Relevant Control: CPS 234.5
"An APRA-regulated entity must maintain information security capabilities commensurate with the size and extent of threats to its information assets, and sufficient to ensure the continued sound operation of the entity."
Mapping:
- Code Scanning & Static Analysis: Identify vulnerabilities early to secure applications.
- Vulnerability Management: Continuously assess and mitigate threats.
- CI/CD Pipeline Scanning: Secure each stage of the software lifecycle against potential threats.