CYB-30 · Cyber security
With load-shedding forcing staff to work from homes or alternative locations, remote working security is a persistent gap. All remote access to corporate systems and client data must be via VPN or a Zero Trust Network Access (ZTNA) solution. BYOD (personal device) usage for client data access must be governed by a formal policy with minimum security requirements.
Trigger
Staff accessing client data over public WiFi without VPN; no remote access policy; personal devices accessing client data without minimum security controls; no mobile device management (MDM) on devices with client data
Applicability gate
This is a readiness rule mapped to JS2 themes. Its presence in the library does not establish that JS2 applies directly to the firm.
Citation
This control maps to the public instruments below. The mapping does not establish entity applicability.
Remediation
Deploy VPN or ZTNA for all remote access. Implement a BYOD policy requiring minimum controls (MDM enrolment, device encryption, remote wipe capability, MFA). Ban use of public WiFi without VPN in acceptable use policy.
Evidence required