ExportableProof — Routines today. Proof tomorrow.

Arcfield ISMS foundation audit

Source: Arcfield EN Companion · Volume 1 audit + OSCAL assessment plan (AP) / assessment results (AR) · oscal/assessment-plan.md, oscal/assessment-results.md · HITL: oscal-guide.md · SIMULATION

How this report is elaborated

Scope is the Volume 1 ISMS foundation audit. Artefacts installed in this volume are in-pack; neighbours named from other volumes stay in those books (Vol. 1, Vol. 2).

The process we followed is ISO 27001 → Policies → Processes and Systems → Protected Assets → Objects needed by the process → Evidences. Standard vs policy examines whether a policy covers the cited clause or control. Policy vs evidence tests the join from policy rule to recorded evidence.

How to read this report

Start with Results at a glance, then how this category is set up. Standard vs policy is EXAMINE and stays not scored. Nonconformities are kernel FAIL (Policy ↔ evidence, default minor) and Requirement ↔ evidence: no policy and no implementation, or implementation without effectiveness evidence. UNKNOWN is not an NC. Glance counts Conformity, Defined, Implemented, and Effectiveness — not PASS/FAIL compliance. Not scored on an inventory row means the subject is not in this topic's kernel join. It is not a Statement of Applicability exclusion.

Results at a glance

83 %Conformity3/18 NC. Share without an NC. DK/NA are out of the denominator. Not a certification statement.
100 %Defined6/6 yes. Defined = yes / rated artefacts or identities. partially is not yes.
100 %Implemented12/12 yes. Implemented = yes / rated artefacts or identities. partially is not yes.
0 %Effectiveness0/3 yes. Effective = yes / rated artefacts or identities. partially is not yes.

Companion Contract/Example unchanged. This audit does not invent a certification statement.

How ISMS foundation is set up

One graph. Green boxes are installed in this volume. Dashed edges: HITL. COMM-P is not joined to LRR. MRART is not joined to MRMT. ICVC is not joined to SOA. WIR-S1 is not joined to ISOCTRL. ISP, ISS and OS stay Volume 1. Not a communication-count or review-day score.

ISP — Information Security Policy
Vol. 1installedpolicycomparison aBasic

Cited HOW policy. Needle POL-SEC-001. You EXAMINE whether it covers 5.1 and 5.2. This audit does not score coverage. Not joined to ISS, OS or PAP.

Artefact

ISS — ISMS Scope Statement
Vol. 1installedsystemhitlBasic

Cited HOW scope. Needle ISMS-SCOPE-001. You EXAMINE whether the ISMS boundary is operated. Not joined to ISP or OS.

Artefact

OS — Organization Statement
Vol. 1installedrolehitlBasic

Cited HOW statement. Needle ORG-STATEMENT-001. You EXAMINE whether roles are operated. Not joined to ISP or ISS.

Artefact

ICVC — ISO 27001 Control Owner Control Validation Checklist
Vol. 1Vol. 2installedprocesshitlPremium

Cited HOW checklist. You EXAMINE ICVC-CHK-001. ICVC-DEC-2026-Q3, ICVC-GAP-001 and ICVC-EX-001 stay citations. Check IDs in the journal stay citations, not an AOAVC join. Not a process-component. Not joined to SOA.

Artefact

MRART — Management Review Agenda & Report
Vol. 1Vol. 2installedprocesshitlPremium

Cited HOW agenda. You EXAMINE MGT-REV-AGENDA-001. Clause 9.3 stays with you. Not a process-component. Not joined to MRMT.

Artefact

MRMT — Management Review Minutes
Vol. 1Vol. 2installedevidencehitlPremium

In-pack minutes. Needle MGT-REV-MIN-001. Meeting date 2026-08-29 stays a citation, not a review-day score. Not joined to MRART or IAP.

Artefact

COMM-P — ISMS Communication Plan
Vol. 2not installedevidenceother-bookPremium

Volume 2 communication plan. Named, not packed, not joined in this volume.

Artefact

LRR — Legal, Regulatory and Contractual Requirements Register
Vol. 2not installedevidenceother-bookPremium

Volume 2 legal register. Named, not packed, not joined in this volume.

Artefact

WIR-S1 — Work Instruction Record — Security Cycle 1
Vol. 2Vol. 5not installedprocessother-bookPremium

Volume 2 work-instruction record. Named, not packed, not joined in this volume. Not a process-component.

Artefact

Nonconformities

Nonconformities this pack can show. Kernel FAIL is Policy ↔ evidence, default minor — not an automatic major. No policy and no implementation, or implementation without effectiveness evidence, is Requirement ↔ evidence. UNKNOWN is not an NC. Assessment Results stay the kernel SSOT. How to fix is the follow-up, not a customer ticket.

RequirementStatementGradePathDetail
4.2 Understanding the needs and expectations of interested parties4.2 Understanding the needs and expectations of interested parties has no policy and no implementation evidence in this pack.minorRequirement ↔ evidenceNC-FOUNDATION-not-implemented
5.1 Leadership and commitment5.1 Leadership and commitment has no policy and no implementation evidence in this pack.minorRequirement ↔ evidenceNC-FOUNDATION-not-implemented
5.2 Information security policy5.2 Information security policy has no policy and no implementation evidence in this pack.minorRequirement ↔ evidenceNC-FOUNDATION-not-implemented
7.4 Communication7.4 Communication has no policy and no implementation evidence in this pack.minorRequirement ↔ evidenceNC-FOUNDATION-not-implemented
7.5 Documented information7.5 Documented information is named in this pack, but there is no effectiveness evidence. Cited implementation: ICVC.minorRequirement ↔ evidenceNC-FOUNDATION-missing-evidence
9.3 Management review9.3 Management review is named in this pack, but there is no effectiveness evidence. Cited implementation: MRART, MRMT.minorRequirement ↔ evidenceNC-FOUNDATION-missing-evidence

Operational Evaluation

Artefacts in this category. Defined is a cited policy (HOW). Implemented is in-pack or named operating evidence. Effective is the kernel join or HITL effectiveness. Ratings are yes, no, or partially. DK or NA when this pack has no data.

ArtifactDefinedImplementedEffectiveArtefact
ISPyesNADKArtefact
ISSNAyesDKArtefact
OSyesNADKArtefact
IPRyesNADKArtefact
IRARyesNADKArtefact
RACIyesNADKArtefact
IGCNAyesDKArtefact
GSyesNADKArtefact
ISONAyesDKArtefact
CRNAyesDKArtefact
DALNAyesDKArtefact
OPCNAyesDKArtefact
RAENAyesDKArtefact
ICLNAyesDKArtefact
MMENAyesDKArtefact
ICVCNAyesnoArtefact
MRARTNAyesnoArtefact
MRMTNAyesnoArtefact

What we found

What this pack actually cited for each artefact. Counts are from this pack. Presence is not a PASS. No ISO shall-text.

ISP

ISP is in-pack in Volume 1. Defined yes, implemented NA, effective DK. Missing layers are explained on the artefact page — not joined from another book.

ISS

ISS is in-pack in Volume 1. Defined NA, implemented yes, effective DK. Missing layers are explained on the artefact page — not joined from another book.

OS

OS is in-pack in Volume 1. Defined yes, implemented NA, effective DK. Missing layers are explained on the artefact page — not joined from another book.

IPR

IPR is in-pack in Volume 1. Defined yes, implemented NA, effective DK. Missing layers are explained on the artefact page — not joined from another book.

IRAR

IRAR is in-pack in Volume 1. Defined yes, implemented NA, effective DK. Missing layers are explained on the artefact page — not joined from another book.

RACI

RACI is in-pack in Volume 1. Defined yes, implemented NA, effective DK. Missing layers are explained on the artefact page — not joined from another book.

IGC

IGC is in-pack in Volume 1. Defined NA, implemented yes, effective DK. Missing layers are explained on the artefact page — not joined from another book.

GS

GS is in-pack in Volume 1. Defined yes, implemented NA, effective DK. Missing layers are explained on the artefact page — not joined from another book.

ISO

ISO is in-pack in Volume 1. Defined NA, implemented yes, effective DK. Missing layers are explained on the artefact page — not joined from another book.

CR

CR is in-pack in Volume 1. Defined NA, implemented yes, effective DK. Missing layers are explained on the artefact page — not joined from another book.

DAL

DAL is in-pack in Volume 1. Defined NA, implemented yes, effective DK. Missing layers are explained on the artefact page — not joined from another book.

OPC

OPC is in-pack in Volume 1. Defined NA, implemented yes, effective DK. Missing layers are explained on the artefact page — not joined from another book.

RAE

RAE is in-pack in Volume 1. Defined NA, implemented yes, effective DK. Missing layers are explained on the artefact page — not joined from another book.

ICL

ICL is in-pack in Volume 1. Defined NA, implemented yes, effective DK. Missing layers are explained on the artefact page — not joined from another book.

MME

MME is in-pack in Volume 1. Defined NA, implemented yes, effective DK. Missing layers are explained on the artefact page — not joined from another book.

ICVC

ICVC is in-pack in Volume 1. Defined NA, implemented yes, effective no. A nonconformity cites this artefact. Missing layers are explained on the artefact page — not joined from another book.

MRART

MRART is in-pack in Volume 1. Defined NA, implemented yes, effective no. A nonconformity cites this artefact. Missing layers are explained on the artefact page — not joined from another book.

MRMT

MRMT is in-pack in Volume 1. Defined NA, implemented yes, effective no. A nonconformity cites this artefact. Missing layers are explained on the artefact page — not joined from another book.

Foundation inventory

No inventory rows in the examined Example JSON.

Tags in this report

Volume

Vol. 1Vol. 2Vol. 5

Presence

installednot installed

Kind

policycomparison asystemhitlroleprocessevidenceother-book

Tier

PremiumBasic

Check installation

What is installed here. Extra volumes are optional and do not change Ready. Update re-runs the check.

CheckResult
Webserver…
Python…
Volumes…
Scripts…
Ready…
Working directory…
Last update…