ExportableProof — Routines today. Proof tomorrow.

Arcfield ISMS implementation audit

Source: Arcfield EN Companion · Volume 1 audit + OSCAL assessment plan (AP) / assessment results (AR) · oscal/assessment-plan.md, oscal/assessment-results.md · HITL: oscal-guide.md · SIMULATION

How this report is elaborated

Scope is the Volume 1 ISMS implementation audit. Artefacts installed in this volume are in-pack; neighbours named from other volumes stay in those books (Vol. 1, Vol. 2, Vol. 3, Vol. 4, Vol. 5).

The process we followed is ISO 27001 → Policies → Processes and Systems → Protected Assets → Objects needed by the process → Evidences. Standard vs policy examines whether a policy covers the cited clause or control. Policy vs evidence tests the join from policy rule to recorded evidence.

How to read this report

Start with Results at a glance, then how this category is set up. Standard vs policy is EXAMINE and stays not scored. Nonconformities are kernel FAIL (Policy ↔ evidence, default minor) and Requirement ↔ evidence: no policy and no implementation, or implementation without effectiveness evidence. UNKNOWN is not an NC. Glance counts Conformity, Defined, Implemented, and Effectiveness — not PASS/FAIL compliance. Not scored on an inventory row means the subject is not in this topic's kernel join. It is not a Statement of Applicability exclusion.

Results at a glance

0 %Conformity1/1 NC. Share without an NC. DK/NA are out of the denominator. Not a certification statement.
—Defined0/0 yes. Defined = yes / rated artefacts or identities. partially is not yes.
100 %Implemented1/1 yes. Implemented = yes / rated artefacts or identities. partially is not yes.
0 %Effectiveness0/1 yes. Effective = yes / rated artefacts or identities. partially is not yes.

Companion Contract/Example unchanged. This audit does not invent a certification statement.

How ISMS implementation is set up

One graph. Green boxes are installed in this volume. Dashed edges: HITL. IMPL-WB is not joined to IMPL-P. Not a kernel score. Not a process-component.

IMPL-WB — Operational ISMS Dashboard
Vol. 1Vol. 2Vol. 3Vol. 4Vol. 5installeddependencyhitlBasic

In-pack operational dashboard. You EXAMINE whether it covers 4.4, 6.2 and 9.1. Presence is not effectiveness. Not joined to IMPL-P. Not a kernel score. Not a process-component.

Artefact

IMPL-P — Phased ISMS Implementation Plan
Vol. 2not installedevidenceother-bookBasic

Volume 2 phased plan. Named, not packed, not joined in this volume.

Artefact

Nonconformities

Nonconformities this pack can show. Kernel FAIL is Policy ↔ evidence, default minor — not an automatic major. No policy and no implementation, or implementation without effectiveness evidence, is Requirement ↔ evidence. UNKNOWN is not an NC. Assessment Results stay the kernel SSOT. How to fix is the follow-up, not a customer ticket.

RequirementStatementGradePathDetail
4.4 Information security management system4.4 Information security management system is named in this pack, but there is no effectiveness evidence. Cited implementation: IMPL-WB.minorRequirement ↔ evidenceNC-IMPLEMENTATION-missing-evidence
6.2 Information security objectives and planning to achieve them6.2 Information security objectives and planning to achieve them is named in this pack, but there is no effectiveness evidence. Cited implementation: IMPL-WB.minorRequirement ↔ evidenceNC-IMPLEMENTATION-missing-evidence
9.1 Monitoring, measurement, analysis and evaluation9.1 Monitoring, measurement, analysis and evaluation is named in this pack, but there is no effectiveness evidence. Cited implementation: IMPL-WB.minorRequirement ↔ evidenceNC-IMPLEMENTATION-missing-evidence

Operational Evaluation

Artefacts in this category. Defined is a cited policy (HOW). Implemented is in-pack or named operating evidence. Effective is the kernel join or HITL effectiveness. Ratings are yes, no, or partially. DK or NA when this pack has no data.

ArtifactDefinedImplementedEffectiveArtefact
IMPL-WBNAyesnoArtefact

What we found

What this pack actually cited for each artefact. Counts are from this pack. Presence is not a PASS. No ISO shall-text.

IMPL-WB

IMPL-WB is in-pack in Volume 1. Defined NA, implemented yes, effective no. A nonconformity cites this artefact. Missing layers are explained on the artefact page — not joined from another book.

Implementation inventory

No inventory rows in the examined Example JSON.

Tags in this report

Volume

Vol. 1Vol. 2Vol. 3Vol. 4Vol. 5

Presence

installednot installed

Kind

dependencyhitlevidenceother-book

Tier

Basic

Check installation

What is installed here. Extra volumes are optional and do not change Ready. Update re-runs the check.

CheckResult
Webserver…
Python…
Volumes…
Scripts…
Ready…
Working directory…
Last update…