South Africa Joint Standard 2 of 2024 — Cybersecurity and Cyber Resilience
Mandatory cybersecurity and cyber resilience requirements for all South African financial institutions including banks, insurers, market infrastructure, pension funds, and fund managers. Issued jointly by FSCA and Prudential Authority. 21 requirements covering governance, strategy, asset classification, risk assessment, access control, network security, monitoring, incident response, resilience, threat intelligence, testing, MFA, data protection, cryptography, patching, personnel security, third-party management, and regulatory reporting. Effective June 2025.
| Clause | Title | SP 800-53 Controls |
|---|---|---|
| JS2-4 | Governance of Cybersecurity and Cyber Resilience | |
| JS2-5 | Cybersecurity Strategy and Framework | |
| JS2-6.1 | Information Asset Classification and Inventory | |
| JS2-6.2 | Security Risk Assessment | |
| JS2-7.1 | Access Control and Identity Management | |
| JS2-7.2 | Network and Infrastructure Security | |
| JS2-7.3 | Security Monitoring and Detection | |
| JS2-7.4 | Incident Response and Management | |
| JS2-7.5 | Cyber Resilience and Recovery | |
| JS2-7.6 | Threat Intelligence and External Monitoring | |
| JS2-7.7 | Testing and Assurance | |
| JS2-8.1 | Multi-Factor Authentication | |
| JS2-8.2 | Data Protection and Loss Prevention | |
| JS2-8.3 | Cryptographic Controls and Key Management | |
| JS2-8.4 | Malware Protection and Endpoint Security | |
| JS2-8.5 | Patch and Vulnerability Management | |
| JS2-8.6 | Personnel Security and Awareness | |
| JS2-8.7 | Third-Party and Outsourcing Security | |
| JS2-9 | Notifications and Regulatory Reporting | |
| JS2-PE | Physical and Environmental Security | |
| JS2-SA | Secure Software Development and Application Security |