CYB-06 · Cyber security
All client-facing web properties (website, quote portals, client portals) must enforce HTTPS with a valid, current TLS certificate. HTTP requests must redirect to HTTPS. HSTS (Strict-Transport-Security) header must be present. Session cookies must carry Secure and HttpOnly flags.
Trigger
HTTP not redirecting to HTTPS, HSTS header absent, TLS certificate expired or expiring within 30 days, or session cookies without Secure/HttpOnly flags
Applicability gate
This is a readiness rule mapped to JS2 themes. Its presence in the library does not establish that JS2 applies directly to the firm.
Citation
This control maps to the public instruments below. The mapping does not establish entity applicability.
Remediation
Enforce HTTPS site-wide. Implement HSTS header (min-age: 31536000). Audit all session cookie configurations. Renew certificates before expiry — automate via Let's Encrypt or equivalent.
Evidence required
Automated assessment
Verified by the Provantis cyber scanner. Machine checks performed: