CYB-05 · Cyber security
Cybersecurity controls must be independently tested at least annually. This includes vulnerability assessments, penetration testing of client-facing systems, and/or scenario-based tabletop exercises. Findings must be tracked to closure.
Trigger
No independent cyber controls test in the last 12 months, or findings from last assessment not tracked or remediated
Applicability gate
This is a readiness rule mapped to JS2 themes. Its presence in the library does not establish that JS2 applies directly to the firm.
Citation
This control maps to the public instruments below. The mapping does not establish entity applicability.
Remediation
Commission an annual vulnerability assessment and penetration test (VAPT) by a qualified tester. Implement a findings tracker. Conduct a tabletop incident exercise with the leadership team.
Evidence required