ExportableProof — Routines today. Proof tomorrow.

Arcfield Certification audit

Source: Arcfield EN Companion · Volume 1 audit + OSCAL assessment plan (AP) / assessment results (AR) · oscal/assessment-plan.md, oscal/assessment-results.md · HITL: oscal-guide.md · SIMULATION

How this report is elaborated

Scope is the Volume 1 Certification audit. Artefacts installed in this volume are in-pack; neighbours named from other volumes stay in those books (Vol. 1, Vol. 2).

The process we followed is ISO 27001 → Policies → Processes and Systems → Protected Assets → Objects needed by the process → Evidences. Standard vs policy examines whether a policy covers the cited clause or control. Policy vs evidence tests the join from policy rule to recorded evidence.

How to read this report

Start with Results at a glance, then how this category is set up. Standard vs policy is EXAMINE and stays not scored. Nonconformities are kernel FAIL (Policy ↔ evidence, default minor) and Requirement ↔ evidence: no policy and no implementation, or implementation without effectiveness evidence. UNKNOWN is not an NC. Glance counts Conformity, Defined, Implemented, and Effectiveness — not PASS/FAIL compliance. Not scored on an inventory row means the subject is not in this topic's kernel join. It is not a Statement of Applicability exclusion.

Results at a glance

0 %Conformity2/2 NC. Share without an NC. DK/NA are out of the denominator. Not a certification statement.
—Defined0/0 yes. Defined = yes / rated artefacts or identities. partially is not yes.
100 %Implemented2/2 yes. Implemented = yes / rated artefacts or identities. partially is not yes.
0 %Effectiveness0/2 yes. Effective = yes / rated artefacts or identities. partially is not yes.

Companion Contract/Example unchanged. This audit does not invent a certification statement.

How certification is set up

One graph. Green boxes are installed in this volume. Dashed edges: HITL. IAP is not joined to IAPC. usesTemplate IAPC stays editorial. Stage 1/2 and CERT-* are EXAMINEd here and stay out of the IAP join. Not a kernel score. Not a process-component.

IAP — Internal Audit Plan
Vol. 1Vol. 2installedassessmenthitlBasic

In-pack internal audit plan. Needle AUDIT-PLAN-001. You EXAMINE whether it covers 9.2. IAP-EV-2026-Q3 stays a citation. IAP-2026 stays a citation, not a REQT join. usesTemplate IAPC stays editorial. Stage 1/2 and CERT-* stay out of this join. Not a process-component. Not a kernel score.

Artefact

IAPC — Internal Audit Program & Checklist
Vol. 1installedassessmenthitlPremium

In-pack programme and checklist. Needle IAPC-CHK-001. You EXAMINE whether it is operated. IAPC-REPORT-2026-Q3 and IAPC-F-001 stay citations. CAR-ACCESS-2026-001 stays a citation, not a CAR join. usesTemplate IAPC stays editorial. Stage 1/2 stays out of this join. Not a process-component. Not a kernel score.

Artefact

Nonconformities

Nonconformities this pack can show. Kernel FAIL is Policy ↔ evidence, default minor — not an automatic major. No policy and no implementation, or implementation without effectiveness evidence, is Requirement ↔ evidence. UNKNOWN is not an NC. Assessment Results stay the kernel SSOT. How to fix is the follow-up, not a customer ticket.

RequirementStatementGradePathDetail
9.2 Internal audit9.2 Internal audit is named in this pack, but there is no effectiveness evidence. Cited implementation: IAP, IAPC.minorRequirement ↔ evidenceNC-CERTIFICATION-missing-evidence
A.5.35 Independent review of information securityA.5.35 Independent review of information security is named in this pack, but there is no effectiveness evidence. Cited implementation: IAP.minorRequirement ↔ evidenceNC-CERTIFICATION-missing-evidence
A.8.34 Protection of information systems during audit testingA.8.34 Protection of information systems during audit testing is named in this pack, but there is no effectiveness evidence. Cited implementation: IAP.minorRequirement ↔ evidenceNC-CERTIFICATION-missing-evidence

Operational Evaluation

Artefacts in this category. Defined is a cited policy (HOW). Implemented is in-pack or named operating evidence. Effective is the kernel join or HITL effectiveness. Ratings are yes, no, or partially. DK or NA when this pack has no data.

ArtifactDefinedImplementedEffectiveArtefact
IAPNAyesnoArtefact
IAPCNAyesnoArtefact

What we found

What this pack actually cited for each artefact. Counts are from this pack. Presence is not a PASS. No ISO shall-text.

IAP

IAP is in-pack in Volume 1. Defined NA, implemented yes, effective no. A nonconformity cites this artefact. Missing layers are explained on the artefact page — not joined from another book.

IAPC

IAPC is in-pack in Volume 1. Defined NA, implemented yes, effective no. A nonconformity cites this artefact. Missing layers are explained on the artefact page — not joined from another book.

Certification inventory

No inventory rows in the examined Example JSON.

Tags in this report

Volume

Vol. 1Vol. 2

Presence

installed

Kind

assessmenthitl

Tier

BasicPremium

Check installation

What is installed here. Extra volumes are optional and do not change Ready. Update re-runs the check.

CheckResult
Webserver…
Python…
Volumes…
Scripts…
Ready…
Working directory…
Last update…