Cyber security · Sub-domain five
4 rules in this sub-domain. Each rule carries a citation, a trigger, evidence requirements and a remediation pathway.
Applicability gate
Confirm the entity's licensed capacity, actual services, agreement, data-processing role and Schedule 1 status. The audience-qualified publication rows below travel with this library and its public API.
Rules
CYB-23 · Joint Standard 2 of 2024 — paragraphs 4.2.3, 7.2.3(a)(iii), 7.7.1(b) and 8.1.1(f) (third-party) / Joint Standard 1
Most SA short-term insurance brokers depend on 3–6 shared technology platforms: a policy admin system (TIAL, Genius, Flexi), a comparator, insurer extranets, and a CRM. A compromise of any single vendor can expose every broker using that platform simultaneously. A formal third-party cyber risk register must document all vendors with access to client data, their assessed risk, and oversight controls.
CYB-24 · Joint Standard 2 of 2024 — paragraph 4.2.3 (SLA roles and responsibilities) / POPIA s.20-21 / Joint Standard 1
All material outsourcing agreements must include: data security obligations, incident notification requirements (breach notification within 24–72 hours to the Responsible Party), right to audit, data return/destruction on termination, and sub-outsourcing restrictions. This extends to cloud providers, IT support companies, and managed service providers.
CYB-25 · Joint Standard 1 of 2023 (IT continuity management) / Joint Standard 2 of 2024 — paragraph 7.4 (response and recovery)
Almost all SA short-term insurance brokers depend on a single Policy Administration System. A ransomware attack on the PAS vendor — or a cloud outage — can render the broker operationally blind. The risk of this dependency must be explicitly assessed, with documented manual fallback procedures and SLA-backed recovery commitments from the vendor.
CYB-26 · Joint Standard 2 of 2024 / POPIA s.19 / CIS Cloud Benchmarks
Three of South Africa's biggest data exposures in recent years were caused by misconfigured cloud storage (S3 buckets, Azure Blob storage) left publicly accessible. Any cloud-hosted system holding client data must be audited for public exposure, default credential usage, and excess permissions (over-privileged service accounts).