Add Operational Best Practices for APRA CPS 234 and CPS 230 - #457
Open
jaybilgaye wants to merge 1 commit into
Open
Add Operational Best Practices for APRA CPS 234 and CPS 230#457jaybilgaye wants to merge 1 commit into
jaybilgaye wants to merge 1 commit into
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
I confirm these files are made available under CC0 1.0 Universal (https://creativecommons.org/publicdomain/zero/1.0/legalcode)
Issue #, if available: -
Description of changes:
Description
Adds two new conformance packs for the Australian Prudential Regulation Authority (APRA) prudential standards:
aws-config-conformance-packs/Operational-Best-Practices-for-APRA-CPS-234.yaml— CPS 234 Information Security (46 rules)aws-config-conformance-packs/Operational-Best-Practices-for-APRA-CPS-230.yaml— CPS 230 Operational Risk Management (32 rules)Both standards are mandatory for all APRA-regulated entities in Australia (ADIs/banks, general & life insurers, private health insurers and superannuation/RSE licensees).
The repo already ships
Operational-Best-Practices-for-APRA-CPG-234.yaml, but that maps CPG 234 (APRA's non-binding practice guide). There is currently no pack for the binding standards CPS234 or CPS 230. These fill that gap and complement the existing APRA/ACSC packs.
CPS 234 (Information Security) — 46 rules
Maps the AWS-observable requirements of CPS 234:
CloudTrail (multi-region + log-file validation + KMS), Config, VPC flow logs, GuardDuty, Security Hub, AWS Backup coverage.
CPS 230 (Operational Risk Management) — 32 rules
Maps the AWS-observable operational-risk controls:
tunnels.
Governance/process paragraphs (board roles, policy framework, incident notification, internal audit, service-provider management) are intentionally out of scope — not observable via AWS Config.
Testing
cfn-lintpasses cleanly on both files.aws configservice put-conformance-pack.Operational-Best-Practices-for-BCP-and-DR.yamlpack.References