CYB-24 · Cyber security
All material outsourcing agreements must include: data security obligations, incident notification requirements (breach notification within 24–72 hours to the Responsible Party), right to audit, data return/destruction on termination, and sub-outsourcing restrictions. This extends to cloud providers, IT support companies, and managed service providers.
Trigger
Vendor agreements lack cyber security clauses; no breach notification obligation on vendors; no right to audit vendors; IT support company has admin access without a formal agreement
Applicability gate
This is a readiness rule mapped to JS2 themes. Its presence in the library does not establish that JS2 applies directly to the firm.
Citation
This control maps to the public instruments below. The mapping does not establish entity applicability.
Remediation
Audit all material vendor contracts for cyber security provisions. Execute addenda or new agreements to include: incident notification (≤24 hours), right to audit, sub-processing restrictions, and data destruction on exit.
Evidence required