Administration
Users & roles, the regulation engine, integrations, retention configuration, notification/escalation rules and API access (Section 4 — Administration; Module 8.1).
| Role | Primary Rights |
|---|---|
| Head / Board | Read portfolio posture; approve Cyber Security Policy, CCMP where applicable, critical remote operation/interconnection approvals; receive major audit findings. |
| CISO | Full compliance administration; approve non-critical remote access; review quarterly compliance; own incidents, risk, policies, audits and regulatory reporting. |
| Alternate CISO | Same operational capabilities under delegated/absence workflow; succession/coverage evidence. |
| Information Security Division | Operate controls, monitoring, incident response, evidence, asset/risk/patch records. |
| Site OT / SCADA Team | Maintain OT assets, network paths, changes, patches, local evidence; raise access/change requests. |
| IT Team | Maintain IT systems, web applications, public IPs, internet controls and IT patches. |
| Vendor / OEM | Restricted portal for BOM, patch, EOL, recovery plan, vulnerability disclosure, personnel and access requests. |
| Auditor | Read-only scoped access plus findings/retest/closure workflow; cannot alter evidence. |
| Compliance Owner | Self-audit, control assignment, evidence review, overdue management. |
| Read-only / Regulator Export | Controlled access to selected records or generated export packs only. |