Cyber security · Sub-domain four
6 rules in this sub-domain. Each rule carries a citation, a trigger, evidence requirements and a remediation pathway.
Applicability gate
Confirm the entity's licensed capacity, actual services, agreement, data-processing role and Schedule 1 status. The audience-qualified publication rows below travel with this library and its public API.
Rules
CYB-17 · Joint Standard 2 of 2024 — paragraph 7.5 (incident response and management) / POPIA s.22
A documented IRP is mandatory under Joint Standard 2 of 2024. The IRP must define: roles and responsibilities, communication escalation paths (including FSCA/regulator notification obligations), containment procedures, evidence preservation, and recovery steps. Critically, it must be tested — not just written.
CYB-18 · Joint Standard 2 of 2024 — paragraphs 7.4 (response and recovery) and 7.8 (learning and evolving) / Joint Standard 1
Ransomware renders unprotected backups useless. Backups must be: immutable or air-gapped (the 3-2-1-1 rule: 3 copies, 2 media types, 1 offsite, 1 immutable), encrypted at rest, and tested via restoration exercises at minimum quarterly. The RTO and RPO must be defined and achievable.
CYB-19 · Joint Standard 2 of 2024 — paragraphs 8.5 (vulnerability and patch management) and 8.7 (malware protection) / NIST CSF
Every endpoint (laptop, desktop, server) must be protected by an Endpoint Detection and Response (EDR) solution — not just legacy antivirus. EDR provides behavioural detection capable of identifying ransomware before full encryption. OS and software patching must be automated with a defined maximum patch window (Critical: 72 hours, High: 7 days).
CYB-20 · Joint Standard 2 of 2024 / NIST CSF / ISO 27001 A.13
Ransomware achieves maximum damage through lateral movement across flat networks. Key controls: network segmentation separating client-data systems from general corporate IT, disabled SMBv1, blocked lateral movement at firewall, and application whitelisting or equivalent on servers holding client data.
CYB-21 · Joint Standard 2 of 2024 / POPIA s.22 / SAIA CSIRT guidelines
ASISA and SAIA jointly operate a Computer Security Incident Response Team (CSIRT) that provides threat intelligence, incident coordination, and sector-specific support. Registration is free for members and is a fundamental baseline control. Additionally, the organisation must have a tested procedure for notifying the FSCA, POPIA Information Regulator, and clients in the event of a material cyber incident.
CYB-22 · Joint Standard 2 of 2024 — paragraph 7.3 (detection) / POPIA s.19
Without adequate logging, incident investigation and forensic analysis is impossible. All critical systems must generate security event logs that are centralised, tamper-protected, and retained for a minimum of 12 months. Logs must include authentication events, privilege escalations, and data access events.