ExportableProof — Routines today. Proof tomorrow.

Arcfield People / HR audit

Source: Arcfield EN Companion · Volume 1 audit + OSCAL assessment plan (AP) / assessment results (AR) · oscal/assessment-plan.md, oscal/assessment-results.md · HITL: oscal-guide.md · SIMULATION

How this report is elaborated

Scope is the Volume 1 People / HR audit. Artefacts installed in this volume are in-pack; neighbours named from other volumes stay in those books (Vol. 1, Vol. 2).

The process we followed is ISO 27001 → Policies → Processes and Systems → Protected Assets → Objects needed by the process → Evidences. Standard vs policy examines whether a policy covers the cited clause or control. Policy vs evidence tests the join from policy rule to recorded evidence.

How to read this report

Start with Results at a glance, then how this category is set up. Standard vs policy is EXAMINE and stays not scored. Nonconformities are kernel FAIL (Policy ↔ evidence, default minor) and Requirement ↔ evidence: no policy and no implementation, or implementation without effectiveness evidence. UNKNOWN is not an NC. Glance counts Conformity, Defined, Implemented, and Effectiveness — not PASS/FAIL compliance. Not scored on an inventory row means the subject is not in this topic's kernel join. It is not a Statement of Applicability exclusion.

Results at a glance

100 %Conformity0/6 NC. Share without an NC. DK/NA are out of the denominator. Not a certification statement.
100 %Defined2/2 yes. Defined = yes / rated artefacts or identities. partially is not yes.
100 %Implemented4/4 yes. Implemented = yes / rated artefacts or identities. partially is not yes.
—Effectiveness0/0 yes. Effective = yes / rated artefacts or identities. partially is not yes.

Companion Contract/Example unchanged. This audit does not invent a certification statement.

How HR is set up

One graph. Green boxes are installed in this volume. Dashed edges: HITL. HRSP is not joined to CMTP. CMTP is not joined to TR, ONC or UAI. HRP, ONC, OFC, TR and TRC stay Volume 1. Not a training-count, gap-count, or competence-day score.

HRP — Human Resources Policy
Vol. 1installedpolicycomparison aPremium

Cited HOW policy. Needle HR-POL-001. You EXAMINE whether it covers A.6.1–A.6.5 and 7.2. This audit does not score coverage. A.6.4 stays here. Not joined to HRSP, CMTP or UAI.

Artefact

HRSP — Human Resources Security Policy
Vol. 1Vol. 2installedpolicyhitlPremium

Cited HOW policy. You EXAMINE HR-SEC-POL-002. Whether it covers A.6.1–A.6.3, A.6.5 and 7.2 stays with you. Not a joiner-count score. Not joined to CMTP. A.6.4 stays with HRP.

Artefact

ONC — Onboarding Checklist
Vol. 1installedprocesshitlPremium

Cited HOW checklist. You EXAMINE whether onboarding is operated. Not joined to CMTP or UAI.

Artefact

OFC — Offboarding Checklist
Vol. 1installedprocesshitlPremium

Cited HOW checklist. You EXAMINE whether offboarding is operated. Not joined to CMTP or UAI.

Artefact

TR — Training Register
Vol. 1installedevidenceinventoryPremium

In-pack register. Needle TR. Training rows stay citations, not a training-count score. Not joined to CMTP.

Artefact

TRC — Training Records
Vol. 1installedevidencehitlPremium

In-pack records. Training evidence stays a citation, not a competence-day score. Not joined to CMTP.

Artefact

CMTP — Competence Matrix and Training Plan
Vol. 2not installeddependencyother-bookPremium

Volume 2 competence matrix. Named, not packed, not joined in this volume. Not a process-component.

Artefact

Nonconformities

Nonconformities this pack can show. Kernel FAIL is Policy ↔ evidence, default minor — not an automatic major. No policy and no implementation, or implementation without effectiveness evidence, is Requirement ↔ evidence. UNKNOWN is not an NC. Assessment Results stay the kernel SSOT. How to fix is the follow-up, not a customer ticket.

RequirementStatementGradePathDetail
7.5 Documented information7.5 Documented information has no policy and no implementation evidence in this pack.minorRequirement ↔ evidenceNC-HR-not-implemented
A.6.4 Disciplinary processA.6.4 Disciplinary process has no policy and no implementation evidence in this pack.minorRequirement ↔ evidenceNC-HR-not-implemented

Operational Evaluation

Artefacts in this category. Defined is a cited policy (HOW). Implemented is in-pack or named operating evidence. Effective is the kernel join or HITL effectiveness. Ratings are yes, no, or partially. DK or NA when this pack has no data.

ArtifactDefinedImplementedEffectiveArtefact
HRPyesNADKArtefact
HRSPyesNADKArtefact
ONCNAyesDKArtefact
OFCNAyesDKArtefact
TRNAyesDKArtefact
TRCNAyesDKArtefact

What we found

What this pack actually cited for each artefact. Counts are from this pack. Presence is not a PASS. No ISO shall-text.

HRP

HRP is in-pack in Volume 1. Defined yes, implemented NA, effective DK. Missing layers are explained on the artefact page — not joined from another book.

HRSP

HRSP is in-pack in Volume 1. Defined yes, implemented NA, effective DK. Missing layers are explained on the artefact page — not joined from another book.

ONC

ONC is in-pack in Volume 1. Defined NA, implemented yes, effective DK. Missing layers are explained on the artefact page — not joined from another book.

OFC

OFC is in-pack in Volume 1. Defined NA, implemented yes, effective DK. Missing layers are explained on the artefact page — not joined from another book.

TR

TR is in-pack in Volume 1. Defined NA, implemented yes, effective DK. Missing layers are explained on the artefact page — not joined from another book.

TRC

TRC is in-pack in Volume 1. Defined NA, implemented yes, effective DK. Missing layers are explained on the artefact page — not joined from another book.

People inventory

No inventory rows in the examined Example JSON.

Tags in this report

Volume

Vol. 1Vol. 2

Presence

installednot installed

Kind

policycomparison ahitlprocessevidenceinventorydependencyother-book

Tier

Premium

Check installation

What is installed here. Extra volumes are optional and do not change Ready. Update re-runs the check.

CheckResult
Webserver…
Python…
Volumes…
Scripts…
Ready…
Working directory…
Last update…