CYB-26 · Cyber security
Three of South Africa's biggest data exposures in recent years were caused by misconfigured cloud storage (S3 buckets, Azure Blob storage) left publicly accessible. Any cloud-hosted system holding client data must be audited for public exposure, default credential usage, and excess permissions (over-privileged service accounts).
Trigger
No cloud security review in last 12 months; cloud storage buckets with public access enabled; default cloud service account credentials in use; no cloud security posture management (CSPM) tool deployed
Applicability gate
This is a readiness rule mapped to JS2 themes. Its presence in the library does not establish that JS2 applies directly to the firm.
Citation
This control maps to the public instruments below. The mapping does not establish entity applicability.
Remediation
Run a cloud security assessment using native tools (Microsoft Secure Score, AWS Security Hub, GCP Security Command Center). Block all public storage access. Rotate default credentials. Implement least-privilege IAM roles. Enable cloud-level audit logging.
Evidence required