CYB-17 · Cyber security
A documented IRP is mandatory under Joint Standard 2 of 2024. The IRP must define: roles and responsibilities, communication escalation paths (including FSCA/regulator notification obligations), containment procedures, evidence preservation, and recovery steps. Critically, it must be tested — not just written.
Trigger
No documented IRP; IRP not tested in last 12 months; IRP does not cover cyber incident scenarios; FSCA notification procedure not included in IRP
Applicability gate
This is a readiness rule mapped to JS2 themes. Its presence in the library does not establish that JS2 applies directly to the firm.
Citation
This control maps to the public instruments below. The mapping does not establish entity applicability.
Remediation
Develop a cyber-specific IRP using the NIST incident response framework (Identify → Protect → Detect → Respond → Recover). Include regulator notification procedures (FSCA, Information Regulator, ASISA/SAIA CSIRT). Conduct an annual tabletop exercise and document findings.
Evidence required