ExportableProof — Routines today. Proof tomorrow.

Arcfield A.6 · People audit

Source: Arcfield EN Companion · Volume 1 audit + OSCAL assessment plan (AP) / assessment results (AR) · oscal/assessment-plan.md, oscal/assessment-results.md · HITL: oscal-guide.md · SIMULATION

How this report is elaborated

Scope is the Volume 1 A.6 · People audit. Identities are the applicable ISO clauses or Annex A controls in this prefix. Process topics remain the operational evidence (hr).

The process we followed is ISO 27001 → Policies → Processes and Systems → Protected Assets → Objects needed by the process → Evidences. Standard vs policy examines whether a policy covers the cited clause or control. Policy vs evidence tests the join from policy rule to recorded evidence.

How to read this report

Start with Results at a glance, then how this category is set up. Glance is Conformity (share without an NC) plus Defined / Implemented / Effectiveness. An NC is recorded when there is no policy and no implementation evidence (Requirement ↔ evidence), when a measure is implemented without effectiveness evidence (Requirement ↔ evidence), or when the kernel join FAILs (Policy ↔ evidence, default minor). Standard vs policy stays HITL. Presence is not Defined = yes as a coverage PASS. UNKNOWN is not an NC.

Results at a glance

0 %Conformity8/8 NC. Share without an NC. DK/NA are out of the denominator. Not a certification statement.
50 %Defined4/8 yes. Defined = yes / rated artefacts or identities. partially is not yes.
50 %Implemented4/8 yes. Implemented = yes / rated artefacts or identities. partially is not yes.
0 %Effectiveness0/4 yes. Effective = yes / rated artefacts or identities. partially is not yes.

Conformity is the share of applicable identities without an NC. Companion Contract/Example unchanged. This is not a certification statement.

How A.6 · People is set up

Human Resources Security Policy
Vol. 1Vol. 2installeddocumentedPremium

Documented evidence in this pack. Not a certification PASS.

Artefact

Human Resources Policy
Vol. 1installeddocumentedPremium

Documented evidence in this pack. Not a certification PASS.

Artefact

Mandatory Documents and Records Register
Vol. 2not installedimplementedBasic

Named implemented evidence. Not in this pack.

Artefact

Document Register
Vol. 1Vol. 2installedimplementedPremium

Implemented evidence in this pack. Not a certification PASS.

Artefact

Records Retention Schedule
Vol. 2not installedimplementedPremium

Named implemented evidence. Not in this pack.

Artefact

Asset Inventory
Vol. 1Vol. 2Vol. 3installedimplementedBasic

Implemented evidence in this pack. Not a certification PASS.

Artefact

Users and Access Inventory
Vol. 2Vol. 3not installedimplementedPremium

Named implemented evidence. Not in this pack.

Artefact

Onboarding Checklist
Vol. 1installedimplementedPremium

Implemented evidence in this pack. Not a certification PASS.

Artefact

Offboarding Checklist
Vol. 1installedimplementedPremium

Implemented evidence in this pack. Not a certification PASS.

Artefact

Training Register
Vol. 1installedimplementedPremium

Implemented evidence in this pack. Not a certification PASS.

Artefact

Training Records
Vol. 1installedimplementedPremium

Implemented evidence in this pack. Not a certification PASS.

Artefact

Topic reports remain the process evidence: hr.

Nonconformities

Nonconformities this pack can show. Kernel FAIL is Policy ↔ evidence, default minor — not an automatic major. No policy and no implementation, or implementation without effectiveness evidence, is Requirement ↔ evidence. UNKNOWN is not an NC. Assessment Results stay the kernel SSOT. How to fix is the follow-up, not a customer ticket.

RequirementStatementGradePathDetail
A.6.1 ScreeningA.6.1 Screening is named in this pack, but there is no effectiveness evidence. Cited policy: HRSP. Cited implementation: MDR, DR, RRS, AI, UAI.minorRequirement ↔ evidenceNC-A6-missing-evidence
A.6.2 Terms and conditions of employmentA.6.2 Terms and conditions of employment is named in this pack, but there is no effectiveness evidence. Cited policy: HRSP. Cited implementation: MDR, DR, RRS, AI, UAI.minorRequirement ↔ evidenceNC-A6-missing-evidence
A.6.3 Information security awareness, education and trainingA.6.3 Information security awareness, education and training is named in this pack, but there is no effectiveness evidence. Cited policy: HRSP. Cited implementation: MDR, DR, RRS, AI, UAI.minorRequirement ↔ evidenceNC-A6-missing-evidence
A.6.4 Disciplinary processA.6.4 Disciplinary process has no policy and no implementation evidence in this pack.minorRequirement ↔ evidenceNC-A6-not-implemented
A.6.5 Responsibilities after termination or change of employmentA.6.5 Responsibilities after termination or change of employment is named in this pack, but there is no effectiveness evidence. Cited policy: HRSP. Cited implementation: MDR, DR, RRS, AI, UAI.minorRequirement ↔ evidenceNC-A6-missing-evidence
A.6.6 Confidentiality or non-disclosure agreementsA.6.6 Confidentiality or non-disclosure agreements has no policy and no implementation evidence in this pack.minorRequirement ↔ evidenceNC-A6-not-implemented
A.6.7 Remote workingA.6.7 Remote working has no policy and no implementation evidence in this pack.minorRequirement ↔ evidenceNC-A6-not-implemented
A.6.8 Information security event reportingA.6.8 Information security event reporting has no policy and no implementation evidence in this pack.minorRequirement ↔ evidenceNC-A6-not-implemented

ISO 27001 norms and controls

Cited clauses and Annex A controls for this category. Defined is a cited policy (HOW). Standard vs policy stays HITL: Defined = yes does not score that the text covers the control. Implemented is in-pack or named operating evidence. Effective is the kernel join or HITL effectiveness. No policy and no implementation is an NC. Implementation without effectiveness evidence is an NC. Ratings are yes, no, or partially. DK or NA when this pack has no data.

IndexNameKindDefinedImplementedEffective
A.6.1Screeningcontrolyesyesno
A.6.2Terms and conditions of employmentcontrolyesyesno
A.6.3Information security awareness, education and trainingcontrolyesyesno
A.6.4Disciplinary processcontrolnonoDK
A.6.5Responsibilities after termination or change of employmentcontrolyesyesno
A.6.6Confidentiality or non-disclosure agreementscontrolnonoDK
A.6.7Remote workingcontrolnonoDK
A.6.8Information security event reportingcontrolnonoDK

What we found

What this pack actually cited for this clause or control identity. Counts are from this pack. Presence is not a PASS. No ISO shall-text.

A.6.1 Screening

Quantitative

Qualitative

Cited artefacts in this pack: HRSP, MDR, DR, RRS, AI, UAI. Nonconformities recorded: A.6.1 Screening is named in this pack, but there is no effectiveness evidence. Cited policy: HRSP. Cited implementation: MDR, DR, RRS, AI, UAI.. Other-book files stay on acquire pages. This chapter does not invent their content.

A.6.2 Terms and conditions of employment

Quantitative

Qualitative

Cited artefacts in this pack: HRSP, MDR, DR, RRS, AI, UAI. Nonconformities recorded: A.6.2 Terms and conditions of employment is named in this pack, but there is no effectiveness evidence. Cited policy: HRSP. Cited implementation: MDR, DR, RRS, AI, UAI.. Other-book files stay on acquire pages. This chapter does not invent their content.

A.6.3 Information security awareness, education and training

Quantitative

Qualitative

Cited artefacts in this pack: HRSP, MDR, DR, RRS, AI, UAI. Nonconformities recorded: A.6.3 Information security awareness, education and training is named in this pack, but there is no effectiveness evidence. Cited policy: HRSP. Cited implementation: MDR, DR, RRS, AI, UAI.. Other-book files stay on acquire pages. This chapter does not invent their content.

A.6.4 Disciplinary process

Quantitative

Qualitative

This pack cites no companion artefacts on this identity. Nonconformities recorded: A.6.4 Disciplinary process has no policy and no implementation evidence in this pack.. Other-book files stay on acquire pages. This chapter does not invent their content.

A.6.5 Responsibilities after termination or change of employment

Quantitative

Qualitative

Cited artefacts in this pack: HRSP, MDR, DR, RRS, AI, UAI. Nonconformities recorded: A.6.5 Responsibilities after termination or change of employment is named in this pack, but there is no effectiveness evidence. Cited policy: HRSP. Cited implementation: MDR, DR, RRS, AI, UAI.. Other-book files stay on acquire pages. This chapter does not invent their content.

A.6.6 Confidentiality or non-disclosure agreements

Quantitative

Qualitative

This pack cites no companion artefacts on this identity. Nonconformities recorded: A.6.6 Confidentiality or non-disclosure agreements has no policy and no implementation evidence in this pack.. Other-book files stay on acquire pages. This chapter does not invent their content.

A.6.7 Remote working

Quantitative

Qualitative

This pack cites no companion artefacts on this identity. Nonconformities recorded: A.6.7 Remote working has no policy and no implementation evidence in this pack.. Other-book files stay on acquire pages. This chapter does not invent their content.

A.6.8 Information security event reporting

Quantitative

Qualitative

This pack cites no companion artefacts on this identity. Nonconformities recorded: A.6.8 Information security event reporting has no policy and no implementation evidence in this pack.. Other-book files stay on acquire pages. This chapter does not invent their content.

Tags in this report

Volume

Vol. 1Vol. 2Vol. 3

Presence

installednot installed

Kind

policyevidenceassetprocess

Check installation

What is installed here. Extra volumes are optional and do not change Ready. Update re-runs the check.

CheckResult
Webserver…
Python…
Volumes…
Scripts…
Ready…
Working directory…
Last update…