CYB-03 · Cyber security
A formal cyber risk register must identify, describe, and rate all material cyber risks facing the organisation. Risks must be classified by likelihood and impact, mapped to controls, and reviewed at least quarterly with findings escalated to governance.
Trigger
No cyber risk register, or register not reviewed in last 6 months, or risks not classified by likelihood and impact
Applicability gate
This is a readiness rule mapped to JS2 themes. Its presence in the library does not establish that JS2 applies directly to the firm.
Citation
This control maps to the public instruments below. The mapping does not establish entity applicability.
Remediation
Develop a cyber risk register using a standard risk taxonomy. Include risk owner, inherent rating, control description, and residual rating. Review quarterly.
Evidence required