ExportableProof — Routines today. Proof tomorrow.

Arcfield Supplier audit

Source: Arcfield EN Companion · Volume 1 audit + OSCAL assessment plan (AP) / assessment results (AR) · oscal/assessment-plan.md, oscal/assessment-results.md · HITL: oscal-guide.md · SIMULATION

How this report is elaborated

Scope is the Volume 1 Supplier audit. Artefacts installed in this volume are in-pack; neighbours named from other volumes stay in those books (Vol. 1, Vol. 5, Vol. 2).

The process we followed is ISO 27001 → Policies → Processes and Systems → Protected Assets → Objects needed by the process → Evidences. Standard vs policy examines whether a policy covers the cited clause or control. Policy vs evidence tests the join from policy rule to recorded evidence.

How to read this report

Start with Results at a glance, then how this category is set up. Standard vs policy is EXAMINE and stays not scored. Nonconformities are kernel FAIL (Policy ↔ evidence, default minor) and Requirement ↔ evidence: no policy and no implementation, or implementation without effectiveness evidence. UNKNOWN is not an NC. Glance counts Conformity, Defined, Implemented, and Effectiveness — not PASS/FAIL compliance. Not scored on an inventory row means the subject is not in this topic's kernel join. It is not a Statement of Applicability exclusion.

Results at a glance

75 %Conformity1/4 NC. Share without an NC. DK/NA are out of the denominator. Not a certification statement.
100 %Defined1/1 yes. Defined = yes / rated artefacts or identities. partially is not yes.
100 %Implemented3/3 yes. Implemented = yes / rated artefacts or identities. partially is not yes.
0 %Effectiveness0/1 yes. Effective = yes / rated artefacts or identities. partially is not yes.

Companion Contract/Example unchanged. This audit does not invent a certification statement.

How supplier is set up

One graph. Green boxes are installed in this volume. Dashed edges: HITL. CSS is not joined to CSSAQ. CSSAQ is not joined to SINV, SRP or SSAQ. SRP, SINV and SSAQ stay Volume 1. Not a supplier-count or questionnaire-score.

SRP — Supplier Relationships Policy
Vol. 1Vol. 5installedpolicycomparison aPremium

Cited HOW policy. Needle SUP-REL-POL-001. You EXAMINE whether it covers A.5.19–A.5.23. This audit does not score coverage. Not joined to SINV, SSAQ or CSSAQ.

Artefact

SINV — Supplier Inventory
Vol. 1Vol. 5installedassetinventoryPremium

In-pack inventory. Supplier rows stay citations, not a supplier-count score. Not joined to CSSAQ or SSAQ.

Artefact

SSAQ — Supplier Security Assessment Questionnaire
Vol. 1Vol. 5installedprocesshitlPremium

Cited HOW questionnaire. You EXAMINE whether it is operated. Not a questionnaire-score. Not joined to CSSAQ or SINV.

Artefact

CSSAQ — Critical Supplier Security Assessment Questionnaire
Vol. 1Vol. 2Vol. 5installedprocesshitlPremium

In-pack questionnaire. Needle CSSAQ-FRM-001 / CSSAQ-2026-CLOUDHOST-001. Open follow-up, Approved with conditions, and Partial stay citations. Track three supplier actions in SINV stays a citation, not a SINV join. Not a process-component.

Artefact

CSS — Cloud Security Statement
Vol. 2not installedpolicyother-bookPremium

Volume 2 cloud-security statement. Named, not packed, not joined in this volume.

Artefact

Nonconformities

Nonconformities this pack can show. Kernel FAIL is Policy ↔ evidence, default minor — not an automatic major. No policy and no implementation, or implementation without effectiveness evidence, is Requirement ↔ evidence. UNKNOWN is not an NC. Assessment Results stay the kernel SSOT. How to fix is the follow-up, not a customer ticket.

RequirementStatementGradePathDetail
A.5.19 Information security in supplier relationshipsA.5.19 Information security in supplier relationships is named in this pack, but there is no effectiveness evidence. Cited implementation: CSSAQ.minorRequirement ↔ evidenceNC-SUPPLIER-missing-evidence
A.5.20 Addressing information security within supplier agreementsA.5.20 Addressing information security within supplier agreements is named in this pack, but there is no effectiveness evidence. Cited implementation: CSSAQ.minorRequirement ↔ evidenceNC-SUPPLIER-missing-evidence
A.5.21 Managing information security in the ICT supply chainA.5.21 Managing information security in the ICT supply chain is named in this pack, but there is no effectiveness evidence. Cited implementation: CSSAQ.minorRequirement ↔ evidenceNC-SUPPLIER-missing-evidence
A.5.22 Monitoring, review and change management of supplier servicesA.5.22 Monitoring, review and change management of supplier services is named in this pack, but there is no effectiveness evidence. Cited implementation: CSSAQ.minorRequirement ↔ evidenceNC-SUPPLIER-missing-evidence
A.5.23 Information security for use of cloud servicesA.5.23 Information security for use of cloud services has no policy and no implementation evidence in this pack.minorRequirement ↔ evidenceNC-SUPPLIER-not-implemented

Operational Evaluation

Artefacts in this category. Defined is a cited policy (HOW). Implemented is in-pack or named operating evidence. Effective is the kernel join or HITL effectiveness. Ratings are yes, no, or partially. DK or NA when this pack has no data.

ArtifactDefinedImplementedEffectiveArtefact
SRPyesNADKArtefact
SINVNAyesDKArtefact
SSAQNAyesDKArtefact
CSSAQNAyesnoArtefact

What we found

What this pack actually cited for each artefact. Counts are from this pack. Presence is not a PASS. No ISO shall-text.

SRP

SRP is in-pack in Volume 1. Defined yes, implemented NA, effective DK. Missing layers are explained on the artefact page — not joined from another book.

SINV

SINV is in-pack in Volume 1. Defined NA, implemented yes, effective DK. Missing layers are explained on the artefact page — not joined from another book.

SSAQ

SSAQ is in-pack in Volume 1. Defined NA, implemented yes, effective DK. Missing layers are explained on the artefact page — not joined from another book.

CSSAQ

CSSAQ is in-pack in Volume 1. Defined NA, implemented yes, effective no. A nonconformity cites this artefact. Missing layers are explained on the artefact page — not joined from another book.

Supplier inventory

No inventory rows in the examined Example JSON.

Tags in this report

Volume

Vol. 1Vol. 2Vol. 5

Presence

installednot installed

Kind

policycomparison aassetinventoryprocesshitlother-book

Tier

Premium

Check installation

What is installed here. Extra volumes are optional and do not change Ready. Update re-runs the check.

CheckResult
Webserver…
Python…
Volumes…
Scripts…
Ready…
Working directory…
Last update…