ExportableProof — Routines today. Proof tomorrow.

Arcfield Documented information audit

Source: Arcfield EN Companion · Volume 1 audit + OSCAL assessment plan (AP) / assessment results (AR) · oscal/assessment-plan.md, oscal/assessment-results.md · HITL: oscal-guide.md · SIMULATION

How this report is elaborated

Scope is the Volume 1 Documented information audit. Artefacts installed in this volume are in-pack; neighbours named from other volumes stay in those books (Vol. 1, Vol. 2).

The process we followed is ISO 27001 → Policies → Processes and Systems → Protected Assets → Objects needed by the process → Evidences. Standard vs policy examines whether a policy covers the cited clause or control. Policy vs evidence tests the join from policy rule to recorded evidence.

How to read this report

Start with Results at a glance, then how this category is set up. Standard vs policy is EXAMINE and stays not scored. Nonconformities are kernel FAIL (Policy ↔ evidence, default minor) and Requirement ↔ evidence: no policy and no implementation, or implementation without effectiveness evidence. UNKNOWN is not an NC. Glance counts Conformity, Defined, Implemented, and Effectiveness — not PASS/FAIL compliance. Not scored on an inventory row means the subject is not in this topic's kernel join. It is not a Statement of Applicability exclusion.

Results at a glance

0 %Conformity2/2 NC. Share without an NC. DK/NA are out of the denominator. Not a certification statement.
100 %Defined1/1 yes. Defined = yes / rated artefacts or identities. partially is not yes.
100 %Implemented1/1 yes. Implemented = yes / rated artefacts or identities. partially is not yes.
0 %Effectiveness0/1 yes. Effective = yes / rated artefacts or identities. partially is not yes.

Companion Contract/Example unchanged. This audit does not invent a certification statement.

How documented information is set up

One graph. Green boxes are installed in this volume. Dashed edges: HITL. DR is not joined to PARR or DCP. Not a document-count, policy-count, or review-day score.

DR — Document Register
Vol. 1Vol. 2installedevidenceinventoryPremium

In-pack register. Needle DR-REG-001 / DR-001. DR-006 Retired stays a citation, not a document-count score. Not joined to DCP, OPI or PARR.

Artefact

PARR — Policy Approval and Review Register
Vol. 1installedevidencehitlBasic

In-pack register. Needle PARR-REG-001 / PARR-001. You EXAMINE whether approvals are operated. Not a policy-count or review-day score. Not joined to DR or DCP.

Artefact

DCP — Document Control Procedure
Vol. 2not installedprocessother-bookPremium

Volume 2 document-control procedure. Named, not packed, not joined in this volume.

Artefact

DOP — Documented Operating Procedure Template
Vol. 2not installedprocessother-bookPremium

Volume 2 operating-procedure template. Named, not packed, not joined in this volume.

Artefact

MDR — Mandatory Documents and Records Register
Vol. 2not installedevidenceother-bookBasic

Volume 2 mandatory-documents register. Named, not packed, not joined in this volume.

Artefact

RRS — Records Retention Schedule
Vol. 2not installedprocessother-bookPremium

Volume 2 records-retention schedule. Named, not packed, not joined in this volume.

Artefact

OPI — Operational Procedures Index
Vol. 4not installeddependencyother-bookBasic

Volume 4 operational-procedures index. Named, not packed, not joined in this volume.

Artefact

Nonconformities

Nonconformities this pack can show. Kernel FAIL is Policy ↔ evidence, default minor — not an automatic major. No policy and no implementation, or implementation without effectiveness evidence, is Requirement ↔ evidence. UNKNOWN is not an NC. Assessment Results stay the kernel SSOT. How to fix is the follow-up, not a customer ticket.

RequirementStatementGradePathDetail
7.5 Documented information7.5 Documented information is named in this pack, but there is no effectiveness evidence. Cited policy: PARR. Cited implementation: DR.minorRequirement ↔ evidenceNC-DOCUMENTED-missing-evidence

Operational Evaluation

Artefacts in this category. Defined is a cited policy (HOW). Implemented is in-pack or named operating evidence. Effective is the kernel join or HITL effectiveness. Ratings are yes, no, or partially. DK or NA when this pack has no data.

ArtifactDefinedImplementedEffectiveArtefact
DRNAyesnoArtefact
PARRyesNADKArtefact

What we found

What this pack actually cited for each artefact. Counts are from this pack. Presence is not a PASS. No ISO shall-text.

DR

DR is in-pack in Volume 1. Defined NA, implemented yes, effective no. A nonconformity cites this artefact. Missing layers are explained on the artefact page — not joined from another book.

PARR

PARR is in-pack in Volume 1. Defined yes, implemented NA, effective DK. A nonconformity cites this artefact. Missing layers are explained on the artefact page — not joined from another book.

Document inventory

No inventory rows in the examined Example JSON.

Tags in this report

Volume

Vol. 1Vol. 2Vol. 4

Presence

installednot installed

Kind

evidenceinventoryhitlprocessother-bookdependency

Tier

BasicPremium

Check installation

What is installed here. Extra volumes are optional and do not change Ready. Update re-runs the check.

CheckResult
Webserver…
Python…
Volumes…
Scripts…
Ready…
Working directory…
Last update…