CYB-19 · Cyber security
Every endpoint (laptop, desktop, server) must be protected by an Endpoint Detection and Response (EDR) solution — not just legacy antivirus. EDR provides behavioural detection capable of identifying ransomware before full encryption. OS and software patching must be automated with a defined maximum patch window (Critical: 72 hours, High: 7 days).
Trigger
Endpoints running legacy antivirus without EDR capability; automatic patching disabled; unpatched critical CVEs on production systems; personal/unmanaged devices used to access client data
Applicability gate
This is a readiness rule mapped to JS2 themes. Its presence in the library does not establish that JS2 applies directly to the firm.
Citation
This control maps to the public instruments below. The mapping does not establish entity applicability.
Remediation
Deploy a modern EDR solution (e.g., Microsoft Defender for Endpoint, CrowdStrike, SentinelOne). Enable automatic OS patching. Implement a patch management policy with defined SLAs by severity. Ensure all endpoints are managed and enrolled.
Evidence required