CYB-01 · Cyber security
A written cybersecurity strategy must define the organisation's risk appetite, key cyber threats, control objectives, and improvement roadmap. Must be board-approved and reviewed at least annually or following material changes.
Trigger
No documented cybersecurity strategy, or strategy not approved at board level, or strategy last reviewed > 12 months ago
Applicability gate
This is a readiness rule mapped to JS2 themes. Its presence in the library does not establish that JS2 applies directly to the firm.
Citation
This control maps to the public instruments below. The mapping does not establish entity applicability.
Remediation
Engage a qualified cyber security practitioner to draft a strategy. Present to board for approval. Include: risk appetite statement, threat landscape assessment, control objectives, and a 12-month improvement roadmap.
Evidence required