ExportableProof — Routines today. Proof tomorrow.

Arcfield 6 · Planning audit

Source: Arcfield EN Companion · Volume 1 audit + OSCAL assessment plan (AP) / assessment results (AR) · oscal/assessment-plan.md, oscal/assessment-results.md · HITL: oscal-guide.md · SIMULATION

How this report is elaborated

Scope is the Volume 1 6 · Planning audit. Identities are the applicable ISO clauses or Annex A controls in this prefix. Process topics remain the operational evidence (risk, implementation).

The process we followed is ISO 27001 → Policies → Processes and Systems → Protected Assets → Objects needed by the process → Evidences. Standard vs policy examines whether a policy covers the cited clause or control. Policy vs evidence tests the join from policy rule to recorded evidence.

How to read this report

Start with Results at a glance, then how this category is set up. Glance is Conformity (share without an NC) plus Defined / Implemented / Effectiveness. An NC is recorded when there is no policy and no implementation evidence (Requirement ↔ evidence), when a measure is implemented without effectiveness evidence (Requirement ↔ evidence), or when the kernel join FAILs (Policy ↔ evidence, default minor). Standard vs policy stays HITL. Presence is not Defined = yes as a coverage PASS. UNKNOWN is not an NC.

Results at a glance

17 %Conformity5/6 NC. Share without an NC. DK/NA are out of the denominator. Not a certification statement.
67 %Defined4/6 yes. Defined = yes / rated artefacts or identities. partially is not yes.
83 %Implemented5/6 yes. Implemented = yes / rated artefacts or identities. partially is not yes.
0 %Effectiveness0/5 yes. Effective = yes / rated artefacts or identities. partially is not yes.

Conformity is the share of applicable identities without an NC. Companion Contract/Example unchanged. This is not a certification statement.

How 6 · Planning is set up

Risk Analysis Statement according to Magerit and ISO 27005
Vol. 1Vol. 2installeddocumentedPremium

Documented evidence in this pack. Not a certification PASS.

Artefact

Risk Register
Vol. 1Vol. 2installedimplementedBasic

Implemented evidence in this pack. Not a certification PASS.

Artefact

Risk Treatment Plan
Vol. 1Vol. 2installedimplementedBasic

Implemented evidence in this pack. Not a certification PASS.

Artefact

Continual Improvement Log
Vol. 2not installedimplementedPremium

Named implemented evidence. Not in this pack.

Artefact

Mandatory Documents and Records Register
Vol. 2not installedimplementedBasic

Named implemented evidence. Not in this pack.

Artefact

Document Register
Vol. 1Vol. 2installedimplementedPremium

Implemented evidence in this pack. Not a certification PASS.

Artefact

Records Retention Schedule
Vol. 2not installedimplementedPremium

Named implemented evidence. Not in this pack.

Artefact

Asset Inventory
Vol. 1Vol. 2Vol. 3installedimplementedBasic

Implemented evidence in this pack. Not a certification PASS.

Artefact

Users and Access Inventory
Vol. 2Vol. 3not installedimplementedPremium

Named implemented evidence. Not in this pack.

Artefact

Operational ISMS Dashboard
Vol. 1Vol. 2Vol. 3Vol. 4Vol. 5installedimplementedBasic

Implemented evidence in this pack. Not a certification PASS.

Artefact

ISMS Change Log
Vol. 2not installedimplementedPremium

Named implemented evidence. Not in this pack.

Artefact

Risk Assessment Methodology
Vol. 1installedimplementedBasic

Implemented evidence in this pack. Not a certification PASS.

Artefact

Risk Management Plan
Vol. 1installedimplementedPremium

Implemented evidence in this pack. Not a certification PASS.

Artefact

Risk Acceptance Minutes Template
Vol. 1installedimplementedPremium

Implemented evidence in this pack. Not a certification PASS.

Artefact

Executive Risk Report
Vol. 1Vol. 5installedimplementedPremium

Implemented evidence in this pack. Not a certification PASS.

Artefact

Topic reports remain the process evidence: risk, implementation.

Nonconformities

Nonconformities this pack can show. Kernel FAIL is Policy ↔ evidence, default minor — not an automatic major. No policy and no implementation, or implementation without effectiveness evidence, is Requirement ↔ evidence. UNKNOWN is not an NC. Assessment Results stay the kernel SSOT. How to fix is the follow-up, not a customer ticket.

RequirementStatementGradePathDetail
6.1.1 Actions to address risks and opportunities6.1.1 Actions to address risks and opportunities is named in this pack, but there is no effectiveness evidence. Cited policy: RASM. Cited implementation: RR, RTP, CIL, MDR, DR, RRS, AI, UAI.minorRequirement ↔ evidenceNC-C6-missing-evidence
6.1.2 Information security risk assessment6.1.2 Information security risk assessment is named in this pack, but there is no effectiveness evidence. Cited policy: RASM. Cited implementation: RR, MDR, DR, RRS, AI, UAI.minorRequirement ↔ evidenceNC-C6-missing-evidence
6.1.3 Information security risk treatment6.1.3 Information security risk treatment is named in this pack, but there is no effectiveness evidence. Cited policy: RASM. Cited implementation: RTP, MDR, DR, RRS, AI, UAI.minorRequirement ↔ evidenceNC-C6-missing-evidence
6.2 Information security objectives and planning to achieve them6.2 Information security objectives and planning to achieve them is named in this pack, but there is no effectiveness evidence. Cited implementation: IMPL-WB.minorRequirement ↔ evidenceNC-C6-missing-evidence
6.3 Planning of changes6.3 Planning of changes is named in this pack, but there is no effectiveness evidence. Cited implementation: ISMS-CL.minorRequirement ↔ evidenceNC-C6-missing-evidence

ISO 27001 norms and controls

Cited clauses and Annex A controls for this category. Defined is a cited policy (HOW). Standard vs policy stays HITL: Defined = yes does not score that the text covers the control. Implemented is in-pack or named operating evidence. Effective is the kernel join or HITL effectiveness. No policy and no implementation is an NC. Implementation without effectiveness evidence is an NC. Ratings are yes, no, or partially. DK or NA when this pack has no data.

IndexNameKindDefinedImplementedEffective
6.1Actions to address risks and opportunitiesclauseyesnoDK
6.1.1Actions to address risks and opportunitiesclauseyesyesno
6.1.2Information security risk assessmentclauseyesyesno
6.1.3Information security risk treatmentclauseyesyesno
6.2Information security objectives and planning to achieve themclausenoyesno
6.3Planning of changesclausenoyesno

What we found

What this pack actually cited for this clause or control identity. Counts are from this pack. Presence is not a PASS. No ISO shall-text.

6.1 Actions to address risks and opportunities

Quantitative

Qualitative

Cited artefacts in this pack: RASM. No nonconformity is recorded for this identity in this pack. Other-book files stay on acquire pages. This chapter does not invent their content.

6.1.1 Actions to address risks and opportunities

Quantitative

Qualitative

Cited artefacts in this pack: RASM, RR, RTP, CIL, MDR, DR, RRS, AI, UAI. Nonconformities recorded: 6.1.1 Actions to address risks and opportunities is named in this pack, but there is no effectiveness evidence. Cited policy: RASM. Cited implementation: RR, RTP, CIL, MDR, DR, RRS, AI, UAI.. Other-book files stay on acquire pages. This chapter does not invent their content.

6.1.2 Information security risk assessment

Quantitative

Qualitative

Cited artefacts in this pack: RASM, RR, MDR, DR, RRS, AI, UAI. Nonconformities recorded: 6.1.2 Information security risk assessment is named in this pack, but there is no effectiveness evidence. Cited policy: RASM. Cited implementation: RR, MDR, DR, RRS, AI, UAI.. Other-book files stay on acquire pages. This chapter does not invent their content.

6.1.3 Information security risk treatment

Quantitative

Qualitative

Cited artefacts in this pack: RASM, RTP, MDR, DR, RRS, AI, UAI. Nonconformities recorded: 6.1.3 Information security risk treatment is named in this pack, but there is no effectiveness evidence. Cited policy: RASM. Cited implementation: RTP, MDR, DR, RRS, AI, UAI.. Other-book files stay on acquire pages. This chapter does not invent their content.

6.2 Information security objectives and planning to achieve them

Quantitative

Qualitative

Cited artefacts in this pack: IMPL-WB. Nonconformities recorded: 6.2 Information security objectives and planning to achieve them is named in this pack, but there is no effectiveness evidence. Cited implementation: IMPL-WB.. Other-book files stay on acquire pages. This chapter does not invent their content.

6.3 Planning of changes

Quantitative

Qualitative

Cited artefacts in this pack: ISMS-CL. Nonconformities recorded: 6.3 Planning of changes is named in this pack, but there is no effectiveness evidence. Cited implementation: ISMS-CL.. Other-book files stay on acquire pages. This chapter does not invent their content.

Tags in this report

Volume

Vol. 1Vol. 2Vol. 3Vol. 4Vol. 5

Presence

installednot installed

Kind

policyriskpoamevidenceassetdependencyprocess

Check installation

What is installed here. Extra volumes are optional and do not change Ready. Update re-runs the check.

CheckResult
Webserver…
Python…
Volumes…
Scripts…
Ready…
Working directory…
Last update…