ExportableProof — Routines today. Proof tomorrow.

Arcfield Risk audit

Source: Arcfield EN Companion · Volume 1 audit + OSCAL assessment plan (AP) / assessment results (AR) · oscal/assessment-plan.md, oscal/assessment-results.md · HITL: oscal-guide.md · SIMULATION

How this report is elaborated

Scope is the Volume 1 Risk audit. Artefacts installed in this volume are in-pack; neighbours named from other volumes stay in those books (Vol. 1, Vol. 2, Vol. 5).

The process we followed is ISO 27001 → Policies → Processes and Systems → Protected Assets → Objects needed by the process → Evidences. Standard vs policy examines whether a policy covers the cited clause or control. Policy vs evidence tests the join from policy rule to recorded evidence.

How to read this report

Start with Results at a glance, then how this category is set up. Standard vs policy is EXAMINE and stays not scored. Nonconformities are kernel FAIL (Policy ↔ evidence, default minor) and Requirement ↔ evidence: no policy and no implementation, or implementation without effectiveness evidence. UNKNOWN is not an NC. Glance counts Conformity, Defined, Implemented, and Effectiveness — not PASS/FAIL compliance. Not scored on an inventory row means the subject is not in this topic's kernel join. It is not a Statement of Applicability exclusion.

Results at a glance

71 %Conformity2/7 NC. Share without an NC. DK/NA are out of the denominator. Not a certification statement.
100 %Defined1/1 yes. Defined = yes / rated artefacts or identities. partially is not yes.
100 %Implemented6/6 yes. Implemented = yes / rated artefacts or identities. partially is not yes.
0 %Effectiveness0/2 yes. Effective = yes / rated artefacts or identities. partially is not yes.

Companion Contract/Example unchanged. This audit does not invent a certification statement.

How risk is set up

One graph. Green boxes are installed in this volume. Dashed edges: HITL. RR is not joined to RTP. AORVC is not joined to RR or AI. PBIVC is not joined to BIA. RAM, RMP and ERR stay Volume 1. Not a residual-score, risk-count, or treatment-day score.

RAM — Risk Assessment Methodology
Vol. 1installedprocesscomparison aBasic

Cited HOW methodology. Needle RISK-METH-001. You EXAMINE whether it covers clause 6.1. ISO/IEC 27005 is named, not scored. Not a residual-score engine. Not joined to RASM or RR.

Artefact

RASM — Risk Analysis Statement
Vol. 1Vol. 2installedpolicyhitlPremium

Cited HOW statement. You EXAMINE RISK-ANALYSIS-STATEMENT-001. Clause 6.1 stays with you. ISO/IEC 27005 is named, not scored. Not a residual-score engine. Not joined to RAM.

Artefact

RR — Risk Register
Vol. 1Vol. 2installedriskinventoryBasic

In-pack register. RISK-2026-014 In treatment stays a citation, not a risk-count or residual-score. Treatment IDs in RR stay citations, not an RTP join. RR-COMPLETE-2026-Q3 stays a citation, not a completeness score.

Artefact

RTP — Risk Treatment Plan
Vol. 1Vol. 2installedpoamhitlBasic

In-pack treatment plan. RTP-2026-014 In progress stays a citation, not a treatment-day score. Related risk IDs in RTP stay citations, not an RR join. Not a process-component.

Artefact

RMP — Risk Management Plan
Vol. 1installedprocesshitlPremium

Cited HOW plan. Needle RMP-WF-001. You EXAMINE whether it is operated. Not joined to RAM or RR.

Artefact

ERR — Executive Risk Report
Vol. 1Vol. 5installedevidencehitlPremium

In-pack report. Needle EXEC-RISK-RPT-001. You EXAMINE whether it is operated. Not a residual-score. Not joined to RR.

Artefact

ROAR — ISMS Risks and Opportunities Register
Vol. 2not installedriskother-bookPremium

Volume 2 opportunities register. Named, not packed, not joined in this volume.

Artefact

AORVC — Asset Owner Risk Validation Checklist
Vol. 2not installedprocessother-bookPremium

Volume 2 owner checklist. Named, not packed, not joined in this volume. Not a process-component.

Artefact

PBIVC — Process Owner Business Impact Validation Checklist
Vol. 2not installedprocessother-bookPremium

Volume 2 impact checklist. Named, not packed, not joined in this volume. Not a process-component.

Artefact

Nonconformities

Nonconformities this pack can show. Kernel FAIL is Policy ↔ evidence, default minor — not an automatic major. No policy and no implementation, or implementation without effectiveness evidence, is Requirement ↔ evidence. UNKNOWN is not an NC. Assessment Results stay the kernel SSOT. How to fix is the follow-up, not a customer ticket.

RequirementStatementGradePathDetail
7.5 Documented information7.5 Documented information is named in this pack, but there is no effectiveness evidence. Cited implementation: RR, RTP.minorRequirement ↔ evidenceNC-RISK-missing-evidence
8.1 Operational planning and control8.1 Operational planning and control is named in this pack, but there is no effectiveness evidence. Cited implementation: RR, RTP.minorRequirement ↔ evidenceNC-RISK-missing-evidence

Operational Evaluation

Artefacts in this category. Defined is a cited policy (HOW). Implemented is in-pack or named operating evidence. Effective is the kernel join or HITL effectiveness. Ratings are yes, no, or partially. DK or NA when this pack has no data.

ArtifactDefinedImplementedEffectiveArtefact
RAMNAyesDKArtefact
RMPNAyesDKArtefact
RAMTNAyesDKArtefact
RASMyesNADKArtefact
RRNAyesnoArtefact
RTPNAyesnoArtefact
ERRNAyesDKArtefact

What we found

What this pack actually cited for each artefact. Counts are from this pack. Presence is not a PASS. No ISO shall-text.

RAM

RAM is in-pack in Volume 1. Defined NA, implemented yes, effective DK. Missing layers are explained on the artefact page — not joined from another book.

RMP

RMP is in-pack in Volume 1. Defined NA, implemented yes, effective DK. Missing layers are explained on the artefact page — not joined from another book.

RAMT

RAMT is in-pack in Volume 1. Defined NA, implemented yes, effective DK. Missing layers are explained on the artefact page — not joined from another book.

RASM

RASM is in-pack in Volume 1. Defined yes, implemented NA, effective DK. Missing layers are explained on the artefact page — not joined from another book.

RR

RR is in-pack in Volume 1. Defined NA, implemented yes, effective no. A nonconformity cites this artefact. Missing layers are explained on the artefact page — not joined from another book.

RTP

RTP is in-pack in Volume 1. Defined NA, implemented yes, effective no. A nonconformity cites this artefact. Missing layers are explained on the artefact page — not joined from another book.

ERR

ERR is in-pack in Volume 1. Defined NA, implemented yes, effective DK. Missing layers are explained on the artefact page — not joined from another book.

Risk inventory

No inventory rows in the examined Example JSON.

Tags in this report

Volume

Vol. 1Vol. 2Vol. 5

Presence

installednot installed

Kind

processcomparison apolicyhitlriskinventorypoamevidenceother-book

Tier

PremiumBasic

Check installation

What is installed here. Extra volumes are optional and do not change Ready. Update re-runs the check.

CheckResult
Webserver…
Python…
Volumes…
Scripts…
Ready…
Working directory…
Last update…