Arcfield People / HR audit
Source: Arcfield EN Companion · Volume 1 audit + OSCAL assessment plan (AP) / assessment results (AR) · oscal/assessment-plan.md, oscal/assessment-results.md · HITL: oscal-guide.md · SIMULATION
How this report is elaborated
Scope is the Volume 1 People / HR audit. Artefacts installed in this volume are in-pack; neighbours named from other volumes stay in those books (Vol. 1, Vol. 2).
The process we followed is ISO 27001 → Policies → Processes and Systems → Protected Assets → Objects needed by the process → Evidences. Standard vs policy examines whether a policy covers the cited clause or control. Policy vs evidence tests the join from policy rule to recorded evidence.
How to read this report
Start with Results at a glance, then how this category is set up. Standard vs policy is EXAMINE and stays not scored. Nonconformities are kernel FAIL (Policy ↔ evidence, default minor) and Requirement ↔ evidence: no policy and no implementation, or implementation without effectiveness evidence. UNKNOWN is not an NC. Glance counts Conformity, Defined, Implemented, and Effectiveness — not PASS/FAIL compliance. Not scored on an inventory row means the subject is not in this topic's kernel join. It is not a Statement of Applicability exclusion.
Results at a glance
Companion Contract/Example unchanged. This audit does not invent a certification statement.
How HR is set up
One graph. Green boxes are installed in this volume. Dashed edges: HITL. HRSP is not joined to CMTP. CMTP is not joined to TR, ONC or UAI. HRP, ONC, OFC, TR and TRC stay Volume 1. Not a training-count, gap-count, or competence-day score.
Cited HOW policy. Needle HR-POL-001. You EXAMINE whether it covers A.6.1–A.6.5 and 7.2. This audit does not score coverage. A.6.4 stays here. Not joined to HRSP, CMTP or UAI.
Cited HOW policy. You EXAMINE HR-SEC-POL-002. Whether it covers A.6.1–A.6.3, A.6.5 and 7.2 stays with you. Not a joiner-count score. Not joined to CMTP. A.6.4 stays with HRP.
Cited HOW checklist. You EXAMINE whether onboarding is operated. Not joined to CMTP or UAI.
Cited HOW checklist. You EXAMINE whether offboarding is operated. Not joined to CMTP or UAI.
In-pack register. Needle TR. Training rows stay citations, not a training-count score. Not joined to CMTP.
In-pack records. Training evidence stays a citation, not a competence-day score. Not joined to CMTP.
Volume 2 competence matrix. Named, not packed, not joined in this volume. Not a process-component.
Nonconformities
Nonconformities this pack can show. Kernel FAIL is Policy ↔ evidence, default minor — not an automatic major. No policy and no implementation, or implementation without effectiveness evidence, is Requirement ↔ evidence. UNKNOWN is not an NC. Assessment Results stay the kernel SSOT. How to fix is the follow-up, not a customer ticket.
| Requirement | Statement | Grade | Path | Detail |
|---|---|---|---|---|
| 7.5 Documented information | 7.5 Documented information has no policy and no implementation evidence in this pack. | minor | Requirement ↔ evidence | NC-HR-not-implemented |
| A.6.4 Disciplinary process | A.6.4 Disciplinary process has no policy and no implementation evidence in this pack. | minor | Requirement ↔ evidence | NC-HR-not-implemented |
Operational Evaluation
Artefacts in this category. Defined is a cited policy (HOW). Implemented is in-pack or named operating evidence. Effective is the kernel join or HITL effectiveness. Ratings are yes, no, or partially. DK or NA when this pack has no data.
| Artifact | Defined | Implemented | Effective | Artefact |
|---|---|---|---|---|
| HRP | yes | NA | DK | Artefact |
| HRSP | yes | NA | DK | Artefact |
| ONC | NA | yes | DK | Artefact |
| OFC | NA | yes | DK | Artefact |
| TR | NA | yes | DK | Artefact |
| TRC | NA | yes | DK | Artefact |
What we found
What this pack actually cited for each artefact. Counts are from this pack. Presence is not a PASS. No ISO shall-text.
HRP
- Defined: yes.
- Implemented: NA.
- Effective: DK.
- Nonconformity on this artefact: no.
- Layers present: Office, OSCAL.
HRP is in-pack in Volume 1. Defined yes, implemented NA, effective DK. Missing layers are explained on the artefact page — not joined from another book.
HRSP
- Defined: yes.
- Implemented: NA.
- Effective: DK.
- Nonconformity on this artefact: no.
- Layers present: Office, OSCAL.
HRSP is in-pack in Volume 1. Defined yes, implemented NA, effective DK. Missing layers are explained on the artefact page — not joined from another book.
ONC
- Defined: NA.
- Implemented: yes.
- Effective: DK.
- Nonconformity on this artefact: no.
- Layers present: Office, OSCAL.
ONC is in-pack in Volume 1. Defined NA, implemented yes, effective DK. Missing layers are explained on the artefact page — not joined from another book.
OFC
- Defined: NA.
- Implemented: yes.
- Effective: DK.
- Nonconformity on this artefact: no.
- Layers present: Office, OSCAL.
OFC is in-pack in Volume 1. Defined NA, implemented yes, effective DK. Missing layers are explained on the artefact page — not joined from another book.
TR
- Defined: NA.
- Implemented: yes.
- Effective: DK.
- Nonconformity on this artefact: no.
- Layers present: Office, OSCAL.
TR is in-pack in Volume 1. Defined NA, implemented yes, effective DK. Missing layers are explained on the artefact page — not joined from another book.
TRC
- Defined: NA.
- Implemented: yes.
- Effective: DK.
- Nonconformity on this artefact: no.
- Layers present: Office, OSCAL.
TRC is in-pack in Volume 1. Defined NA, implemented yes, effective DK. Missing layers are explained on the artefact page — not joined from another book.
People inventory
No inventory rows in the examined Example JSON.
