CYB-02 · Cyber security
The board or governing body must have explicit, documented accountability for cyber risk. This includes a designated board-level cyber risk owner, cyber items on board agenda at least quarterly, and evidence that the board understands and challenges the organisation's cyber risk exposure.
Trigger
No designated board-level cyber risk owner, or no cyber agenda items in board packs for the last 2 quarters, or board members have not received cyber awareness briefing
Applicability gate
This is a readiness rule mapped to JS2 themes. Its presence in the library does not establish that JS2 applies directly to the firm.
Citation
This control maps to the public instruments below. The mapping does not establish entity applicability.
Remediation
Designate a board cyber risk owner (non-exec or dedicated role). Add cyber MI to standing board agenda. Schedule an annual board cyber awareness briefing.
Evidence required