CPS 230 Postcard #5 Flashcards

1
Q

What is the title of CPS 230?

A

Operational Risk Management

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Which regulator set the regulatory requirement known as CPS 230?

A

APRA

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are the general goals of CPS 230?

A

Strengthening operational resilience & reducing disruption to customer, company & country

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are the three main expected outcomes of CPS 230?

A
  1. Effectively managing risks.
  2. Maintaining COs within tolerance levels through severe but plausible disruptions.
  3. Effectively managing the risks associated with the use of service providers.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are the 3 key dates for NAB regarding CPS 230?

A
  • 31 Dec 24: Internal readiness target
  • 1 July 25: Effective date
  • 1 July 26: Material Service Provider contracts udpated
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What 2 key things must we do to fundamentally shift how we manage Critical Operations?

A
  1. Maintain/Strengthen COs, which often span across Divisions, while recognising FAR accountabilities.
  2. Effectively connect, manage, and strengthen the ecosystem of each CO, comprising the service providers, technology assets, office locations, and enabling teams that support them.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

How many Critical Operations does NAB have?

A

17

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Regarding Critical Operations, what are some workstream highlights completed in April?

A
  1. Reduced COs from 19 to 17
  2. Progressed BIAs for COs
  3. L4 Processes validated by CO Owners.
  4. Updated NFI/FI tables to support Risk Profiles.
  5. ‘Critical Process’ measure for prioritising PACE delivery at NAB has been retired.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Why are we mobilising Critical Operations? (6 steps)

A
  1. COs defined (based on L4 processes)
  2. Dependencies mapped (based on BIAs)
  3. Impact Tolerance Levels defined and tested
  4. Risk Profiles approved
  5. Gaps & exposures identified
  6. Remediation plans approved (for elements negatively impacting the resilience of COs)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What activities will CO owners be completing in April?

A
  • Validate L4 processes by 30 April
  • Triage sessions to identify FY25 funding requirements
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What activities will CO owners be completing in May?

A
  • L4 processes for all COs documented in PH by end of May
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What activities will CO owners be completing in June?

A
  • CO Owners define tolerance levels
  • CO Risk Profiles commence
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What activities will CO owners be completing in August?

A
  • Gaps in L4 processes certified
  • Commence drafting Customer Playbooks
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What activities will CO owners be completing in September?

A
  • BIAs approved by CO Owners
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What activities will CO owners be completing in October?

A
  • Risk profiles approved by CO Owners
  • MSP register confirmed
  • Findings raised in GRACE
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What 5 CPS 230 features have already been completed?

A
  1. Identify Critical Operations
  2. Identify CO Owners
  3. Identify CO Processes
  4. Tech Integration
  5. Define Framework
17
Q

When was Identify Critical Operations completed?

A

Oct 23

18
Q

When was Identify CO Owners completed?

A

Dec 23

19
Q

When was Identify CO processes completed?

A

Feb 24

20
Q

When are the two CO drops?

A

April and June 24

21
Q

When will CO reporting be delivered?

A

August 24