CYB-10 · Cyber security
Public exposure of administrative interfaces (/admin, /wp-admin, /cpanel, /phpmyadmin, etc.) without strong authentication is one of the most exploited weaknesses in SA SME environments. Admin portals must not be publicly reachable or must require MFA before any content is served.
Trigger
Admin portal accessible from public internet without MFA, or returns a login page without any additional authentication layer, or server/CMS version information exposed in HTTP headers
Applicability gate
This is a readiness rule mapped to JS2 themes. Its presence in the library does not establish that JS2 applies directly to the firm.
Citation
This control maps to the public instruments below. The mapping does not establish entity applicability.
Remediation
Restrict admin portal access to IP allowlist or VPN. Enforce MFA on all admin accounts. Remove or mask server version headers (Server:, X-Powered-By:). Change default admin URL paths.
Evidence required
Automated assessment
Verified by the Provantis cyber scanner. Machine checks performed: