Swipe to see all columns →
| Clause | Requirement | Runback capability | Evidence |
|---|---|---|---|
| Information security capability | Maintain information security capability commensurate with the size and extent of threats to information assets. | Policy engine with runtime enforcement | A policy rule evaluated on a real tool call See it in the dashboard → |
| Access control | Implement access controls to information assets, including for third parties, commensurate with the criticality of the asset. | SSO (OIDC) + team roles (RBAC) | Whether SSO (OIDC) + RBAC is enabled for your org See it in the dashboard → |
| Incident management | Have robust mechanisms to detect and respond to information security incidents in a timely manner. | Alert rules + immutable, tamper-evident ledger | An entry in the hash-chained, append-only ledger See it in the dashboard → |
| Testing program | Test information security controls through a systematic testing program. | Golden test suite + Upgrade gate | A captured run in the audit trace See it in the dashboard → |
Honest limits
What this page does not claim.
- As with CPS 230, the citations below are section-level, not independently re-verified paragraph numbering against the current CPS 234 PDF.
- CPS 234 requires testing and assurance of security controls at a program level. Runback's golden-test suite and policy engine are two inputs to that, not the whole program.
- This is a capability map, not a conformity determination. Whether your deployment satisfies APRA CPS 234 is a determination for your own assessor — what's listed above is the evidence that argument draws on.