Arcfield Risk audit
Source: Arcfield EN Companion · Volume 1 audit + OSCAL assessment plan (AP) / assessment results (AR) · oscal/assessment-plan.md, oscal/assessment-results.md · HITL: oscal-guide.md · SIMULATION
How this report is elaborated
Scope is the Volume 1 Risk audit. Artefacts installed in this volume are in-pack; neighbours named from other volumes stay in those books (Vol. 1, Vol. 2, Vol. 5).
The process we followed is ISO 27001 → Policies → Processes and Systems → Protected Assets → Objects needed by the process → Evidences. Standard vs policy examines whether a policy covers the cited clause or control. Policy vs evidence tests the join from policy rule to recorded evidence.
How to read this report
Start with Results at a glance, then how this category is set up. Standard vs policy is EXAMINE and stays not scored. Nonconformities are kernel FAIL (Policy ↔ evidence, default minor) and Requirement ↔ evidence: no policy and no implementation, or implementation without effectiveness evidence. UNKNOWN is not an NC. Glance counts Conformity, Defined, Implemented, and Effectiveness — not PASS/FAIL compliance. Not scored on an inventory row means the subject is not in this topic's kernel join. It is not a Statement of Applicability exclusion.
Results at a glance
Companion Contract/Example unchanged. This audit does not invent a certification statement.
How risk is set up
One graph. Green boxes are installed in this volume. Dashed edges: HITL. RR is not joined to RTP. AORVC is not joined to RR or AI. PBIVC is not joined to BIA. RAM, RMP and ERR stay Volume 1. Not a residual-score, risk-count, or treatment-day score.
Cited HOW methodology. Needle RISK-METH-001. You EXAMINE whether it covers clause 6.1. ISO/IEC 27005 is named, not scored. Not a residual-score engine. Not joined to RASM or RR.
Cited HOW statement. You EXAMINE RISK-ANALYSIS-STATEMENT-001. Clause 6.1 stays with you. ISO/IEC 27005 is named, not scored. Not a residual-score engine. Not joined to RAM.
In-pack register. RISK-2026-014 In treatment stays a citation, not a risk-count or residual-score. Treatment IDs in RR stay citations, not an RTP join. RR-COMPLETE-2026-Q3 stays a citation, not a completeness score.
In-pack treatment plan. RTP-2026-014 In progress stays a citation, not a treatment-day score. Related risk IDs in RTP stay citations, not an RR join. Not a process-component.
Cited HOW plan. Needle RMP-WF-001. You EXAMINE whether it is operated. Not joined to RAM or RR.
In-pack report. Needle EXEC-RISK-RPT-001. You EXAMINE whether it is operated. Not a residual-score. Not joined to RR.
Volume 2 opportunities register. Named, not packed, not joined in this volume.
Volume 2 owner checklist. Named, not packed, not joined in this volume. Not a process-component.
Volume 2 impact checklist. Named, not packed, not joined in this volume. Not a process-component.
Nonconformities
Nonconformities this pack can show. Kernel FAIL is Policy ↔ evidence, default minor — not an automatic major. No policy and no implementation, or implementation without effectiveness evidence, is Requirement ↔ evidence. UNKNOWN is not an NC. Assessment Results stay the kernel SSOT. How to fix is the follow-up, not a customer ticket.
| Requirement | Statement | Grade | Path | Detail |
|---|---|---|---|---|
| 7.5 Documented information | 7.5 Documented information is named in this pack, but there is no effectiveness evidence. Cited implementation: RR, RTP. | minor | Requirement ↔ evidence | NC-RISK-missing-evidence |
| 8.1 Operational planning and control | 8.1 Operational planning and control is named in this pack, but there is no effectiveness evidence. Cited implementation: RR, RTP. | minor | Requirement ↔ evidence | NC-RISK-missing-evidence |
Operational Evaluation
Artefacts in this category. Defined is a cited policy (HOW). Implemented is in-pack or named operating evidence. Effective is the kernel join or HITL effectiveness. Ratings are yes, no, or partially. DK or NA when this pack has no data.
| Artifact | Defined | Implemented | Effective | Artefact |
|---|---|---|---|---|
| RAM | NA | yes | DK | Artefact |
| RMP | NA | yes | DK | Artefact |
| RAMT | NA | yes | DK | Artefact |
| RASM | yes | NA | DK | Artefact |
| RR | NA | yes | no | Artefact |
| RTP | NA | yes | no | Artefact |
| ERR | NA | yes | DK | Artefact |
What we found
What this pack actually cited for each artefact. Counts are from this pack. Presence is not a PASS. No ISO shall-text.
RAM
- Defined: NA.
- Implemented: yes.
- Effective: DK.
- Nonconformity on this artefact: no.
- Layers present: Office, OSCAL.
RAM is in-pack in Volume 1. Defined NA, implemented yes, effective DK. Missing layers are explained on the artefact page — not joined from another book.
RMP
- Defined: NA.
- Implemented: yes.
- Effective: DK.
- Nonconformity on this artefact: no.
- Layers present: Office, OSCAL.
RMP is in-pack in Volume 1. Defined NA, implemented yes, effective DK. Missing layers are explained on the artefact page — not joined from another book.
RAMT
- Defined: NA.
- Implemented: yes.
- Effective: DK.
- Nonconformity on this artefact: no.
- Layers present: Office, OSCAL.
RAMT is in-pack in Volume 1. Defined NA, implemented yes, effective DK. Missing layers are explained on the artefact page — not joined from another book.
RASM
- Defined: yes.
- Implemented: NA.
- Effective: DK.
- Nonconformity on this artefact: no.
- Layers present: Office, OSCAL.
RASM is in-pack in Volume 1. Defined yes, implemented NA, effective DK. Missing layers are explained on the artefact page — not joined from another book.
RR
- Defined: NA.
- Implemented: yes.
- Effective: no.
- Nonconformity on this artefact: yes.
- Layers present: Office, OSCAL.
RR is in-pack in Volume 1. Defined NA, implemented yes, effective no. A nonconformity cites this artefact. Missing layers are explained on the artefact page — not joined from another book.
RTP
- Defined: NA.
- Implemented: yes.
- Effective: no.
- Nonconformity on this artefact: yes.
- Layers present: Office, OSCAL.
RTP is in-pack in Volume 1. Defined NA, implemented yes, effective no. A nonconformity cites this artefact. Missing layers are explained on the artefact page — not joined from another book.
ERR
- Defined: NA.
- Implemented: yes.
- Effective: DK.
- Nonconformity on this artefact: no.
- Layers present: Office, OSCAL.
ERR is in-pack in Volume 1. Defined NA, implemented yes, effective DK. Missing layers are explained on the artefact page — not joined from another book.
Risk inventory
No inventory rows in the examined Example JSON.
