← Cyber Security and Resilience

Cyber security · Sub-domain three

Identity and Access Control

4 rules in this sub-domain. Each rule carries a citation, a trigger, evidence requirements and a remediation pathway.

Applicability gate

A rule's presence does not establish a direct legal duty

Confirm the entity's licensed capacity, actual services, agreement, data-processing role and Schedule 1 status. The audience-qualified publication rows below travel with this library and its public API.

Js2 2024
  • Insurance Broker: Most independent non-life Category I brokers are not directly in JS2's defined scope. A broker may be directly in scope if it separately meets a listed category, and may face contract or oversight requirements from an in-scope institution. Third-party provisions impose duties on the in-scope financial institution. They do not themselves make every supplier or intermediary directly subject to JS2.
  • Uma Binder Holder: UMA or binder-holder status is not itself listed in JS2's definition. Direct scope depends on another listed capacity; insurer contracts and oversight may create evidence requirements. JS2 paragraph 3.3 concerns juristic persons structured under an insurer or designated insurance group; it is not a blanket rule for every independent UMA or intermediary.
  • Insurer: An insurer as defined in the Insurance Act is directly in scope of JS2 from 1 June 2025. Apply proportionality and distinguish the insurer's own duty from requirements it places on third parties.
1
Critical — board exposure
2
High — significant exposure
1
Medium — material exposure
0
Low — hygiene

Rules

4 rules in Identity and Access Control

CYB-13 · Joint Standard 2 of 2024 — paragraphs 7.2.2 (identity and access management) and 8.3 (multi-factor authentication) / POPIA s.19

Multi-factor authentication (MFA) — enforced for all staff accounts across all systems

Critical

MFA is the single most effective control against credential-based attacks — which account for the majority of SA financial sector breaches. MFA must be enforced (not optional) for: email, policy admin systems, CRMs, file sharing, and any system holding client personal information. Joint Standard 2 explicitly mandates MFA.

Trigger
MFA not enforced on email accounts; MFA not enforced on policy admin system; MFA optional rather than mandatory for any system holding client PII

CYB-14 · Joint Standard 2 of 2024 — paragraphs 7.2.2 and 8.2 (privileged access management) / ISO 27001 A.9

Privileged access management — admin/elevated accounts limited, documented, and reviewed

High

Local and global admin accounts represent the highest-value target for attackers. Privileged accounts must be: minimised (least privilege principle), named to individuals (no shared admin accounts), MFA-enforced, and reviewed quarterly. Break-glass emergency accounts must be sealed and audited.

Trigger
Shared admin accounts in use; privileged accounts not reviewed in last 6 months; admin accounts used for day-to-day tasks; no record of who holds elevated privileges

CYB-15 · Joint Standard 2 of 2024 — paragraphs 7.2.2 and 8.1 (access management) / POPIA s.19

Access lifecycle management — user access provisioned, reviewed, and deprovisioned systematically

High

Orphaned accounts (former staff, former contractors) represent a persistent access risk. A formal joiners-movers-leavers (JML) process must exist to provision, modify, and revoke access to all systems within defined timeframes. Departing staff access must be revoked on the same day as departure.

Trigger
No formal JML access management process; evidence of active accounts for former employees; access not reviewed in last 6 months; no defined revocation SLA

Password policy must enforce: minimum 12 characters, complexity requirements, and prohibition of reuse (last 12 passwords). Ideally aligned to NIST SP800-63b (length over complexity). Leaked credential monitoring must be in place to identify staff credentials that have appeared in data breach databases.

Trigger
Password policy below 8 characters; no complexity requirements enforced; no password history restriction; no breach credential monitoring in place