ExportableProof — Routines today. Proof tomorrow.

Policy

Human Resources Policy

This document is Arcfield's Human Resources Policy, document ID HR-POL-001. It binds HR lifecycle controls that support security: joiners, movers, contractors and leavers for people with Arcfield Platform access. It is not the ISMS Scope Statement, the Risk Assessment Methodology or the Statement of Applicability. It applies to Arcfield Platform production, customer data, CI/CD, privileged access and critical suppliers. Neighbouring records cite this Document Control version. Do not copy these paragraphs into those records.

This file is a fictional Arcfield example, not your organization's approved policy. Copy this file as the controlled Word master for your ISMS only after you replace Arcfield decisions with your own.

Back to demo

OSCAL source · HRP

{
  "artifactId": "HRP",
  "iso": [
    "A.6.1",
    "A.6.2",
    "A.6.3",
    "A.6.4",
    "A.6.5",
    "7.2"
  ],
  "catalog": [
    {
      "iso": "A.6.1",
      "oscalId": "iso27001-a.6.1",
      "title": "Screening",
      "className": "iso27001-annex-a",
      "group": "People controls (Annex A.6)"
    },
    {
      "iso": "A.6.2",
      "oscalId": "iso27001-a.6.2",
      "title": "Terms and conditions of employment",
      "className": "iso27001-annex-a",
      "group": "People controls (Annex A.6)"
    },
    {
      "iso": "A.6.3",
      "oscalId": "iso27001-a.6.3",
      "title": "Information security awareness, education and training",
      "className": "iso27001-annex-a",
      "group": "People controls (Annex A.6)"
    },
    {
      "iso": "A.6.4",
      "oscalId": "iso27001-a.6.4",
      "title": "Disciplinary process",
      "className": "iso27001-annex-a",
      "group": "People controls (Annex A.6)"
    },
    {
      "iso": "A.6.5",
      "oscalId": "iso27001-a.6.5",
      "title": "Responsibilities after termination or change of employment",
      "className": "iso27001-annex-a",
      "group": "People controls (Annex A.6)"
    },
    {
      "iso": "7.2",
      "oscalId": "iso27001-7.2",
      "title": "Competence",
      "className": "iso27001-clause",
      "group": "Support"
    }
  ],
  "profileAlters": [
    {
      "control-id": "iso27001-7.2",
      "adds": [
        {
          "props": [
            {
              "name": "applicability",
              "value": "applicable"
            },
            {
              "name": "applicability-justification",
              "value": "ISO/IEC 27001:2022 management-system clause. Always in the certification scope; not subject to Annex A SoA exclusion."
            },
            {
              "name": "implementation-status",
              "value": "always-in-scope"
            }
          ]
        }
      ]
    },
    {
      "control-id": "iso27001-a.6.1",
      "adds": [
        {
          "props": [
            {
              "name": "applicability",
              "value": "applicable"
            },
            {
              "name": "applicability-justification",
              "value": "Required for relevant roles before employment."
            },
            {
              "name": "implementation-status",
              "value": "Implemented"
            }
          ]
        }
      ]
    },
    {
      "control-id": "iso27001-a.6.2",
      "adds": [
        {
          "props": [
            {
              "name": "applicability",
              "value": "applicable"
            },
            {
              "name": "applicability-justification",
              "value": "Required for contractual security obligations."
            },
            {
              "name": "implementation-status",
              "value": "Implemented"
            }
          ]
        }
      ]
    },
    {
      "control-id": "iso27001-a.6.3",
      "adds": [
        {
          "props": [
            {
              "name": "applicability",
              "value": "applicable"
            },
            {
              "name": "applicability-justification",
              "value": "Required for staff and contractors."
            },
            {
              "name": "implementation-status",
              "value": "Implemented"
            }
          ]
        }
      ]
    },
    {
      "control-id": "iso27001-a.6.4",
      "adds": [
        {
          "props": [
            {
              "name": "applicability",
              "value": "applicable"
            },
            {
              "name": "applicability-justification",
              "value": "Required for security policy violations."
            },
            {
              "name": "implementation-status",
              "value": "Planned"
            }
          ]
        }
      ]
    },
    {
      "control-id": "iso27001-a.6.5",
      "adds": [
        {
          "props": [
            {
              "name": "applicability",
              "value": "applicable"
            },
            {
              "name": "applicability-justification",
              "value": "Required for offboarding and role changes."
            },
            {
              "name": "implementation-status",
              "value": "Implemented"
            }
          ]
        }
      ]
    }
  ],
  "components": [],
  "sspImplementedRequirements": [
    {
      "control-id": "iso27001-a.6.4",
      "props": [
        {
          "name": "iso-id",
          "value": "A.6.4"
        },
        {
          "name": "applicability",
          "value": "applicable"
        },
        {
          "name": "evidence-layer",
          "value": "documented"
        },
        {
          "name": "implementation-status-raw",
          "value": "Planned"
        },
        {
          "name": "control-owner",
          "value": "HR Manager"
        },
        {
          "name": "evidence-status",
          "value": "Partial"
        },
        {
          "name": "unresolved-evidence",
          "value": "HRP"
        }
      ],
      "links": [
        {
          "rel": "cites",
          "text": "SOA"
        },
        {
          "rel": "cites",
          "text": "ISOCTRL"
        }
      ]
    }
  ]
}

Check installation

What is installed here. Extra volumes are optional and do not change Ready. Update re-runs the check.

CheckResult
Webserver…
Python…
Volumes…
Scripts…
Ready…
Working directory…
Last update…