Cyber security · Sub-domain three
4 rules in this sub-domain. Each rule carries a citation, a trigger, evidence requirements and a remediation pathway.
Applicability gate
Confirm the entity's licensed capacity, actual services, agreement, data-processing role and Schedule 1 status. The audience-qualified publication rows below travel with this library and its public API.
Rules
CYB-13 · Joint Standard 2 of 2024 — paragraphs 7.2.2 (identity and access management) and 8.3 (multi-factor authentication) / POPIA s.19
MFA is the single most effective control against credential-based attacks — which account for the majority of SA financial sector breaches. MFA must be enforced (not optional) for: email, policy admin systems, CRMs, file sharing, and any system holding client personal information. Joint Standard 2 explicitly mandates MFA.
CYB-14 · Joint Standard 2 of 2024 — paragraphs 7.2.2 and 8.2 (privileged access management) / ISO 27001 A.9
Local and global admin accounts represent the highest-value target for attackers. Privileged accounts must be: minimised (least privilege principle), named to individuals (no shared admin accounts), MFA-enforced, and reviewed quarterly. Break-glass emergency accounts must be sealed and audited.
CYB-15 · Joint Standard 2 of 2024 — paragraphs 7.2.2 and 8.1 (access management) / POPIA s.19
Orphaned accounts (former staff, former contractors) represent a persistent access risk. A formal joiners-movers-leavers (JML) process must exist to provision, modify, and revoke access to all systems within defined timeframes. Departing staff access must be revoked on the same day as departure.
CYB-16 · Joint Standard 2 of 2024 / NIST SP800-63b
Password policy must enforce: minimum 12 characters, complexity requirements, and prohibition of reuse (last 12 passwords). Ideally aligned to NIST SP800-63b (length over complexity). Leaked credential monitoring must be in place to identify staff credentials that have appeared in data breach databases.