CYB-04 · Cyber security
The organisation must have a mechanism to receive, assess, and act on cyber threat intelligence relevant to the SA insurance sector. Minimum: ASISA/SAIA CSIRT membership and alert subscription, with evidence that alerts are reviewed and actioned.
Trigger
Organisation not registered with ASISA/SAIA CSIRT, or no evidence of threat intel review process, or no action records against received alerts
Applicability gate
This is a readiness rule mapped to JS2 themes. Its presence in the library does not establish that JS2 applies directly to the firm.
Citation
This control maps to the public instruments below. The mapping does not establish entity applicability.
Remediation
Register with ASISA/SAIA CSIRT immediately (free for SAIA members). Subscribe to FSCA cyber advisories. Implement a monthly threat intel review process with documented actions.
Evidence required