← Cyber Security and Resilience

Cyber security · Sub-domain four

Operational Resilience

6 rules in this sub-domain. Each rule carries a citation, a trigger, evidence requirements and a remediation pathway.

Applicability gate

A rule's presence does not establish a direct legal duty

Confirm the entity's licensed capacity, actual services, agreement, data-processing role and Schedule 1 status. The audience-qualified publication rows below travel with this library and its public API.

Js2 2024
  • Insurance Broker: Most independent non-life Category I brokers are not directly in JS2's defined scope. A broker may be directly in scope if it separately meets a listed category, and may face contract or oversight requirements from an in-scope institution. Third-party provisions impose duties on the in-scope financial institution. They do not themselves make every supplier or intermediary directly subject to JS2.
  • Uma Binder Holder: UMA or binder-holder status is not itself listed in JS2's definition. Direct scope depends on another listed capacity; insurer contracts and oversight may create evidence requirements. JS2 paragraph 3.3 concerns juristic persons structured under an insurer or designated insurance group; it is not a blanket rule for every independent UMA or intermediary.
  • Insurer: An insurer as defined in the Insurance Act is directly in scope of JS2 from 1 June 2025. Apply proportionality and distinguish the insurer's own duty from requirements it places on third parties.
2
Critical — board exposure
4
High — significant exposure
0
Medium — material exposure
0
Low — hygiene

Rules

6 rules in Operational Resilience

CYB-17 · Joint Standard 2 of 2024 — paragraph 7.5 (incident response and management) / POPIA s.22

Incident Response Plan (IRP) — written, tested annually, and includes a cyber-specific playbook

Critical

A documented IRP is mandatory under Joint Standard 2 of 2024. The IRP must define: roles and responsibilities, communication escalation paths (including FSCA/regulator notification obligations), containment procedures, evidence preservation, and recovery steps. Critically, it must be tested — not just written.

Trigger
No documented IRP; IRP not tested in last 12 months; IRP does not cover cyber incident scenarios; FSCA notification procedure not included in IRP

CYB-18 · Joint Standard 2 of 2024 — paragraphs 7.4 (response and recovery) and 7.8 (learning and evolving) / Joint Standard 1

Backup and recovery — immutable, offsite backups tested; recovery time objective (RTO) defined

Critical

Ransomware renders unprotected backups useless. Backups must be: immutable or air-gapped (the 3-2-1-1 rule: 3 copies, 2 media types, 1 offsite, 1 immutable), encrypted at rest, and tested via restoration exercises at minimum quarterly. The RTO and RPO must be defined and achievable.

Trigger
Backup only stored on same system as production data; no offsite/cloud backup; backup restoration not tested in last 6 months; no defined RTO/RPO; backups stored in same cloud tenant as primary systems (same ransomware blast radius)

CYB-19 · Joint Standard 2 of 2024 — paragraphs 8.5 (vulnerability and patch management) and 8.7 (malware protection) / NIST CSF

Endpoint protection — all devices running current EDR/AV with automatic patching enabled

High

Every endpoint (laptop, desktop, server) must be protected by an Endpoint Detection and Response (EDR) solution — not just legacy antivirus. EDR provides behavioural detection capable of identifying ransomware before full encryption. OS and software patching must be automated with a defined maximum patch window (Critical: 72 hours, High: 7 days).

Trigger
Endpoints running legacy antivirus without EDR capability; automatic patching disabled; unpatched critical CVEs on production systems; personal/unmanaged devices used to access client data

CYB-20 · Joint Standard 2 of 2024 / NIST CSF / ISO 27001 A.13

Ransomware resilience — network segmentation and lateral movement controls in place

High

Ransomware achieves maximum damage through lateral movement across flat networks. Key controls: network segmentation separating client-data systems from general corporate IT, disabled SMBv1, blocked lateral movement at firewall, and application whitelisting or equivalent on servers holding client data.

Trigger
Flat network with no segmentation; SMBv1 enabled on any network device; no firewall rules restricting lateral movement; client data accessible from all network segments
High

ASISA and SAIA jointly operate a Computer Security Incident Response Team (CSIRT) that provides threat intelligence, incident coordination, and sector-specific support. Registration is free for members and is a fundamental baseline control. Additionally, the organisation must have a tested procedure for notifying the FSCA, POPIA Information Regulator, and clients in the event of a material cyber incident.

Trigger
Organisation not registered with ASISA/SAIA CSIRT; no documented notification procedure for cyber incidents; notification procedure not tested in last 12 months

CYB-22 · Joint Standard 2 of 2024 — paragraph 7.3 (detection) / POPIA s.19

Security event logging — centralised logging enabled; logs retained for minimum 12 months

High

Without adequate logging, incident investigation and forensic analysis is impossible. All critical systems must generate security event logs that are centralised, tamper-protected, and retained for a minimum of 12 months. Logs must include authentication events, privilege escalations, and data access events.

Trigger
No centralised log management; logs stored only on source systems (modifiable by attackers); logs retained for less than 12 months; authentication events not logged