{
  "schemaVersion": "artifactExample.v2",
  "artifactId": "CR",
  "title": "Context Register",
  "definitionRef": {
    "artifactId": "CR",
    "definitionSchemaVersion": "artifactDefinition.v2",
    "definitionId": "CR.artifactDefinition.v2",
    "title": "Context Register"
  },
  "organization": "Arcfield",
  "sections": [
    {
      "id": "title_page",
      "title": "Title Page",
      "values": {
        "Register Title": "Context Register",
        "Register ID": "CR-REG-001",
        "Version": "1.1",
        "Status": "Approved",
        "Organization": "Arcfield",
        "Owner": "ISMS Manager",
        "Approver": "Top Management",
        "Classification": "Internal",
        "Effective Date": "2026-09-11",
        "Next Review Date": "2027-09-11"
      },
      "items": [
        "Register Title: Context Register",
        "Register ID: CR-REG-001",
        "Version: 1.1",
        "Status: Approved",
        "Organization: Arcfield",
        "Owner: ISMS Manager",
        "Approver: Top Management",
        "Classification: Internal",
        "Effective Date: 2026-09-11",
        "Next Review Date: 2027-09-11"
      ],
      "contentType": "metadata"
    },
    {
      "id": "abstract",
      "title": "Abstract",
      "text": "This example records Arcfield internal and external context issues that affect ISMS scope, risks, objectives, interested parties, supplier controls and management review. Rows are the 11 September 2026 operating sample of the certified Arcfield Platform ISMS in the surveillance cycle after certificate ARC-ISMS-2025-001.",
      "contentType": "narrative"
    },
    {
      "id": "document_control",
      "title": "Document Control",
      "rows": [
        {
          "Property": "Purpose",
          "Value": "Maintain context issues relevant to the ISMS."
        },
        {
          "Property": "Used by",
          "Value": "ISMS Manager, Top Management, Risk Manager"
        },
        {
          "Property": "Maintained by",
          "Value": "ISMS Manager"
        },
        {
          "Property": "Evidence role",
          "Value": "Clause 4.1 context evidence"
        },
        {
          "Property": "ISO reference",
          "Value": "ISO/IEC 27001:2022 Clause 4.1"
        },
        {
          "Property": "Review cadence",
          "Value": "Quarterly and after major organizational or external changes"
        }
      ],
      "contentType": "control_table"
    },
    {
      "id": "instructions",
      "title": "Instructions",
      "items": [
        "Record internal and external issues that affect the ISMS.",
        "Explain why each issue matters for security, risk, scope or objectives.",
        "Assign an owner and monitoring method.",
        "Link each issue to evidence and review dates.",
        "Feed relevant issues into the risk register and management review.",
        "Use sheets ending in “Ex” as read-only examples. Enter live data only on the matching “Wk” (Working) sheets.",
        "Every operative list is an Excel Table with frozen headers and filters. Add new rows on the next empty worksheet row beneath the table so Excel expands it — do not leave blank rows inside the table.",
        "Where a column offers a dropdown, choose a value from the list (Status, Owner role, Priority, Severity, Likelihood, Impact, Applicability, Evidence Status, Review Result). Do not invent free-text variants.",
        "Enter dates as YYYY-MM-DD. Date columns are validated and formatted accordingly.",
        "Review the Flag columns (Overdue, Review Due, Missing Owner, Missing Evidence). They calculate automatically and highlight gaps for follow-up.",
        "Keep Cover, Legal, Book, Lists and Metadata unchanged. System sheets are protected on purpose."
      ],
      "contentType": "ordered_list"
    },
    {
      "id": "context_register",
      "title": "Context register",
      "schemaRef": {
        "definitionId": "CR.artifactDefinition.v2",
        "sectionId": "context_register",
        "columnsRef": "sections.context_register.columns"
      },
      "rows": [
        {
          "Context ID": "CR-001",
          "Issue Type": "External",
          "Issue": "Customers increasingly require ISO 27001 certification before contract renewal.",
          "Relevance to ISMS": "Certification readiness is a strategic sales and trust requirement.",
          "Affected objective or risk": "Objective OBJ-001; Risk RISK-2026-018",
          "Owner": "CEO",
          "Monitoring method": "Quarterly customer and sales review",
          "Review frequency": "Quarterly",
          "Status": "Active",
          "Evidence reference": "MR-2026-Q3",
          "Next review date": "2026-11-29"
        },
        {
          "Context ID": "CR-002",
          "Issue Type": "External",
          "Issue": "Cloud supplier concentration affects service resilience.",
          "Relevance to ISMS": "Supplier dependency influences risk treatment and business continuity planning.",
          "Affected objective or risk": "RISK-2026-018",
          "Owner": "Supplier Manager",
          "Monitoring method": "Critical supplier review",
          "Review frequency": "Quarterly",
          "Status": "Active",
          "Evidence reference": "SINV-CLOUDHOST-2026-Q3",
          "Next review date": "2026-10-15"
        },
        {
          "Context ID": "CR-003",
          "Issue Type": "Internal",
          "Issue": "Engineering team releases product changes every two weeks.",
          "Relevance to ISMS": "Change control and secure development controls must fit agile release cadence.",
          "Affected objective or risk": "RISK-2026-027",
          "Owner": "Engineering Lead",
          "Monitoring method": "Release and change review",
          "Review frequency": "Monthly",
          "Status": "Active",
          "Evidence reference": "CMP-2026-Q3",
          "Next review date": "2026-09-30"
        },
        {
          "Context ID": "CR-004",
          "Issue Type": "Internal",
          "Issue": "Remote-first workforce uses managed endpoints and SaaS services.",
          "Relevance to ISMS": "Remote work affects endpoint security, access control and awareness needs.",
          "Affected objective or risk": "RISK-2026-031",
          "Owner": "IT Operations Manager",
          "Monitoring method": "Endpoint compliance report",
          "Review frequency": "Monthly",
          "Status": "Active",
          "Evidence reference": "MDM-2026-Q3",
          "Next review date": "2026-09-30"
        },
        {
          "Context ID": "CR-005",
          "Issue Type": "External",
          "Issue": "GDPR obligations apply to customer and employee personal data.",
          "Relevance to ISMS": "Privacy requirements influence records, access controls and supplier assurance.",
          "Affected objective or risk": "RISK-2026-033",
          "Owner": "Privacy Lead",
          "Monitoring method": "Legal register review",
          "Review frequency": "Quarterly",
          "Status": "Active",
          "Evidence reference": "LRR-2026-Q3",
          "Next review date": "2026-11-20"
        }
      ],
      "contentType": "register_table"
    },
    {
      "id": "review_decision",
      "title": "Review decision",
      "values": {
        "Review result": "Context issues reviewed and reflected in risks, objectives and supplier controls",
        "Open issues": 5,
        "Reviewed by": "ISMS Manager",
        "Decision date": "2026-08-29",
        "Evidence reference": "CR-REVIEW-2026-Q3"
      },
      "rows": [
        {
          "Field": "Review result",
          "Value": "Context issues reviewed and reflected in risks, objectives and supplier controls"
        },
        {
          "Field": "Open issues",
          "Value": "5"
        },
        {
          "Field": "Reviewed by",
          "Value": "ISMS Manager"
        },
        {
          "Field": "Decision date",
          "Value": "2026-08-29"
        },
        {
          "Field": "Evidence reference",
          "Value": "CR-REVIEW-2026-Q3"
        }
      ],
      "contentType": "decision_table"
    },
    {
      "id": "external_references",
      "title": "References",
      "groups": [
        {
          "text": "Cite these sources from workshops and audits. This list names ISO clauses, book chapters and companion artifacts used by this file."
        },
        {
          "rows": [
            {
              "Kind": "ISO",
              "Reference": "ISO/IEC 27001:2022 4.1",
              "How this document uses it": "Normative source this artifact implements or cites.",
              "href": "https://www.iso.org/standard/82875.html"
            },
            {
              "Kind": "Book",
              "Reference": "Building the ISMS, Context of the Organization (Clause 4)",
              "How this document uses it": "Primary operating chapter for this companion artifact.",
              "href": "https://www.amazon.com/dp/9789908983448"
            },
            {
              "Kind": "Artifact",
              "Reference": "ISO Information Security Objectives (Building the ISMS, Information Security Policies & Risk Management)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/dp/9789908983448"
            },
            {
              "Kind": "Artifact",
              "Reference": "CMP Change Management Policy & Procedure (Building the ISMS, Operation & Change Management (Clause 8))",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/dp/9789908983448"
            },
            {
              "Kind": "Artifact",
              "Reference": "LRR Legal, Regulatory and Contractual Requirements Register (Building the ISMS, Legal, Regulatory & Contractual Requirements)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/dp/9789908983448"
            },
            {
              "Kind": "Artifact",
              "Reference": "SINV Supplier Inventory (Building the ISMS, Supplier Security & Third-party Risk Management)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/dp/9789908983448"
            }
          ]
        }
      ],
      "contentType": "reference_table"
    }
  ],
  "enrichment": {
    "source": "Example.json",
    "method": "curated-json",
    "note": "Completes Example JSON with renderer-native sections and generalized groups; no mdSource helper fields."
  },
  "snapshotRef": {
    "snapshotId": "arcfield.platform.surv.2026-09-11",
    "schemaVersion": "evidenceSnapshot.v1"
  },
  "scenarioRef": {
    "githubIssue": 64,
    "crId": "CR-TYPE-ARCFIELD-001",
    "family": "Register",
    "role": "Operating sample of the 11 September 2026 freeze"
  }
}
