Arcfield A.6 · People audit
Source: Arcfield EN Companion · Volume 1 audit + OSCAL assessment plan (AP) / assessment results (AR) · oscal/assessment-plan.md, oscal/assessment-results.md · HITL: oscal-guide.md · SIMULATION
How this report is elaborated
Scope is the Volume 1 A.6 · People audit. Identities are the applicable ISO clauses or Annex A controls in this prefix. Process topics remain the operational evidence (hr).
The process we followed is ISO 27001 → Policies → Processes and Systems → Protected Assets → Objects needed by the process → Evidences. Standard vs policy examines whether a policy covers the cited clause or control. Policy vs evidence tests the join from policy rule to recorded evidence.
How to read this report
Start with Results at a glance, then how this category is set up. Glance is Conformity (share without an NC) plus Defined / Implemented / Effectiveness. An NC is recorded when there is no policy and no implementation evidence (Requirement ↔ evidence), when a measure is implemented without effectiveness evidence (Requirement ↔ evidence), or when the kernel join FAILs (Policy ↔ evidence, default minor). Standard vs policy stays HITL. Presence is not Defined = yes as a coverage PASS. UNKNOWN is not an NC.
Results at a glance
Conformity is the share of applicable identities without an NC. Companion Contract/Example unchanged. This is not a certification statement.
How A.6 · People is set up
Upper row is documented information. Lower row is operating evidence. Green is installed here. Dashed is named, not packed. The subject is the clause or control.
Documented evidence in this pack. Not a certification PASS.
Documented evidence in this pack. Not a certification PASS.
Named implemented evidence. Not in this pack.
Implemented evidence in this pack. Not a certification PASS.
Named implemented evidence. Not in this pack.
Implemented evidence in this pack. Not a certification PASS.
Named implemented evidence. Not in this pack.
Implemented evidence in this pack. Not a certification PASS.
Implemented evidence in this pack. Not a certification PASS.
Implemented evidence in this pack. Not a certification PASS.
Implemented evidence in this pack. Not a certification PASS.
Topic reports remain the process evidence: hr.
Nonconformities
Nonconformities this pack can show. Kernel FAIL is Policy ↔ evidence, default minor — not an automatic major. No policy and no implementation, or implementation without effectiveness evidence, is Requirement ↔ evidence. UNKNOWN is not an NC. Assessment Results stay the kernel SSOT. How to fix is the follow-up, not a customer ticket.
| Requirement | Statement | Grade | Path | Detail |
|---|---|---|---|---|
| A.6.1 Screening | A.6.1 Screening is named in this pack, but there is no effectiveness evidence. Cited policy: HRSP. Cited implementation: MDR, DR, RRS, AI, UAI. | minor | Requirement ↔ evidence | NC-A6-missing-evidence |
| A.6.2 Terms and conditions of employment | A.6.2 Terms and conditions of employment is named in this pack, but there is no effectiveness evidence. Cited policy: HRSP. Cited implementation: MDR, DR, RRS, AI, UAI. | minor | Requirement ↔ evidence | NC-A6-missing-evidence |
| A.6.3 Information security awareness, education and training | A.6.3 Information security awareness, education and training is named in this pack, but there is no effectiveness evidence. Cited policy: HRSP. Cited implementation: MDR, DR, RRS, AI, UAI. | minor | Requirement ↔ evidence | NC-A6-missing-evidence |
| A.6.4 Disciplinary process | A.6.4 Disciplinary process has no policy and no implementation evidence in this pack. | minor | Requirement ↔ evidence | NC-A6-not-implemented |
| A.6.5 Responsibilities after termination or change of employment | A.6.5 Responsibilities after termination or change of employment is named in this pack, but there is no effectiveness evidence. Cited policy: HRSP. Cited implementation: MDR, DR, RRS, AI, UAI. | minor | Requirement ↔ evidence | NC-A6-missing-evidence |
| A.6.6 Confidentiality or non-disclosure agreements | A.6.6 Confidentiality or non-disclosure agreements has no policy and no implementation evidence in this pack. | minor | Requirement ↔ evidence | NC-A6-not-implemented |
| A.6.7 Remote working | A.6.7 Remote working has no policy and no implementation evidence in this pack. | minor | Requirement ↔ evidence | NC-A6-not-implemented |
| A.6.8 Information security event reporting | A.6.8 Information security event reporting has no policy and no implementation evidence in this pack. | minor | Requirement ↔ evidence | NC-A6-not-implemented |
ISO 27001 norms and controls
Cited clauses and Annex A controls for this category. Defined is a cited policy (HOW). Standard vs policy stays HITL: Defined = yes does not score that the text covers the control. Implemented is in-pack or named operating evidence. Effective is the kernel join or HITL effectiveness. No policy and no implementation is an NC. Implementation without effectiveness evidence is an NC. Ratings are yes, no, or partially. DK or NA when this pack has no data.
| Index | Name | Kind | Defined | Implemented | Effective |
|---|---|---|---|---|---|
| A.6.1 | Screening | control | yes | yes | no |
| A.6.2 | Terms and conditions of employment | control | yes | yes | no |
| A.6.3 | Information security awareness, education and training | control | yes | yes | no |
| A.6.4 | Disciplinary process | control | no | no | DK |
| A.6.5 | Responsibilities after termination or change of employment | control | yes | yes | no |
| A.6.6 | Confidentiality or non-disclosure agreements | control | no | no | DK |
| A.6.7 | Remote working | control | no | no | DK |
| A.6.8 | Information security event reporting | control | no | no | DK |
What we found
What this pack actually cited for this clause or control identity. Counts are from this pack. Presence is not a PASS. No ISO shall-text.
A.6.1 Screening
Quantitative
- Defined / Implemented / Effective = yes: 2/3 (DK/NA not counted as yes).
- Nonconformities (major/minor) on this identity: 1.
- Cited artefact IDs: 6.
Qualitative
Cited artefacts in this pack: HRSP, MDR, DR, RRS, AI, UAI. Nonconformities recorded: A.6.1 Screening is named in this pack, but there is no effectiveness evidence. Cited policy: HRSP. Cited implementation: MDR, DR, RRS, AI, UAI.. Other-book files stay on acquire pages. This chapter does not invent their content.
A.6.2 Terms and conditions of employment
Quantitative
- Defined / Implemented / Effective = yes: 2/3 (DK/NA not counted as yes).
- Nonconformities (major/minor) on this identity: 1.
- Cited artefact IDs: 6.
Qualitative
Cited artefacts in this pack: HRSP, MDR, DR, RRS, AI, UAI. Nonconformities recorded: A.6.2 Terms and conditions of employment is named in this pack, but there is no effectiveness evidence. Cited policy: HRSP. Cited implementation: MDR, DR, RRS, AI, UAI.. Other-book files stay on acquire pages. This chapter does not invent their content.
A.6.3 Information security awareness, education and training
Quantitative
- Defined / Implemented / Effective = yes: 2/3 (DK/NA not counted as yes).
- Nonconformities (major/minor) on this identity: 1.
- Cited artefact IDs: 6.
Qualitative
Cited artefacts in this pack: HRSP, MDR, DR, RRS, AI, UAI. Nonconformities recorded: A.6.3 Information security awareness, education and training is named in this pack, but there is no effectiveness evidence. Cited policy: HRSP. Cited implementation: MDR, DR, RRS, AI, UAI.. Other-book files stay on acquire pages. This chapter does not invent their content.
A.6.4 Disciplinary process
Quantitative
- Defined / Implemented / Effective = yes: 0/3 (DK/NA not counted as yes).
- Nonconformities (major/minor) on this identity: 1.
- Cited artefact IDs: 0.
Qualitative
This pack cites no companion artefacts on this identity. Nonconformities recorded: A.6.4 Disciplinary process has no policy and no implementation evidence in this pack.. Other-book files stay on acquire pages. This chapter does not invent their content.
A.6.5 Responsibilities after termination or change of employment
Quantitative
- Defined / Implemented / Effective = yes: 2/3 (DK/NA not counted as yes).
- Nonconformities (major/minor) on this identity: 1.
- Cited artefact IDs: 6.
Qualitative
Cited artefacts in this pack: HRSP, MDR, DR, RRS, AI, UAI. Nonconformities recorded: A.6.5 Responsibilities after termination or change of employment is named in this pack, but there is no effectiveness evidence. Cited policy: HRSP. Cited implementation: MDR, DR, RRS, AI, UAI.. Other-book files stay on acquire pages. This chapter does not invent their content.
A.6.6 Confidentiality or non-disclosure agreements
Quantitative
- Defined / Implemented / Effective = yes: 0/3 (DK/NA not counted as yes).
- Nonconformities (major/minor) on this identity: 1.
- Cited artefact IDs: 0.
Qualitative
This pack cites no companion artefacts on this identity. Nonconformities recorded: A.6.6 Confidentiality or non-disclosure agreements has no policy and no implementation evidence in this pack.. Other-book files stay on acquire pages. This chapter does not invent their content.
A.6.7 Remote working
Quantitative
- Defined / Implemented / Effective = yes: 0/3 (DK/NA not counted as yes).
- Nonconformities (major/minor) on this identity: 1.
- Cited artefact IDs: 0.
Qualitative
This pack cites no companion artefacts on this identity. Nonconformities recorded: A.6.7 Remote working has no policy and no implementation evidence in this pack.. Other-book files stay on acquire pages. This chapter does not invent their content.
A.6.8 Information security event reporting
Quantitative
- Defined / Implemented / Effective = yes: 0/3 (DK/NA not counted as yes).
- Nonconformities (major/minor) on this identity: 1.
- Cited artefact IDs: 0.
Qualitative
This pack cites no companion artefacts on this identity. Nonconformities recorded: A.6.8 Information security event reporting has no policy and no implementation evidence in this pack.. Other-book files stay on acquire pages. This chapter does not invent their content.
