Map assets, data flows, trust boundaries and responsible parties.
A.M.P.E.R.E. TOOLKIT · ANNEX E
Cybersecurity and Privacy Readiness
Reviews governance, identity, data protection, monitoring, response and vendor risk.
A decision instrument, not a paperwork exercise.
Prepare the governance and operating controls required before connecting field devices, communications and utility systems at scale.
Start with uncertainty.
Use the annex to make the decision and its missing evidence visible before discussing a preferred product or schedule.
- 01Who owns security, privacy, incident response and third-party access?
- 02How are identities, privileges, keys and remote sessions controlled?
- 03What data is collected, retained, shared and protected?
- 04Can the utility detect, contain, recover from and learn from an incident?
Required inputs
- Security and privacy policies
- Architecture, data-flow and asset information
- Identity, access, logging and vendor-access procedures
- Incident response, backup and continuity plans
Controlled outputs
- Security and privacy gap register
- Prioritized control-improvement plan
- Required pilot security tests
- Named risk owners and escalation paths
Four disciplined moves.
Review identity, encryption, logging, patching and remote-access controls.
Test incident, recovery and vendor-support responsibilities.
Record residual risks and required actions before pilot approval.
What this page does not do.
This readiness review does not constitute penetration testing, legal compliance certification or an independent security audit. This educational page explains the instrument but does not reproduce its complete working tables. Use the controlled Protocol PDF and the responsible professional or authority for actual project work.
Open the complete working instrument in Protocol 3.2.
The downloadable publication preserves the full annex, version context and framework limitations.