together around a suite they could all stand behind.