{
  "schemaVersion": "artifactDefinition.v2",
  "definitionId": "AI.artifactDefinition.v2",
  "artifactId": "AI",
  "title": "Asset Inventory",
  "artifactType": "Inventory",
  "format": "xlsx",
  "productTier": "Basic",
  "definitionRole": "contract",
  "sourceModel": {
    "body": "canonical human-readable register template/example maintained in the Artifact Candidate page",
    "jsonDefinition": "machine-readable register contract and validation model",
    "jsonExample": "curated realistic register data fixture",
    "mdDefinition": "generated output",
    "mdExample": "generated output"
  },
  "purpose": "Define the audit-ready Asset Inventory register contract, including required columns, controlled values, example-data expectations, review logic, lifecycle linkage, and completeness decision.",
  "hintPolicy": {
    "storage": "Each content section stores its hint in this JSON Definition.",
    "visualization": "Generated Office and Markdown outputs render each hint as a visually highlighted callout after the section content.",
    "minimumRule": "Every content section except formal title/document-control sections should have one context-specific hint. Hints must not be generic or mechanically repeated.",
    "format": {
      "requiredParts": [
        "short practical explanation",
        "detailed book reference"
      ]
    }
  },
  "controlledValues": {
    "assetType": [
      "Application",
      "SaaS application",
      "Information repository",
      "Code repository",
      "Identity service",
      "Database",
      "Device",
      "Infrastructure service",
      "Supplier-hosted platform",
      "Documentation repository"
    ],
    "classification": [
      "Public",
      "Internal",
      "Confidential",
      "Restricted"
    ],
    "ciaNeed": [
      "Low",
      "Medium",
      "High"
    ],
    "yesNo": [
      "Yes",
      "No",
      "Not applicable"
    ],
    "lifecycleStatus": [
      "Planned",
      "Active",
      "Changed",
      "Under review",
      "Retiring",
      "Retired",
      "Archived"
    ],
    "reviewResult": [
      "Confirmed",
      "Updated",
      "Confirmed with action",
      "Gap identified",
      "Retired",
      "Exception approved"
    ],
    "completenessStatus": [
      "Complete",
      "Conditionally complete",
      "Pending",
      "Not audit-ready"
    ],
    "evidenceQuality": [
      "Complete",
      "Partial",
      "Missing",
      "Not applicable"
    ]
  },
  "sections": [
    {
      "order": 1,
      "id": "title_page",
      "title": "Title Page",
      "contentType": "metadata",
      "required": true,
      "hint": null,
      "fields": [
        {
          "name": "Register Title",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Register ID",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Version",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Status",
          "type": "select",
          "required": "yes",
          "valueSet": "domain.status.generic",
          "options": [
            "Draft",
            "In Progress",
            "Under Review",
            "Approved",
            "Closed",
            "Deferred"
          ],
          "validation": {
            "allowBlank": false,
            "errorTitle": "Invalid value",
            "error": "Select a value from the list."
          }
        },
        {
          "name": "Organization",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Owner",
          "type": "select",
          "required": "yes",
          "valueSet": "domain.owner",
          "options": [
            "ISMS Manager",
            "Control Owner",
            "Risk Owner",
            "Process Owner",
            "Asset Owner",
            "IT Security",
            "HR",
            "Legal",
            "Executive Management",
            "Internal Audit"
          ],
          "validation": {
            "allowBlank": false,
            "errorTitle": "Invalid value",
            "error": "Select a value from the list."
          }
        },
        {
          "name": "Approver",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Classification",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Effective Date",
          "type": "date",
          "required": "yes"
        },
        {
          "name": "Next Review Date",
          "type": "date",
          "required": "yes"
        }
      ],
      "intro": "Use this section to identify the register and its control context."
    },
    {
      "order": 2,
      "id": "abstract",
      "title": "Abstract",
      "contentType": "narrative",
      "required": true,
      "requiredContent": "Explain that the Asset Inventory is the authoritative register for information assets, ownership, classification, CIA needs, hosting, suppliers, personal-data relevance, lifecycle status, review dates, linked risks, access dependencies, and evidence references.",
      "hint": {
        "text": "Use this register as the evidence backbone for asset ownership, classification, access control, supplier dependency, continuity, and risk assessment.",
        "bookReference": "Volume 1, S-00-06-00 Performance, Monitoring & Audit (Clau"
      }
    },
    {
      "order": 3,
      "id": "document_control",
      "title": "Document Control",
      "contentType": "control_table",
      "required": true,
      "hint": null,
      "fields": [
        {
          "name": "Purpose",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Used by",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Maintained by",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Evidence role",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "ISO reference",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Review cadence",
          "type": "text",
          "required": "yes"
        }
      ],
      "intro": "Record ownership, use, maintenance, evidence role, ISO references, and review cadence."
    },
    {
      "order": 4,
      "id": "instructions",
      "title": "Instructions",
      "contentType": "ordered_list",
      "required": true,
      "intro": "Complete the Working sheets using the example tabs as a model. Follow the workbook usage rules below.",
      "requiredContent": "1. Register every in-scope information asset, system, repository, data store, critical service, and relevant supporting infrastructure.\n2. Assign a business owner, asset owner, technical custodian, and review owner for every active asset.\n3. Record classification, confidentiality, integrity, and availability needs using controlled values.\n4. Link assets to business process, hosting location, supplier, personal-data processing relevance, risks, access controls, backup or continuity dependencies, and evidence.\n5. Maintain lifecycle status, last review date, next review date, and review result.\n6. Treat missing owner, missing classification, missing review date, or missing evidence for critical assets as audit blockers.\n7. Retire or archive assets only when ownership, data retention, access removal, and evidence requirements have been closed.",
      "hint": {
        "text": "A good asset inventory is not just a list of systems. It explains why each asset matters, who is accountable, which controls depend on it, and where the audit evidence is stored.",
        "bookReference": "Volume 1, S-00-06-00 Performance, Monitoring & Audit (Clau"
      }
    },
    {
      "order": 5,
      "id": "register_schema",
      "title": "Register schema",
      "contentType": "schema_table",
      "required": true,
      "intro": "Define the columns that must exist in the Asset Inventory workbook.",
      "columns": [
        {
          "name": "Column",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Type",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Required",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Description",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Example",
          "type": "text",
          "required": "yes"
        }
      ],
      "requiredColumns": [
        "Asset ID",
        "Asset name",
        "Asset type",
        "Business process",
        "Business owner",
        "Asset owner",
        "Technical custodian",
        "Classification",
        "Confidentiality need",
        "Integrity need",
        "Availability need",
        "Location / hosting",
        "Supplier",
        "Contains personal data?",
        "Related risk",
        "Related access control",
        "Backup / continuity dependency",
        "Lifecycle status",
        "Last review date",
        "Next review date",
        "Review result",
        "Evidence reference",
        "Notes"
      ],
      "hint": {
        "text": "The schema should make links to risk, access, supplier, backup, classification, and evidence explicit. These links are what make the register useful during audit sampling.",
        "bookReference": "Volume 1, S-00-06-00 Performance, Monitoring & Audit (Clau"
      }
    },
    {
      "order": 6,
      "id": "asset_inventory_entries",
      "title": "Asset inventory entries",
      "contentType": "register_table",
      "required": true,
      "intro": "Maintain one row per asset or asset group using realistic ISMS object information.",
      "columns": [
        {
          "name": "Asset ID",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Asset name",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Asset type",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Business process",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Business owner",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Asset owner",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Technical custodian",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Classification",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Confidentiality need",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Integrity need",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Availability need",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Location / hosting",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Supplier",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Contains personal data?",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Related risk",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Related access control",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Backup / continuity dependency",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Lifecycle status",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Last review date",
          "type": "date",
          "required": "yes"
        },
        {
          "name": "Next review date",
          "type": "date",
          "required": "yes"
        },
        {
          "name": "Review result",
          "type": "select",
          "required": "yes",
          "valueSet": "domain.reviewResult",
          "options": [
            "Pass",
            "Pass with observations",
            "Fail",
            "Deferred"
          ],
          "validation": {
            "allowBlank": false,
            "errorTitle": "Invalid value",
            "error": "Select a value from the list."
          }
        },
        {
          "name": "Evidence reference",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Notes",
          "type": "text",
          "required": "yes"
        }
      ],
      "minimumExampleRows": 6,
      "hint": {
        "text": "Use enough example rows to show different asset types and control implications: application, SaaS, repository, identity service, HR data store, and audit evidence repository.",
        "bookReference": "Volume 1, S-00-06-00 Performance, Monitoring & Audit (Clau"
      }
    },
    {
      "order": 7,
      "id": "review_and_maintenance",
      "title": "Review and maintenance",
      "contentType": "review_table",
      "required": true,
      "intro": "Define how the Asset Inventory is reviewed and maintained over time.",
      "columns": [
        {
          "name": "Review item",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Owner",
          "type": "select",
          "required": "yes",
          "valueSet": "domain.owner",
          "options": [
            "ISMS Manager",
            "Control Owner",
            "Risk Owner",
            "Process Owner",
            "Asset Owner",
            "IT Security",
            "HR",
            "Legal",
            "Executive Management",
            "Internal Audit"
          ],
          "validation": {
            "allowBlank": false,
            "errorTitle": "Invalid value",
            "error": "Select a value from the list."
          }
        },
        {
          "name": "Frequency / trigger",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Required evidence",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Example evidence reference",
          "type": "text",
          "required": "yes"
        }
      ],
      "hint": {
        "text": "Review evidence should prove that the register is actively maintained. A stale asset inventory is weak evidence even if the column structure is good.",
        "bookReference": "Volume 1, S-00-06-00 Performance, Monitoring & Audit (Clau"
      }
    },
    {
      "order": 8,
      "id": "lifecycle_linkage",
      "title": "Lifecycle linkage",
      "contentType": "linkage_table",
      "required": true,
      "intro": "Link the Asset Inventory to operational and assurance registers that depend on accurate asset information.",
      "columns": [
        {
          "name": "Linked record",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Reference",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Owner",
          "type": "select",
          "required": "yes",
          "valueSet": "domain.owner",
          "options": [
            "ISMS Manager",
            "Control Owner",
            "Risk Owner",
            "Process Owner",
            "Asset Owner",
            "IT Security",
            "HR",
            "Legal",
            "Executive Management",
            "Internal Audit"
          ],
          "validation": {
            "allowBlank": false,
            "errorTitle": "Invalid value",
            "error": "Select a value from the list."
          }
        },
        {
          "name": "Status",
          "type": "select",
          "required": "yes",
          "valueSet": "domain.status.generic",
          "options": [
            "Draft",
            "In Progress",
            "Under Review",
            "Approved",
            "Closed",
            "Deferred"
          ],
          "validation": {
            "allowBlank": false,
            "errorTitle": "Invalid value",
            "error": "Select a value from the list."
          }
        }
      ],
      "hint": {
        "text": "Asset inventory evidence becomes much stronger when every critical asset can be traced to risks, access, suppliers, continuity, and audit evidence.",
        "bookReference": "Volume 1, S-00-06-00 Performance, Monitoring & Audit (Clau"
      }
    },
    {
      "order": 9,
      "id": "register_completeness_decision",
      "title": "Register completeness decision",
      "contentType": "decision_table",
      "required": true,
      "intro": "Record whether the Asset Inventory is complete enough to support audit sampling.",
      "fields": [
        {
          "name": "Completeness result",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Reviewed by",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Open blocker decision",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Critical assets without owner",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Critical assets without classification",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Critical assets without review date",
          "type": "date",
          "required": "yes"
        },
        {
          "name": "Critical assets without evidence reference",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Final status",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Decision date",
          "type": "date",
          "required": "yes"
        },
        {
          "name": "Evidence reference",
          "type": "text",
          "required": "yes"
        }
      ],
      "hint": {
        "text": "A completeness decision makes the register auditable. It shows whether missing owners, classification, reviews, or evidence links create blockers.",
        "bookReference": "Volume 1, S-00-06-00 Performance, Monitoring & Audit (Clau"
      }
    },
    {
      "order": 10,
      "id": "evidence_and_records",
      "title": "Evidence and records",
      "contentType": "evidence_table",
      "required": true,
      "intro": "Related records live in the companion documents named below. This file cites them by their approved version. It does not copy their content. The Owner named on the cover is accountable for those live records."
    },
    {
      "order": 11,
      "id": "external_references",
      "title": "References",
      "contentType": "reference_table",
      "required": true
    }
  ],
  "validationRules": [
    "Body MD, JSON Definition, and JSON Example must use the same section order and compatible section titles.",
    "The Asset inventory entries section must include all requiredColumns from the Register schema section.",
    "JSON Example and Body examples must include at least six realistic asset rows covering different asset types.",
    "Every active critical asset must have an owner, classification, CIA needs, lifecycle status, review date, and evidence reference.",
    "Every critical application or SaaS asset should link to at least one related risk, access control, backup or continuity dependency, and evidence reference where applicable.",
    "Do not include a separate Book reference chapter; book linkage belongs inside section hints.",
    "Example data must look realistic and audit-ready, but must not contain real personal data.",
    "JSON Example must contain definitionRef pointing to AI.artifactDefinition.v2."
  ],
  "instructionsForGenerator": [
    "Use this JSON Definition as the machine-readable register contract.",
    "Use JSON Example as the curated realistic register data source.",
    "Use Body MD as the canonical human-readable source.",
    "Generate MD Definition and MD Example downstream; do not treat them as curated source relations.",
    "Render section intros before content and section hints as callouts after content.",
    "Render decision-style single-record sections vertically as Field/Value tables and multi-record register sections horizontally."
  ],
  "enrichment": {
    "source": "Contract.json",
    "method": "curated-json",
    "note": "Completes Contract JSON from MD-only schema/sections, removes duplicate alias sections, and normalizes string columns into structured column objects."
  },
  "editorialStandard": {
    "isoAnchors": [
      {
        "label": "ISO/IEC 27001:2022",
        "href": "https://www.iso.org/standard/82875.html",
        "role": "Normative source this artifact implements or cites."
      },
      {
        "label": "ISO/IEC 27001:2022 8.1",
        "href": "https://www.iso.org/standard/82875.html",
        "role": "Operational planning and control this register evidences."
      },
      {
        "label": "ISO/IEC 27001:2022 7.5",
        "href": "https://www.iso.org/standard/82875.html",
        "role": "Documented information: identify, review and cite this workbook by version."
      }
    ],
    "bookSources": [
      {
        "series": "ISO 27001 for Software Companies",
        "volume": 1,
        "volumeTitle": "Building the ISMS",
        "chapterId": "S-00-06-00",
        "chapterTitle": "Performance, Monitoring & Audit (Clau",
        "primary": true,
        "role": "Primary operating chapter for this companion artifact.",
        "href": "https://www.amazon.com/dp/9789908983448"
      },
      {
        "series": "ISO 27001 for Software Companies",
        "volume": 1,
        "volumeTitle": "Building the ISMS",
        "chapterId": "S-00-03-00",
        "chapterTitle": "Planning, Risk & Objectives (Clause 6)",
        "primary": false,
        "role": "Documented information, review and version discipline.",
        "href": "https://www.amazon.com/dp/9789908983448"
      }
    ],
    "acronyms": [
      {
        "abbr": "ISMS",
        "longForm": "Information Security Management System"
      },
      {
        "abbr": "SaaS",
        "longForm": "Software as a Service"
      },
      {
        "abbr": "CIA",
        "longForm": "Confidentiality, Integrity, and Availability"
      },
      {
        "abbr": "CI/CD",
        "longForm": "Continuous Integration / Continuous Delivery"
      },
      {
        "abbr": "CI",
        "longForm": "Continuous Integration"
      },
      {
        "abbr": "CD",
        "longForm": "Continuous Delivery"
      },
      {
        "abbr": "AI",
        "longForm": "Artificial Intelligence"
      },
      {
        "abbr": "BCP",
        "longForm": "Business Continuity Plan"
      },
      {
        "abbr": "CISO",
        "longForm": "Chief Information Security Officer"
      },
      {
        "abbr": "CRM",
        "longForm": "Customer Relationship Management"
      },
      {
        "abbr": "DR",
        "longForm": "Disaster Recovery"
      },
      {
        "abbr": "DRP",
        "longForm": "Disaster Recovery Plan"
      },
      {
        "abbr": "HR",
        "longForm": "Human Resources"
      },
      {
        "abbr": "IAM",
        "longForm": "Identity and Access Management"
      },
      {
        "abbr": "JSON",
        "longForm": "JavaScript Object Notation"
      },
      {
        "abbr": "SDLC",
        "longForm": "Software Development Life Cycle"
      }
    ],
    "must": [
      "Keep one live row per record on Working sheets. Do not merge several cases into one row.",
      "Example sheets must contain realistic Arcfield rows for every required sheet. Empty required cells are not an example."
    ],
    "mustNot": [
      "Do not invent live rows in the renderer. Example data lives in the Example JSON.",
      "Do not treat Ex example tabs as working sheets. Do not put live data on system sheets."
    ],
    "softwareCompanyAdaptations": [
      "Use Arcfield as the worked example (cover variant A).",
      "Name SaaS, CI/CD, privileged access or supplier interfaces in example rows where they affect this register."
    ],
    "exampleWorkbook": {
      "workedExampleOrg": "Arcfield",
      "requiredSheets": [
        "register_schema",
        "asset_inventory_entries",
        "review_and_maintenance",
        "lifecycle_linkage",
        "register_completeness_decision"
      ],
      "minExampleRows": 6,
      "coverFromExample": true
    }
  },
  "editorialContractId": "editorial.xlsx.register.v1",
  "contentContractId": "content.register.inventory.v1"
}
