Arcfield ISMS foundation audit
Source: Arcfield EN Companion · Volume 1 audit + OSCAL assessment plan (AP) / assessment results (AR) · oscal/assessment-plan.md, oscal/assessment-results.md · HITL: oscal-guide.md · SIMULATION
How this report is elaborated
Scope is the Volume 1 ISMS foundation audit. Artefacts installed in this volume are in-pack; neighbours named from other volumes stay in those books (Vol. 1, Vol. 2).
The process we followed is ISO 27001 → Policies → Processes and Systems → Protected Assets → Objects needed by the process → Evidences. Standard vs policy examines whether a policy covers the cited clause or control. Policy vs evidence tests the join from policy rule to recorded evidence.
How to read this report
Start with Results at a glance, then how this category is set up. Standard vs policy is EXAMINE and stays not scored. Nonconformities are kernel FAIL (Policy ↔ evidence, default minor) and Requirement ↔ evidence: no policy and no implementation, or implementation without effectiveness evidence. UNKNOWN is not an NC. Glance counts Conformity, Defined, Implemented, and Effectiveness — not PASS/FAIL compliance. Not scored on an inventory row means the subject is not in this topic's kernel join. It is not a Statement of Applicability exclusion.
Results at a glance
Companion Contract/Example unchanged. This audit does not invent a certification statement.
How ISMS foundation is set up
One graph. Green boxes are installed in this volume. Dashed edges: HITL. COMM-P is not joined to LRR. MRART is not joined to MRMT. ICVC is not joined to SOA. WIR-S1 is not joined to ISOCTRL. ISP, ISS and OS stay Volume 1. Not a communication-count or review-day score.
Cited HOW policy. Needle POL-SEC-001. You EXAMINE whether it covers 5.1 and 5.2. This audit does not score coverage. Not joined to ISS, OS or PAP.
Cited HOW scope. Needle ISMS-SCOPE-001. You EXAMINE whether the ISMS boundary is operated. Not joined to ISP or OS.
Cited HOW statement. Needle ORG-STATEMENT-001. You EXAMINE whether roles are operated. Not joined to ISP or ISS.
Cited HOW checklist. You EXAMINE ICVC-CHK-001. ICVC-DEC-2026-Q3, ICVC-GAP-001 and ICVC-EX-001 stay citations. Check IDs in the journal stay citations, not an AOAVC join. Not a process-component. Not joined to SOA.
Cited HOW agenda. You EXAMINE MGT-REV-AGENDA-001. Clause 9.3 stays with you. Not a process-component. Not joined to MRMT.
In-pack minutes. Needle MGT-REV-MIN-001. Meeting date 2026-08-29 stays a citation, not a review-day score. Not joined to MRART or IAP.
Volume 2 communication plan. Named, not packed, not joined in this volume.
Volume 2 legal register. Named, not packed, not joined in this volume.
Volume 2 work-instruction record. Named, not packed, not joined in this volume. Not a process-component.
Nonconformities
Nonconformities this pack can show. Kernel FAIL is Policy ↔ evidence, default minor — not an automatic major. No policy and no implementation, or implementation without effectiveness evidence, is Requirement ↔ evidence. UNKNOWN is not an NC. Assessment Results stay the kernel SSOT. How to fix is the follow-up, not a customer ticket.
| Requirement | Statement | Grade | Path | Detail |
|---|---|---|---|---|
| 4.2 Understanding the needs and expectations of interested parties | 4.2 Understanding the needs and expectations of interested parties has no policy and no implementation evidence in this pack. | minor | Requirement ↔ evidence | NC-FOUNDATION-not-implemented |
| 5.1 Leadership and commitment | 5.1 Leadership and commitment has no policy and no implementation evidence in this pack. | minor | Requirement ↔ evidence | NC-FOUNDATION-not-implemented |
| 5.2 Information security policy | 5.2 Information security policy has no policy and no implementation evidence in this pack. | minor | Requirement ↔ evidence | NC-FOUNDATION-not-implemented |
| 7.4 Communication | 7.4 Communication has no policy and no implementation evidence in this pack. | minor | Requirement ↔ evidence | NC-FOUNDATION-not-implemented |
| 7.5 Documented information | 7.5 Documented information is named in this pack, but there is no effectiveness evidence. Cited implementation: ICVC. | minor | Requirement ↔ evidence | NC-FOUNDATION-missing-evidence |
| 9.3 Management review | 9.3 Management review is named in this pack, but there is no effectiveness evidence. Cited implementation: MRART, MRMT. | minor | Requirement ↔ evidence | NC-FOUNDATION-missing-evidence |
Operational Evaluation
Artefacts in this category. Defined is a cited policy (HOW). Implemented is in-pack or named operating evidence. Effective is the kernel join or HITL effectiveness. Ratings are yes, no, or partially. DK or NA when this pack has no data.
| Artifact | Defined | Implemented | Effective | Artefact |
|---|---|---|---|---|
| ISP | yes | NA | DK | Artefact |
| ISS | NA | yes | DK | Artefact |
| OS | yes | NA | DK | Artefact |
| IPR | yes | NA | DK | Artefact |
| IRAR | yes | NA | DK | Artefact |
| RACI | yes | NA | DK | Artefact |
| IGC | NA | yes | DK | Artefact |
| GS | yes | NA | DK | Artefact |
| ISO | NA | yes | DK | Artefact |
| CR | NA | yes | DK | Artefact |
| DAL | NA | yes | DK | Artefact |
| OPC | NA | yes | DK | Artefact |
| RAE | NA | yes | DK | Artefact |
| ICL | NA | yes | DK | Artefact |
| MME | NA | yes | DK | Artefact |
| ICVC | NA | yes | no | Artefact |
| MRART | NA | yes | no | Artefact |
| MRMT | NA | yes | no | Artefact |
What we found
What this pack actually cited for each artefact. Counts are from this pack. Presence is not a PASS. No ISO shall-text.
ISP
- Defined: yes.
- Implemented: NA.
- Effective: DK.
- Nonconformity on this artefact: no.
- Layers present: Office, OSCAL.
ISP is in-pack in Volume 1. Defined yes, implemented NA, effective DK. Missing layers are explained on the artefact page — not joined from another book.
ISS
- Defined: NA.
- Implemented: yes.
- Effective: DK.
- Nonconformity on this artefact: no.
- Layers present: Office, OSCAL.
ISS is in-pack in Volume 1. Defined NA, implemented yes, effective DK. Missing layers are explained on the artefact page — not joined from another book.
OS
- Defined: yes.
- Implemented: NA.
- Effective: DK.
- Nonconformity on this artefact: no.
- Layers present: Office, OSCAL.
OS is in-pack in Volume 1. Defined yes, implemented NA, effective DK. Missing layers are explained on the artefact page — not joined from another book.
IPR
- Defined: yes.
- Implemented: NA.
- Effective: DK.
- Nonconformity on this artefact: no.
- Layers present: Office, OSCAL.
IPR is in-pack in Volume 1. Defined yes, implemented NA, effective DK. Missing layers are explained on the artefact page — not joined from another book.
IRAR
- Defined: yes.
- Implemented: NA.
- Effective: DK.
- Nonconformity on this artefact: no.
- Layers present: Office, OSCAL.
IRAR is in-pack in Volume 1. Defined yes, implemented NA, effective DK. Missing layers are explained on the artefact page — not joined from another book.
RACI
- Defined: yes.
- Implemented: NA.
- Effective: DK.
- Nonconformity on this artefact: no.
- Layers present: Office, OSCAL.
RACI is in-pack in Volume 1. Defined yes, implemented NA, effective DK. Missing layers are explained on the artefact page — not joined from another book.
IGC
- Defined: NA.
- Implemented: yes.
- Effective: DK.
- Nonconformity on this artefact: no.
- Layers present: Office, OSCAL.
IGC is in-pack in Volume 1. Defined NA, implemented yes, effective DK. Missing layers are explained on the artefact page — not joined from another book.
GS
- Defined: yes.
- Implemented: NA.
- Effective: DK.
- Nonconformity on this artefact: no.
- Layers present: Office, OSCAL.
GS is in-pack in Volume 1. Defined yes, implemented NA, effective DK. Missing layers are explained on the artefact page — not joined from another book.
ISO
- Defined: NA.
- Implemented: yes.
- Effective: DK.
- Nonconformity on this artefact: no.
- Layers present: Office, OSCAL.
ISO is in-pack in Volume 1. Defined NA, implemented yes, effective DK. Missing layers are explained on the artefact page — not joined from another book.
CR
- Defined: NA.
- Implemented: yes.
- Effective: DK.
- Nonconformity on this artefact: no.
- Layers present: Office, OSCAL.
CR is in-pack in Volume 1. Defined NA, implemented yes, effective DK. Missing layers are explained on the artefact page — not joined from another book.
DAL
- Defined: NA.
- Implemented: yes.
- Effective: DK.
- Nonconformity on this artefact: no.
- Layers present: Office, OSCAL.
DAL is in-pack in Volume 1. Defined NA, implemented yes, effective DK. Missing layers are explained on the artefact page — not joined from another book.
OPC
- Defined: NA.
- Implemented: yes.
- Effective: DK.
- Nonconformity on this artefact: no.
- Layers present: Office, OSCAL.
OPC is in-pack in Volume 1. Defined NA, implemented yes, effective DK. Missing layers are explained on the artefact page — not joined from another book.
RAE
- Defined: NA.
- Implemented: yes.
- Effective: DK.
- Nonconformity on this artefact: no.
- Layers present: Office, OSCAL.
RAE is in-pack in Volume 1. Defined NA, implemented yes, effective DK. Missing layers are explained on the artefact page — not joined from another book.
ICL
- Defined: NA.
- Implemented: yes.
- Effective: DK.
- Nonconformity on this artefact: no.
- Layers present: Office, OSCAL.
ICL is in-pack in Volume 1. Defined NA, implemented yes, effective DK. Missing layers are explained on the artefact page — not joined from another book.
MME
- Defined: NA.
- Implemented: yes.
- Effective: DK.
- Nonconformity on this artefact: no.
- Layers present: Office, OSCAL.
MME is in-pack in Volume 1. Defined NA, implemented yes, effective DK. Missing layers are explained on the artefact page — not joined from another book.
ICVC
- Defined: NA.
- Implemented: yes.
- Effective: no.
- Nonconformity on this artefact: yes.
- Layers present: Office, OSCAL.
ICVC is in-pack in Volume 1. Defined NA, implemented yes, effective no. A nonconformity cites this artefact. Missing layers are explained on the artefact page — not joined from another book.
MRART
- Defined: NA.
- Implemented: yes.
- Effective: no.
- Nonconformity on this artefact: yes.
- Layers present: Office, OSCAL.
MRART is in-pack in Volume 1. Defined NA, implemented yes, effective no. A nonconformity cites this artefact. Missing layers are explained on the artefact page — not joined from another book.
MRMT
- Defined: NA.
- Implemented: yes.
- Effective: no.
- Nonconformity on this artefact: yes.
- Layers present: Office, OSCAL.
MRMT is in-pack in Volume 1. Defined NA, implemented yes, effective no. A nonconformity cites this artefact. Missing layers are explained on the artefact page — not joined from another book.
Foundation inventory
No inventory rows in the examined Example JSON.
