Define audit scope, criteria, independence and evidence needs.
A.M.P.E.R.E. TOOLKIT · ANNEX P
Cybersecurity and Data Governance Audit
Verifies data, access, encryption, logging, response, vendors and awareness controls.
A decision instrument, not a paperwork exercise.
Test whether required cybersecurity, privacy and data-governance controls are operating and evidenced after design and deployment.
Start with uncertainty.
Use the annex to make the decision and its missing evidence visible before discussing a preferred product or schedule.
- 01Are identities, privileges, keys and remote access operating as approved?
- 02Can logs, incidents, changes and vendor activity be reconstructed?
- 03Are data collection, retention, sharing and disposal controlled?
- 04Have corrective actions been verified rather than merely reported?
Required inputs
- Approved control framework and architecture
- Asset, identity, access, log and change records
- Data inventory, privacy and retention evidence
- Incident, vendor, training and corrective-action records
Controlled outputs
- Audit findings and evidence register
- Risk rating and corrective-action plan
- Control-owner and closure verification
- Management and governance reporting
Four disciplined moves.
Test design and operating effectiveness of selected controls.
Rate findings and assign accountable corrective actions.
Verify closure and report residual risk.
What this page does not do.
A website guide cannot define the final audit scope or substitute for competent independent security, privacy or legal review. This educational page explains the instrument but does not reproduce its complete working tables. Use the controlled Protocol PDF and the responsible professional or authority for actual project work.
Open the complete working instrument in Protocol 3.2.
The downloadable publication preserves the full annex, version context and framework limitations.