ExportableProof — Routines today. Proof tomorrow.

Arcfield Assets / Architecture audit

Source: Arcfield EN Companion · Volume 1 audit + OSCAL assessment plan (AP) / assessment results (AR) · oscal/assessment-plan.md, oscal/assessment-results.md · HITL: oscal-guide.md · SIMULATION

How this report is elaborated

Scope is the Volume 1 Assets / Architecture audit. Artefacts installed in this volume are in-pack; neighbours named from other volumes stay in those books (Vol. 1, Vol. 3, Vol. 2, Vol. 4).

The process we followed is ISO 27001 → Policies → Processes and Systems → Protected Assets → Objects needed by the process → Evidences. Standard vs policy examines whether a policy covers the cited clause or control. Policy vs evidence tests the join from policy rule to recorded evidence.

How to read this report

Start with Results at a glance, then how this category is set up. Standard vs policy is EXAMINE and stays not scored. Nonconformities are kernel FAIL (Policy ↔ evidence, default minor) and Requirement ↔ evidence: no policy and no implementation, or implementation without effectiveness evidence. UNKNOWN is not an NC. Glance counts Conformity, Defined, Implemented, and Effectiveness — not PASS/FAIL compliance. Not scored on an inventory row means the subject is not in this topic's kernel join. It is not a Statement of Applicability exclusion.

Results at a glance

40 %Conformity3/5 NC. Share without an NC. DK/NA are out of the denominator. Not a certification statement.
100 %Defined2/2 yes. Defined = yes / rated artefacts or identities. partially is not yes.
100 %Implemented3/3 yes. Implemented = yes / rated artefacts or identities. partially is not yes.
0 %Effectiveness0/2 yes. Effective = yes / rated artefacts or identities. partially is not yes.

Companion Contract/Example unchanged. This audit does not invent a certification statement.

How assets are set up

One graph. Green boxes are installed in this volume. Dashed edges: HITL. SAS includesInstance to AI is cited, not scored here. SI-001 CloudDesk stays an SI name, not AST-014. AMP and IAS are Volume 1 — named, not packed, not joined. ARR asset-FK stays the access audit.

AMP — Asset Management Policy
Vol. 1installedpolicycomparison aPremium

Cited HOW policy. Needle ASSET-POL-001. You EXAMINE whether it covers A.5.9–A.5.13. This audit does not score coverage. Not joined to IAS or AI.

Artefact

IAS — Information Asset Standard
Vol. 1installedprocesshitlPremium

Cited HOW standard. Needle INFO-ASSET-STD-001. You EXAMINE whether it is operated. Not joined to AMP or AI.

Artefact

ICP — Information Classification Policy
Vol. 1Vol. 3installedpolicyhitlPremium

Cited HOW policy. You EXAMINE whether it covers A.5.12 and A.5.13. Classification levels stay citations, not a labelling score. Not joined to AMP.

Artefact

AI — Asset Inventory
Vol. 1Vol. 2Vol. 3installedassetinventoryBasic

In-pack inventory. AST-001 stays a citation, not a CMDB score. Not joined to AOAVC. ARR asset-FK stays the access audit.

Artefact

SAS — System Architecture Statement
Vol. 1Vol. 3Vol. 4installedsystemhitlPremium

In-pack system statement. Needle SYS-ARCH-STATEMENT-001. includesInstance points at AI. Architecture boxes that are not Asset names stay unresolved. Not an ARR join.

Artefact

AOAVC — Asset Owner Asset Validation Checklist
Vol. 2Vol. 3not installedprocessother-bookPremium

Volume 2–3 owner checklist. Named, not packed, not joined in this volume. Not a process-component.

Artefact

SI — Software Inventory
Vol. 3Vol. 4not installedsystemother-bookPremium

Volume 3/4 software inventory. Named, not packed, not joined in this volume.

Artefact

Nonconformities

Nonconformities this pack can show. Kernel FAIL is Policy ↔ evidence, default minor — not an automatic major. No policy and no implementation, or implementation without effectiveness evidence, is Requirement ↔ evidence. UNKNOWN is not an NC. Assessment Results stay the kernel SSOT. How to fix is the follow-up, not a customer ticket.

RequirementStatementGradePathDetail
7.5 Documented information7.5 Documented information has no policy and no implementation evidence in this pack.minorRequirement ↔ evidenceNC-ASSETS-not-implemented
A.5.10 Acceptable use of information and other associated assetsA.5.10 Acceptable use of information and other associated assets has no policy and no implementation evidence in this pack.minorRequirement ↔ evidenceNC-ASSETS-not-implemented
A.5.11 Return of assetsA.5.11 Return of assets has no policy and no implementation evidence in this pack.minorRequirement ↔ evidenceNC-ASSETS-not-implemented
A.5.32 Intellectual property rightsA.5.32 Intellectual property rights has no policy and no implementation evidence in this pack.minorRequirement ↔ evidenceNC-ASSETS-not-implemented
A.5.9 Inventory of information and other associated assetsA.5.9 Inventory of information and other associated assets is named in this pack, but there is no effectiveness evidence. Cited policy: AMP. Cited implementation: IAS, AI.minorRequirement ↔ evidenceNC-ASSETS-missing-evidence
A.8.8 Management of technical vulnerabilitiesA.8.8 Management of technical vulnerabilities has no policy and no implementation evidence in this pack.minorRequirement ↔ evidenceNC-ASSETS-not-implemented

Operational Evaluation

Artefacts in this category. Defined is a cited policy (HOW). Implemented is in-pack or named operating evidence. Effective is the kernel join or HITL effectiveness. Ratings are yes, no, or partially. DK or NA when this pack has no data.

ArtifactDefinedImplementedEffectiveArtefact
AMPyesNADKArtefact
IASNAyesnoArtefact
ICPyesNADKArtefact
AINAyesnoArtefact
SASNAyesDKArtefact

What we found

What this pack actually cited for each artefact. Counts are from this pack. Presence is not a PASS. No ISO shall-text.

AMP

AMP is in-pack in Volume 1. Defined yes, implemented NA, effective DK. A nonconformity cites this artefact. Missing layers are explained on the artefact page — not joined from another book.

IAS

IAS is in-pack in Volume 1. Defined NA, implemented yes, effective no. A nonconformity cites this artefact. Missing layers are explained on the artefact page — not joined from another book.

ICP

ICP is in-pack in Volume 1. Defined yes, implemented NA, effective DK. Missing layers are explained on the artefact page — not joined from another book.

AI

AI is in-pack in Volume 1. Defined NA, implemented yes, effective no. A nonconformity cites this artefact. Missing layers are explained on the artefact page — not joined from another book.

SAS

SAS is in-pack in Volume 1. Defined NA, implemented yes, effective DK. Missing layers are explained on the artefact page — not joined from another book.

Asset inventory

No inventory rows in the examined Example JSON.

Tags in this report

Volume

Vol. 1Vol. 2Vol. 3Vol. 4

Presence

installednot installed

Kind

policycomparison aprocesshitlassetinventorysystemother-book

Tier

PremiumBasic

Check installation

What is installed here. Extra volumes are optional and do not change Ready. Update re-runs the check.

CheckResult
Webserver…
Python…
Volumes…
Scripts…
Ready…
Working directory…
Last update…