Cyber security · Sub-domain one
5 rules in this sub-domain. Each rule carries a citation, a trigger, evidence requirements and a remediation pathway.
Applicability gate
Confirm the entity's licensed capacity, actual services, agreement, data-processing role and Schedule 1 status. The audience-qualified publication rows below travel with this library and its public API.
Rules
CYB-01 · Joint Standard 2 of 2024 — paragraph 6.1.1 (strategy; annual review 6.1.2)
A written cybersecurity strategy must define the organisation's risk appetite, key cyber threats, control objectives, and improvement roadmap. Must be board-approved and reviewed at least annually or following material changes.
CYB-02 · Joint Standard 2 of 2024 — paragraphs 4.1 and 4.2.1 (roles and responsibilities) / King V Principle 12
The board or governing body must have explicit, documented accountability for cyber risk. This includes a designated board-level cyber risk owner, cyber items on board agenda at least quarterly, and evidence that the board understands and challenges the organisation's cyber risk exposure.
CYB-03 · Joint Standard 2 of 2024 — paragraphs 5.1 (governance) and 7.1 (identification) / Joint Standard 1 of 2023
A formal cyber risk register must identify, describe, and rate all material cyber risks facing the organisation. Risks must be classified by likelihood and impact, mapped to controls, and reviewed at least quarterly with findings escalated to governance.
CYB-04 · Joint Standard 2 of 2024 — paragraph 7.6.2 (threat intelligence and information sharing)
The organisation must have a mechanism to receive, assess, and act on cyber threat intelligence relevant to the SA insurance sector. Minimum: ASISA/SAIA CSIRT membership and alert subscription, with evidence that alerts are reviewed and actioned.
CYB-05 · Joint Standard 2 of 2024 — paragraphs 7.7.1 (control effectiveness) and 7.7.2–7.7.3 (vulnerability assessment and penetration testing)
Cybersecurity controls must be independently tested at least annually. This includes vulnerability assessments, penetration testing of client-facing systems, and/or scenario-based tabletop exercises. Findings must be tracked to closure.