← Cyber Security and Resilience

Cyber security · Sub-domain one

Joint Standard 2 Governance

5 rules in this sub-domain. Each rule carries a citation, a trigger, evidence requirements and a remediation pathway.

Applicability gate

A rule's presence does not establish a direct legal duty

Confirm the entity's licensed capacity, actual services, agreement, data-processing role and Schedule 1 status. The audience-qualified publication rows below travel with this library and its public API.

Js2 2024
  • Insurance Broker: Most independent non-life Category I brokers are not directly in JS2's defined scope. A broker may be directly in scope if it separately meets a listed category, and may face contract or oversight requirements from an in-scope institution. Third-party provisions impose duties on the in-scope financial institution. They do not themselves make every supplier or intermediary directly subject to JS2.
  • Uma Binder Holder: UMA or binder-holder status is not itself listed in JS2's definition. Direct scope depends on another listed capacity; insurer contracts and oversight may create evidence requirements. JS2 paragraph 3.3 concerns juristic persons structured under an insurer or designated insurance group; it is not a blanket rule for every independent UMA or intermediary.
  • Insurer: An insurer as defined in the Insurance Act is directly in scope of JS2 from 1 June 2025. Apply proportionality and distinguish the insurer's own duty from requirements it places on third parties.
2
Critical — board exposure
3
High — significant exposure
0
Medium — material exposure
0
Low — hygiene

Rules

5 rules in Joint Standard 2 Governance

CYB-01 · Joint Standard 2 of 2024 — paragraph 6.1.1 (strategy; annual review 6.1.2)

Cybersecurity strategy — documented, board-approved, and aligned to business goals

Critical

A written cybersecurity strategy must define the organisation's risk appetite, key cyber threats, control objectives, and improvement roadmap. Must be board-approved and reviewed at least annually or following material changes.

Trigger
No documented cybersecurity strategy, or strategy not approved at board level, or strategy last reviewed > 12 months ago

CYB-02 · Joint Standard 2 of 2024 — paragraphs 4.1 and 4.2.1 (roles and responsibilities) / King V Principle 12

Board cyber accountability — governing body personally accountable for cyber risk oversight

Critical

The board or governing body must have explicit, documented accountability for cyber risk. This includes a designated board-level cyber risk owner, cyber items on board agenda at least quarterly, and evidence that the board understands and challenges the organisation's cyber risk exposure.

Trigger
No designated board-level cyber risk owner, or no cyber agenda items in board packs for the last 2 quarters, or board members have not received cyber awareness briefing

CYB-03 · Joint Standard 2 of 2024 — paragraphs 5.1 (governance) and 7.1 (identification) / Joint Standard 1 of 2023

Cyber risk register — documented, classified by criticality, reviewed quarterly

High

A formal cyber risk register must identify, describe, and rate all material cyber risks facing the organisation. Risks must be classified by likelihood and impact, mapped to controls, and reviewed at least quarterly with findings escalated to governance.

Trigger
No cyber risk register, or register not reviewed in last 6 months, or risks not classified by likelihood and impact

CYB-04 · Joint Standard 2 of 2024 — paragraph 7.6.2 (threat intelligence and information sharing)

Cyber threat intelligence — organisation actively receives and acts on current threat intelligence

High

The organisation must have a mechanism to receive, assess, and act on cyber threat intelligence relevant to the SA insurance sector. Minimum: ASISA/SAIA CSIRT membership and alert subscription, with evidence that alerts are reviewed and actioned.

Trigger
Organisation not registered with ASISA/SAIA CSIRT, or no evidence of threat intel review process, or no action records against received alerts

CYB-05 · Joint Standard 2 of 2024 — paragraphs 7.7.1 (control effectiveness) and 7.7.2–7.7.3 (vulnerability assessment and penetration testing)

Controls assurance — annual independent testing of cybersecurity controls

High

Cybersecurity controls must be independently tested at least annually. This includes vulnerability assessments, penetration testing of client-facing systems, and/or scenario-based tabletop exercises. Findings must be tracked to closure.

Trigger
No independent cyber controls test in the last 12 months, or findings from last assessment not tracked or remediated