ExportableProof — Routines today. Proof tomorrow.

Policy

Asset Management Policy

This document is Arcfield's Asset Management Policy, document ID ASSET-POL-001. It binds how Arcfield identifies, owns, classifies, protects, transfers and retires information and technology assets for the Arcfield Platform. It is not the ISMS Scope Statement, the Risk Assessment Methodology or the Statement of Applicability. It applies to Arcfield Platform production, customer data, CI/CD, privileged access and critical suppliers. Neighbouring records cite this Document Control version. Do not copy these paragraphs into those records.

This file is a fictional Arcfield example, not your organization's approved policy. Copy this file as the controlled Word master for your ISMS only after you replace Arcfield decisions with your own.

Back to demo

OSCAL source · AMP

{
  "artifactId": "AMP",
  "iso": [
    "A.5.9",
    "A.5.10",
    "A.5.11",
    "A.5.12",
    "A.5.13"
  ],
  "catalog": [
    {
      "iso": "A.5.9",
      "oscalId": "iso27001-a.5.9",
      "title": "Inventory of information and other associated assets",
      "className": "iso27001-annex-a",
      "group": "Organizational controls (Annex A.5)"
    },
    {
      "iso": "A.5.10",
      "oscalId": "iso27001-a.5.10",
      "title": "Acceptable use of information and other associated assets",
      "className": "iso27001-annex-a",
      "group": "Organizational controls (Annex A.5)"
    },
    {
      "iso": "A.5.11",
      "oscalId": "iso27001-a.5.11",
      "title": "Return of assets",
      "className": "iso27001-annex-a",
      "group": "Organizational controls (Annex A.5)"
    },
    {
      "iso": "A.5.12",
      "oscalId": "iso27001-a.5.12",
      "title": "Classification of information",
      "className": "iso27001-annex-a",
      "group": "Organizational controls (Annex A.5)"
    },
    {
      "iso": "A.5.13",
      "oscalId": "iso27001-a.5.13",
      "title": "Labelling of information",
      "className": "iso27001-annex-a",
      "group": "Organizational controls (Annex A.5)"
    }
  ],
  "profileAlters": [
    {
      "control-id": "iso27001-a.5.9",
      "adds": [
        {
          "props": [
            {
              "name": "applicability",
              "value": "applicable"
            },
            {
              "name": "applicability-justification",
              "value": "Required because in-scope assets support customer, HR, code, identity and evidence processes."
            },
            {
              "name": "implementation-status",
              "value": "Implemented"
            }
          ]
        }
      ]
    },
    {
      "control-id": "iso27001-a.5.10",
      "adds": [
        {
          "props": [
            {
              "name": "applicability",
              "value": "applicable"
            },
            {
              "name": "applicability-justification",
              "value": "Required for user obligations on company assets and services."
            },
            {
              "name": "implementation-status",
              "value": "Implemented"
            }
          ]
        }
      ]
    },
    {
      "control-id": "iso27001-a.5.11",
      "adds": [
        {
          "props": [
            {
              "name": "applicability",
              "value": "applicable"
            },
            {
              "name": "applicability-justification",
              "value": "Required during offboarding and role changes."
            },
            {
              "name": "implementation-status",
              "value": "Implemented"
            }
          ]
        }
      ]
    },
    {
      "control-id": "iso27001-a.5.12",
      "adds": [
        {
          "props": [
            {
              "name": "applicability",
              "value": "applicable"
            },
            {
              "name": "applicability-justification",
              "value": "Required for handling and protection decisions."
            },
            {
              "name": "implementation-status",
              "value": "Implemented"
            }
          ]
        }
      ]
    },
    {
      "control-id": "iso27001-a.5.13",
      "adds": [
        {
          "props": [
            {
              "name": "applicability",
              "value": "applicable"
            },
            {
              "name": "applicability-justification",
              "value": "Required to communicate classification handling."
            },
            {
              "name": "implementation-status",
              "value": "Implemented"
            }
          ]
        }
      ]
    }
  ],
  "components": [],
  "sspImplementedRequirements": []
}

Check installation

What is installed here. Extra volumes are optional and do not change Ready. Update re-runs the check.

CheckResult
Webserver…
Python…
Volumes…
Scripts…
Ready…
Working directory…
Last update…