{
  "schemaVersion": "artifactExample.v2",
  "artifactId": "CAR",
  "title": "Corrective Actions Register",
  "definitionRef": {
    "artifactId": "CAR",
    "definitionSchemaVersion": "artifactDefinition.v2",
    "definitionId": "CAR.artifactDefinition.v2",
    "title": "Corrective Actions Register"
  },
  "organization": "Arcfield",
  "sections": [
    {
      "id": "title_page",
      "title": "Title Page",
      "values": {
        "Register Title": "Corrective Actions Register",
        "Register ID": "CAR-REG-001",
        "Version": "1.1",
        "Status": "Approved",
        "Organization": "Arcfield",
        "Owner": "ISMS Manager",
        "Approver": "Top Management",
        "Classification": "Internal",
        "Effective Date": "2026-09-11",
        "Next Review Date": "2027-09-11"
      },
      "items": [
        "Register Title: Corrective Actions Register",
        "Register ID: CAR-REG-001",
        "Version: 1.1",
        "Status: Approved",
        "Organization: Arcfield",
        "Owner: ISMS Manager",
        "Approver: Top Management",
        "Classification: Internal",
        "Effective Date: 2026-09-11",
        "Next Review Date: 2027-09-11"
      ],
      "contentType": "metadata"
    },
    {
      "id": "abstract",
      "title": "Abstract",
      "text": "This example tracks Arcfield nonconformities, corrections, root causes, corrective actions, effectiveness checks, ownership, deadlines, closure and evidence. Rows are the 11 September 2026 operating sample of the certified Arcfield Platform ISMS in the surveillance cycle after certificate ARC-ISMS-2025-001.",
      "contentType": "narrative"
    },
    {
      "id": "document_control",
      "title": "Document Control",
      "rows": [
        {
          "Property": "Purpose",
          "Value": "Track nonconformities and corrective actions through root cause, implementation, effectiveness check and closure."
        },
        {
          "Property": "Used by",
          "Value": "ISMS Manager, Internal Auditor, Process Owners, Top Management"
        },
        {
          "Property": "Maintained by",
          "Value": "ISMS Manager"
        },
        {
          "Property": "Evidence role",
          "Value": "Mandatory ISO 27001 record"
        },
        {
          "Property": "ISO reference",
          "Value": "ISO/IEC 27001:2022 Clause 10.1 and 10.2"
        },
        {
          "Property": "Review cadence",
          "Value": "Monthly while actions are open; before management review"
        }
      ],
      "contentType": "control_table"
    },
    {
      "id": "instructions",
      "title": "Instructions",
      "items": [
        "Register every nonconformity and significant improvement action.",
        "Record the immediate correction separately from the root-cause corrective action.",
        "Identify root cause before closing the action.",
        "Link implementation evidence.",
        "Perform and document an effectiveness check before final closure.",
        "Escalate overdue or ineffective actions to management review.",
        "Use sheets ending in “Ex” as read-only examples. Enter live data only on the matching “Wk” (Working) sheets.",
        "Every operative list is an Excel Table with frozen headers and filters. Add new rows on the next empty worksheet row beneath the table so Excel expands it — do not leave blank rows inside the table.",
        "Where a column offers a dropdown, choose a value from the list (Status, Owner role, Priority, Severity, Likelihood, Impact, Applicability, Evidence Status, Review Result). Do not invent free-text variants.",
        "Enter dates as YYYY-MM-DD. Date columns are validated and formatted accordingly.",
        "Review the Flag columns (Overdue, Review Due, Missing Owner, Missing Evidence). They calculate automatically and highlight gaps for follow-up.",
        "Keep Cover, Legal, Book, Lists and Metadata unchanged. System sheets are protected on purpose.",
        "Do not close an action until Evidence reference and effectiveness checks are filled; watch Missing Evidence / Overdue flags on the Working sheet."
      ],
      "contentType": "ordered_list"
    },
    {
      "id": "corrective_actions_register",
      "title": "Corrective actions register",
      "schemaRef": {
        "definitionId": "CAR.artifactDefinition.v2",
        "sectionId": "corrective_actions_register",
        "columnsRef": "sections.corrective_actions_register.columns"
      },
      "rows": [
        {
          "NC ID": "CAR-001",
          "Date raised": "2026-08-05",
          "Source": "Internal audit",
          "Raised by": "Internal Auditor",
          "Clause or control": "Clause 9.2",
          "Description of nonconformity": "Audit evidence for privileged access review was incomplete for two production systems.",
          "Grading": "Minor nonconformity",
          "Immediate correction": "Collected missing access review exports for the sampled systems.",
          "Root cause": "Access review checklist did not require evidence attachment before closure.",
          "Similar issues elsewhere": "Checked identity provider and source repository; no further missing exports found.",
          "Corrective action": "Update access review procedure and require evidence attachment before review closure.",
          "Action owner": "IT Operations Manager",
          "Target date": "2026-09-15",
          "Status": "In progress",
          "Implementation evidence": "Draft ARR review procedure update",
          "Effectiveness check": "Verify next quarterly review has evidence attached before sign-off.",
          "Effectiveness result": "Pending",
          "Closure date": "",
          "Evidence reference": "CAR-001-ACC-REV"
        },
        {
          "NC ID": "CAR-002",
          "Date raised": "2026-08-10",
          "Source": "Incident",
          "Raised by": "Incident Manager",
          "Clause or control": "A.5.24",
          "Description of nonconformity": "Incident communication checklist was not used during a low-severity security event.",
          "Grading": "Observation",
          "Immediate correction": "Completed retrospective communication log for the event.",
          "Root cause": "Incident runbook link was missing from the support escalation page.",
          "Similar issues elsewhere": "Reviewed three other runbooks; links were present.",
          "Corrective action": "Add runbook link to escalation page and brief support leads.",
          "Action owner": "Incident Manager",
          "Target date": "2026-09-05",
          "Status": "Implemented",
          "Implementation evidence": "IR-RB-2026 update and support briefing record",
          "Effectiveness check": "Confirm checklist use in next incident simulation.",
          "Effectiveness result": "Not due",
          "Closure date": "",
          "Evidence reference": "CAR-002-IR"
        },
        {
          "NC ID": "CAR-003",
          "Date raised": "2026-07-22",
          "Source": "Management review",
          "Raised by": "Top Management",
          "Clause or control": "Clause 7.2",
          "Description of nonconformity": "Competence evidence for two control owners was outdated.",
          "Grading": "Minor nonconformity",
          "Immediate correction": "Scheduled refresher training for affected roles.",
          "Root cause": "Training register did not trigger reminders before competence evidence expiry.",
          "Similar issues elsewhere": "Reviewed all control owner records; two additional reminders created.",
          "Corrective action": "Add expiry date and reminder column to competence matrix.",
          "Action owner": "HR Manager",
          "Target date": "2026-08-25",
          "Status": "Effectiveness check",
          "Implementation evidence": "CMTP-2026-Q3 updated with reminder dates",
          "Effectiveness check": "Verify reminders triggered for September training renewals.",
          "Effectiveness result": "Pending",
          "Closure date": "",
          "Evidence reference": "CAR-003-CMTP"
        },
        {
          "NC ID": "CAR-004",
          "Date raised": "2026-06-30",
          "Source": "Supplier review",
          "Raised by": "Supplier Manager",
          "Clause or control": "A.5.20",
          "Description of nonconformity": "One critical supplier agreement lacked explicit breach-notification timing.",
          "Grading": "Improvement",
          "Immediate correction": "Added interim manual notification requirement to supplier file.",
          "Root cause": "Contract review checklist did not include breach-notification timing.",
          "Similar issues elsewhere": "Checked top five suppliers; one similar gap found and logged separately.",
          "Corrective action": "Update supplier security clause checklist and request contract addendum.",
          "Action owner": "Supplier Manager",
          "Target date": "2026-09-30",
          "Status": "In progress",
          "Implementation evidence": "CSS-2026-001 checklist update",
          "Effectiveness check": "Confirm clause included in renewed agreement.",
          "Effectiveness result": "Pending",
          "Closure date": "",
          "Evidence reference": "CAR-004-SUP"
        },
        {
          "NC ID": "CAR-005",
          "Date raised": "2026-05-18",
          "Source": "Monitoring",
          "Raised by": "Security Lead",
          "Clause or control": "A.8.8",
          "Description of nonconformity": "Critical vulnerability remediation exceeded the defined SLA by three business days.",
          "Grading": "Minor nonconformity",
          "Immediate correction": "Patch deployed and vulnerability rescanned successfully.",
          "Root cause": "Patch owner was not assigned when the alert was triaged.",
          "Similar issues elsewhere": "Reviewed last 20 high and critical findings; no repeat pattern found.",
          "Corrective action": "Require owner assignment during vulnerability triage.",
          "Action owner": "Security Lead",
          "Target date": "2026-06-15",
          "Status": "Closed",
          "Implementation evidence": "VULN-2026-Q2 triage workflow updated",
          "Effectiveness check": "Next three critical findings had owners assigned within one business day.",
          "Effectiveness result": "Effective",
          "Closure date": "2026-07-20",
          "Evidence reference": "CAR-005-VULN"
        },
        {
          "NC ID": "CAR-2026-027",
          "Date raised": "2026-08-22",
          "Source": "Incident",
          "Raised by": "Incident Manager",
          "Clause or control": "A.8.9, A.8.32, A.5.15, A.5.37",
          "Description of nonconformity": "IL-005: Manual change outside the standard deployment workflow. Internal draft articles were world-readable for 12 minutes. No confirmed Arcfield Platform customer PII exposure.",
          "Grading": "Minor nonconformity",
          "Immediate correction": "Permission reverted and access logs preserved.",
          "Root cause": "Manual change outside the standard deployment workflow",
          "Similar issues elsewhere": "Storage ACL changes in support and backup buckets reviewed; CYB-CLM-2026-001 denied.",
          "Corrective action": "Require peer approval in the deployment workflow for storage ACL changes; do not treat cyber insurance as a substitute control.",
          "Action owner": "Engineering Lead",
          "Target date": "2026-10-15",
          "Status": "In progress",
          "Implementation evidence": "CHG-POST-2026-0822 plus workflow draft",
          "Effectiveness check": "Next storage-permission change uses the approved pipeline.",
          "Effectiveness result": "Pending",
          "Closure date": "",
          "Evidence reference": "CHG-POST-2026-0822"
        }
      ],
      "contentType": "register_table"
    },
    {
      "id": "closure_decision",
      "title": "Closure decision",
      "values": {
        "Review result": "Controlled with two open actions and one effectiveness check pending",
        "Open actions": 2,
        "Overdue actions": 0,
        "Actions awaiting effectiveness check": 1,
        "Closed actions": 1,
        "Reviewed by": "ISMS Manager",
        "Decision date": "2026-08-29",
        "Evidence reference": "CAR-REVIEW-2026-Q3"
      },
      "rows": [
        {
          "Field": "Review result",
          "Value": "Controlled with two open actions and one effectiveness check pending"
        },
        {
          "Field": "Open actions",
          "Value": "2"
        },
        {
          "Field": "Overdue actions",
          "Value": "0"
        },
        {
          "Field": "Actions awaiting effectiveness check",
          "Value": "1"
        },
        {
          "Field": "Closed actions",
          "Value": "1"
        },
        {
          "Field": "Reviewed by",
          "Value": "ISMS Manager"
        },
        {
          "Field": "Decision date",
          "Value": "2026-08-29"
        },
        {
          "Field": "Evidence reference",
          "Value": "CAR-REVIEW-2026-Q3"
        }
      ],
      "contentType": "decision_table"
    },
    {
      "id": "external_references",
      "title": "References",
      "groups": [
        {
          "text": "Cite these sources from workshops and audits. This list names ISO clauses, book chapters and companion artifacts used by this file."
        },
        {
          "rows": [
            {
              "Kind": "ISO",
              "Reference": "ISO/IEC 27001:2022",
              "How this document uses it": "Normative source this artifact implements or cites.",
              "href": "https://www.iso.org/standard/82875.html"
            },
            {
              "Kind": "ISO",
              "Reference": "ISO/IEC 27001:2022 10.1",
              "How this document uses it": "Normative source this artifact implements or cites.",
              "href": "https://www.iso.org/standard/82875.html"
            },
            {
              "Kind": "Book",
              "Reference": "Building the ISMS, Context of the Organization (Clause 4)",
              "How this document uses it": "Primary operating chapter for this companion artifact.",
              "href": "https://www.amazon.com/dp/9789908983448"
            },
            {
              "Kind": "Artifact",
              "Reference": "ISO Information Security Objectives (Building the ISMS, Information Security Policies & Risk Management)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/dp/9789908983448"
            },
            {
              "Kind": "Artifact",
              "Reference": "CMTP Competence Matrix and Training Plan (Building the ISMS, Security Awareness & Training Programs)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/dp/9789908983448"
            },
            {
              "Kind": "Artifact",
              "Reference": "ARR Access Rights Register (Secure Engineering, Access Control & Identity Management)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/dp/9789908983455"
            },
            {
              "Kind": "Artifact",
              "Reference": "CSS Contract Security Schedule (Building the ISMS, HR Security: Screening, Onboarding & Offboarding)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/dp/9789908983448"
            }
          ]
        }
      ],
      "contentType": "reference_table"
    }
  ],
  "enrichment": {
    "source": "Example.json",
    "method": "curated-json",
    "note": "Completes Example JSON with renderer-native sections and generalized groups; no mdSource helper fields."
  },
  "snapshotRef": {
    "snapshotId": "arcfield.platform.surv.2026-09-11",
    "schemaVersion": "evidenceSnapshot.v1"
  },
  "scenarioRef": {
    "githubIssue": 64,
    "crId": "CR-TYPE-ARCFIELD-001",
    "family": "Register",
    "role": "Operating sample of the 11 September 2026 freeze"
  }
}
