Cyber security · Sub-domain seven
2 rules in this sub-domain. Each rule carries a citation, a trigger, evidence requirements and a remediation pathway.
Applicability gate
Confirm the entity's licensed capacity, actual services, agreement, data-processing role and Schedule 1 status. The audience-qualified publication rows below travel with this library and its public API.
Rules
CYB-31 · Joint Standard 2 of 2024 (resilience) — SA-specific risk factor
This risk is unique to South Africa. During load-shedding: firewalls and monitoring systems lose power if not UPS-backed, access control systems go offline, staff switch to personal mobile data (bypassing corporate security), and backup generators introduce new unmanaged network devices. Each of these creates a window of elevated cyber exposure that attackers know how to exploit.
CYB-32 · Joint Standard 2 of 2024 / FAIS Act risk management / Cyber insurance best practice
Cyber-insurance applications may ask the applicant to declare whether controls such as MFA, backups and incident response are implemented. Those declarations should be checked against current evidence before submission. A Provantis readiness assessment can organise that evidence but does not determine coverage or guarantee claim acceptance.