{
  "schemaVersion": "artifactExample.v2",
  "artifactId": "CSSAQ",
  "title": "Critical Supplier Security Assessment Questionnaire",
  "definitionRef": {
    "artifactId": "CSSAQ",
    "definitionSchemaVersion": "artifactDefinition.v2",
    "definitionId": "CSSAQ.artifactDefinition.v2",
    "title": "Critical Supplier Security Assessment Questionnaire"
  },
  "organization": "Arcfield",
  "sections": [
    {
      "id": "title_page",
      "title": "Title Page",
      "values": {
        "Form Title": "Critical Supplier Security Assessment Questionnaire",
        "Form ID": "CSSAQ-FRM-001",
        "Version": "1.1",
        "Status": "Approved",
        "Organization": "Arcfield",
        "Owner": "Supplier Manager",
        "Approver": "ISMS Manager",
        "Classification": "Internal",
        "Effective Date": "2026-09-11",
        "Next Review Date": "2027-09-11"
      },
      "items": [
        "Form Title: Critical Supplier Security Assessment Questionnaire",
        "Form ID: CSSAQ-FRM-001",
        "Version: 1.1",
        "Status: Approved",
        "Organization: Arcfield",
        "Owner: Supplier Manager",
        "Approver: ISMS Manager",
        "Classification: Internal",
        "Effective Date: 2026-09-11",
        "Next Review Date: 2027-09-11"
      ],
      "contentType": "metadata"
    },
    {
      "id": "abstract",
      "title": "Abstract",
      "text": "This example shows a critical supplier assessment for a cloud analytics hosting provider. It demonstrates how certification evidence, SOC 2 assurance, data-protection commitments, continuity evidence and subprocessor questions are tied to approval conditions. This form is the operating template used with Arcfield Platform freeze records in the surveillance cycle after certificate ARC-ISMS-2025-001.",
      "contentType": "narrative"
    },
    {
      "id": "document_control",
      "title": "Document Control",
      "contentType": "control_table"
    },
    {
      "id": "change_log",
      "title": "Revision history",
      "groups": [
        {
          "text": "A published change is a new row. Do not edit an approved version in place."
        },
        {
          "rows": [
            {
              "Version": "1.0",
              "Date": "2026-08-29",
              "Change": "Initial Arcfield Platform publication.",
              "Approved by": "ISMS Manager"
            },
            {
              "Version": "1.1",
              "Date": "2026-09-11",
              "Change": "Approved Arcfield worked example after the 11 September 2026 internal audit.",
              "Approved by": "ISMS Manager"
            }
          ]
        }
      ],
      "contentType": "revision_table"
    },
    {
      "id": "instructions",
      "title": "Instructions",
      "groups": [
        {
          "text": "Copy this file as the controlled Word master for your ISMS. The Arcfield identity fields on the cover are the approved worked example. Complete the steps below when you adopt the file for your organization."
        },
        {
          "items": [
            "Fill the cover identity fields (Organization, Version, Classification, Owner, Approver, Effective Date and Next Review Date) when you adopt this file. The Arcfield values shown here are the approved worked example.",
            "Issue your own version and a new Revision history row. Do not edit an approved version in place.",
            "Cite this approved version from related records. Do not copy this file into those records."
          ]
        }
      ],
      "contentType": "ordered_list"
    },
    {
      "id": "form_schema",
      "title": "Form schema",
      "fields": [
        "Assessment ID",
        "Supplier Legal Name",
        "Supplier Type",
        "Country or Region",
        "Service Provided",
        "Arcfield Business Owner",
        "Supplier Criticality",
        "Data Processed",
        "Security Contact Role",
        "Assessment Date",
        "Assessor Role",
        "Overall Assessment",
        "Status"
      ],
      "questionGroups": [
        "Certifications and Compliance",
        "Information Security Governance",
        "Access Control and Endpoint Security",
        "Data Protection",
        "Backup Continuity and Incident Management",
        "Subcontractors"
      ],
      "groups": [
        {
          "id": "worked_example",
          "heading": "Worked example",
          "level": 1,
          "text": "Use this worked record. Keep one accountable owner per row and cite this Document Control version from the live register.",
          "rows": [
            {
              "Field": "Assessment ID",
              "Type": "text",
              "Required": "yes",
              "Description": "Unique assessment reference.",
              "Example": "CSSAQ-2026-CLOUDHOST-001"
            },
            {
              "Field": "Supplier Legal Name",
              "Type": "text",
              "Required": "yes",
              "Description": "Supplier legal name.",
              "Example": "CloudHost Analytics Ltd."
            },
            {
              "Field": "Supplier Type",
              "Type": "text",
              "Required": "yes",
              "Description": "Supplier category.",
              "Example": "Cloud infrastructure provider"
            },
            {
              "Field": "Country or Region",
              "Type": "text",
              "Required": "yes",
              "Description": "Supplier operating region.",
              "Example": "EU and UK"
            },
            {
              "Field": "Service Provided",
              "Type": "text",
              "Required": "yes",
              "Description": "Service in scope.",
              "Example": "Cloud analytics hosting"
            },
            {
              "Field": "Arcfield Business Owner",
              "Type": "text",
              "Required": "yes",
              "Description": "Internal business owner.",
              "Example": "Cloud Service Owner"
            },
            {
              "Field": "Supplier Criticality",
              "Type": "select",
              "Required": "yes",
              "Description": "Critical, important or standard.",
              "Example": "Critical"
            },
            {
              "Field": "Data Processed",
              "Type": "text",
              "Required": "yes",
              "Description": "Data type processed.",
              "Example": "Customer support metadata"
            },
            {
              "Field": "Security Contact Role",
              "Type": "text",
              "Required": "yes",
              "Description": "Supplier security contact function.",
              "Example": "Security Assurance Manager"
            },
            {
              "Field": "Assessment Date",
              "Type": "date",
              "Required": "yes",
              "Description": "Assessment date.",
              "Example": "2026-08-29"
            },
            {
              "Field": "Assessor Role",
              "Type": "text",
              "Required": "yes",
              "Description": "Role completing assessment.",
              "Example": "Supplier Manager"
            },
            {
              "Field": "Overall Assessment",
              "Type": "select",
              "Required": "yes",
              "Description": "Approved, approved with conditions, not approved or further review.",
              "Example": "Approved with conditions"
            },
            {
              "Field": "Status",
              "Type": "select",
              "Required": "yes",
              "Description": "Draft, complete, open follow-up or approved.",
              "Example": "Open follow-up"
            }
          ]
        }
      ],
      "contentType": "form_schema"
    },
    {
      "id": "form_responses",
      "title": "Form responses",
      "schemaRef": {
        "definitionId": "CSSAQ.artifactDefinition.v2",
        "sectionId": "form_responses"
      },
      "values": {
        "Assessment ID": "CSSAQ-2026-CLOUDHOST-001",
        "Supplier Legal Name": "CloudHost Analytics Ltd.",
        "Supplier Type": "Cloud infrastructure and analytics provider",
        "Country or Region": "EU and UK",
        "Service Provided": "Cloud analytics hosting for customer support telemetry",
        "Arcfield Business Owner": "Cloud Service Owner",
        "Supplier Criticality": "Critical",
        "Data Processed": "Customer support metadata and operational logs",
        "Security Contact Role": "Supplier Security Assurance Manager",
        "Assessment Date": "2026-08-29",
        "Assessor Role": "Supplier Manager",
        "Overall Assessment": "Approved with conditions",
        "Status": "Open follow-up"
      },
      "answers": [
        {
          "Question ID": "CSSAQ-Q001",
          "Area": "Certifications and Compliance",
          "Question": "Does the supplier maintain ISO 27001 certification or equivalent assurance?",
          "Response": "Yes",
          "Evidence Reference": "CLOUDHOST-ISO27001-2026",
          "Follow-up Required": "No",
          "Notes": "Certificate current and scope covers hosting service."
        },
        {
          "Question ID": "CSSAQ-Q002",
          "Area": "Certifications and Compliance",
          "Question": "Does the supplier provide SOC 2 or equivalent cloud assurance?",
          "Response": "Yes",
          "Evidence Reference": "CLOUDHOST-SOC2-2026",
          "Follow-up Required": "No",
          "Notes": "SOC 2 report reviewed for access and operations controls."
        },
        {
          "Question ID": "CSSAQ-Q003",
          "Area": "Information Security Governance",
          "Question": "Are security roles, policies and management responsibilities defined?",
          "Response": "Yes",
          "Evidence Reference": "CLOUDHOST-SEC-OVERVIEW-2026",
          "Follow-up Required": "No",
          "Notes": "Governance overview accepted."
        },
        {
          "Question ID": "CSSAQ-Q004",
          "Area": "Access Control and Endpoint Security",
          "Question": "Is MFA enforced for privileged and remote access?",
          "Response": "Yes",
          "Evidence Reference": "CLOUDHOST-IAM-STATEMENT-2026",
          "Follow-up Required": "No",
          "Notes": "MFA control description included."
        },
        {
          "Question ID": "CSSAQ-Q005",
          "Area": "Data Protection",
          "Question": "Are data locations, subprocessors and deletion commitments documented?",
          "Response": "Partial",
          "Evidence Reference": "DPA-CLOUDHOST-2026",
          "Follow-up Required": "Yes",
          "Notes": "Subprocessor list current; deletion evidence requested."
        },
        {
          "Question ID": "CSSAQ-Q006",
          "Area": "Backup Continuity and Incident Management",
          "Question": "Are RTO/RPO and restore tests documented for the service?",
          "Response": "Partial",
          "Evidence Reference": "CLOUDHOST-BCP-2026",
          "Follow-up Required": "Yes",
          "Notes": "Restore test summary not yet provided."
        },
        {
          "Question ID": "CSSAQ-Q007",
          "Area": "Backup Continuity and Incident Management",
          "Question": "Are incident notification timelines contractually defined?",
          "Response": "Yes",
          "Evidence Reference": "CLOUDHOST-MSA-SEC-SCHEDULE-2026",
          "Follow-up Required": "No",
          "Notes": "Customer notification route defined."
        },
        {
          "Question ID": "CSSAQ-Q008",
          "Area": "Subcontractors",
          "Question": "Are critical subprocessors disclosed and controlled?",
          "Response": "Partial",
          "Evidence Reference": "CLOUDHOST-SUBPROCESSORS-2026",
          "Follow-up Required": "Yes",
          "Notes": "Need confirmation for monitoring subprocessor region."
        }
      ],
      "groups": [
        {
          "id": "introduction",
          "heading": "What this form is",
          "level": 1,
          "text": "This document is Arcfield's Critical Supplier Security Assessment Questionnaire. Assess critical suppliers against information security and compliance expectations before onboarding and during periodic review. It is not a methodology essay or the governing policy. This form applies to the Arcfield Platform (B2B SaaS for regulated fintech and health customers): production, customer data, CI/CD, privileged access and critical suppliers. Neighbouring records (SINV, ISO, BCP) cite this Document Control version. Do not copy these paragraphs into them."
        },
        {
          "id": "scope",
          "heading": "Scope",
          "level": 1,
          "text": "Use this table before you copy a rule into another record or exclude a duty from this file.",
          "rows": [
            {
              "In this file": "The rules, roles, worked Arcfield example and the records this file owns.",
              "Not in this file": "The ISMS boundary (ISS), Annex A selection (SoA) or live rows in SINV, ISO, BCP."
            },
            {
              "In this file": "Interfaces that must cite this Document Control version, including CI/CD, identity and suppliers where they affect CIA.",
              "Not in this file": "Live ISS scope rows, SoA applicability decisions, or neighbouring live registers. Those files keep their own approved versions; this file does not duplicate them."
            }
          ]
        },
        {
          "id": "terms",
          "heading": "Terms used here",
          "level": 1,
          "text": "These terms are local to this file. Expand every acronym on first use in the body.",
          "rows": [
            {
              "Term": "Check ID",
              "Meaning": "The stable identifier for one check or question. Do not reuse an ID for a different question."
            },
            {
              "Term": "Exception",
              "Meaning": "A time-bound, approved departure with expiry and a compensating control."
            },
            {
              "Term": "CIA",
              "Meaning": "Confidentiality, Integrity and Availability of in-scope information and services."
            },
            {
              "Term": "Document Control version",
              "Meaning": "The approved version cited from neighbouring records. Do not copy this body into those records."
            }
          ]
        },
        {
          "id": "evidence_and_attachments",
          "heading": "Evidence and attachments",
          "level": 1,
          "rows": [
            {
              "Evidence ID": "CSSAQ-EV-001",
              "Evidence Type": "Certification",
              "Description": "ISO 27001 certificate and scope statement.",
              "Owner": "Supplier Manager",
              "Evidence Reference": "CLOUDHOST-ISO27001-2026",
              "Retention Note": "Retain with critical supplier file."
            },
            {
              "Evidence ID": "CSSAQ-EV-002",
              "Evidence Type": "Assurance report",
              "Description": "SOC 2 Type II report covering hosted service operations.",
              "Owner": "Supplier Manager",
              "Evidence Reference": "CLOUDHOST-SOC2-2026",
              "Retention Note": "Retain with assurance package."
            },
            {
              "Evidence ID": "CSSAQ-EV-003",
              "Evidence Type": "Contract evidence",
              "Description": "Data processing addendum and security schedule.",
              "Owner": "Legal Counsel",
              "Evidence Reference": "DPA-CLOUDHOST-2026",
              "Retention Note": "Retain during supplier relationship."
            },
            {
              "Evidence ID": "CSSAQ-EV-004",
              "Evidence Type": "Follow-up request",
              "Description": "Deletion evidence, restore test and subprocessor-region confirmation.",
              "Owner": "Supplier Manager",
              "Evidence Reference": "SINV-CLOUDHOST-FU-2026-Q3",
              "Retention Note": "Close before renewal decision."
            }
          ]
        },
        {
          "id": "review_and_decision",
          "heading": "Review and decision",
          "level": 1,
          "rows": [
            {
              "Field": "Decision",
              "Value": "Approved with conditions"
            },
            {
              "Field": "Risk Rating",
              "Value": "High"
            },
            {
              "Field": "Approval Conditions",
              "Value": "Supplier must provide deletion evidence, latest restore-test summary and subprocessor-region confirmation."
            },
            {
              "Field": "Required Follow-up Actions",
              "Value": "Track three supplier actions in SINV and review before renewal."
            },
            {
              "Field": "Owner Role",
              "Value": "Supplier Manager"
            },
            {
              "Field": "Target Date",
              "Value": "2026-09-20"
            },
            {
              "Field": "Reviewed by",
              "Value": "ISMS Manager"
            },
            {
              "Field": "Decision date",
              "Value": "2026-08-29"
            },
            {
              "Field": "Evidence reference",
              "Value": "CSSAQ-2026-CLOUDHOST-001"
            }
          ]
        }
      ],
      "contentType": "form_response"
    },
    {
      "id": "evidence_and_attachments",
      "title": "Evidence and attachments",
      "schemaRef": {
        "definitionId": "CSSAQ.artifactDefinition.v2",
        "sectionId": "evidence_and_attachments",
        "fieldsRef": "sections.evidence_and_attachments.fields"
      },
      "groups": [
        {},
        {
          "rows": [
            {
              "Evidence ID": "CSSAQ-EV-001",
              "Evidence Type": "Certification",
              "Description": "ISO 27001 certificate and scope statement.",
              "Owner": "Supplier Manager",
              "Evidence Reference": "CLOUDHOST-ISO27001-2026",
              "Retention Note": "Retain with critical supplier file."
            },
            {
              "Evidence ID": "CSSAQ-EV-002",
              "Evidence Type": "Assurance report",
              "Description": "SOC 2 Type II report covering hosted service operations.",
              "Owner": "Supplier Manager",
              "Evidence Reference": "CLOUDHOST-SOC2-2026",
              "Retention Note": "Retain with assurance package."
            },
            {
              "Evidence ID": "CSSAQ-EV-003",
              "Evidence Type": "Contract evidence",
              "Description": "Data processing addendum and security schedule.",
              "Owner": "Legal Counsel",
              "Evidence Reference": "DPA-CLOUDHOST-2026",
              "Retention Note": "Retain during supplier relationship."
            },
            {
              "Evidence ID": "CSSAQ-EV-004",
              "Evidence Type": "Follow-up request",
              "Description": "Deletion evidence, restore test and subprocessor-region confirmation.",
              "Owner": "Supplier Manager",
              "Evidence Reference": "SINV-CLOUDHOST-FU-2026-Q3",
              "Retention Note": "Close before renewal decision."
            }
          ]
        }
      ],
      "contentType": "evidence_table"
    },
    {
      "id": "review_and_decision",
      "title": "Review and decision",
      "values": {
        "Decision": "Approved with conditions",
        "Risk Rating": "High",
        "Approval Conditions": "Supplier must provide deletion evidence, latest restore-test summary and subprocessor-region confirmation.",
        "Required Follow-up Actions": "Track three supplier actions in SINV and review before renewal.",
        "Owner Role": "Supplier Manager",
        "Target Date": "2026-09-20",
        "Reviewed by": "ISMS Manager",
        "Decision date": "2026-08-29",
        "Evidence reference": "CSSAQ-2026-CLOUDHOST-001"
      },
      "groups": [
        {},
        {
          "rows": [
            {
              "Field": "Decision",
              "Value": "Approved with conditions"
            },
            {
              "Field": "Risk Rating",
              "Value": "High"
            },
            {
              "Field": "Approval Conditions",
              "Value": "Supplier must provide deletion evidence, latest restore-test summary and subprocessor-region confirmation."
            },
            {
              "Field": "Required Follow-up Actions",
              "Value": "Track three supplier actions in SINV and review before renewal."
            },
            {
              "Field": "Owner Role",
              "Value": "Supplier Manager"
            },
            {
              "Field": "Target Date",
              "Value": "2026-09-20"
            },
            {
              "Field": "Reviewed by",
              "Value": "ISMS Manager"
            },
            {
              "Field": "Decision date",
              "Value": "2026-08-29"
            },
            {
              "Field": "Evidence reference",
              "Value": "CSSAQ-2026-CLOUDHOST-001"
            }
          ]
        }
      ],
      "contentType": "decision_table"
    },
    {
      "id": "external_references",
      "title": "References",
      "groups": [
        {
          "text": "Cite these sources from workshops and audits. This list names ISO clauses, book chapters and companion artifacts used by this file."
        },
        {
          "rows": [
            {
              "Kind": "ISO",
              "Reference": "ISO/IEC 27001:2022",
              "How this document uses it": "Normative ISMS requirements this companion artifact supports.",
              "href": "https://www.iso.org/standard/82875.html"
            },
            {
              "Kind": "Book",
              "Reference": "Building the ISMS, HR Security: Screening, Onboarding & Offboarding",
              "How this document uses it": "Primary operating chapter for this companion artifact.",
              "href": "https://www.amazon.com/dp/9789908983448"
            },
            {
              "Kind": "Artifact",
              "Reference": "SINV Supplier Inventory (Building the ISMS, Supplier Security & Third-party Risk Management)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/dp/9789908983448"
            },
            {
              "Kind": "Artifact",
              "Reference": "ISO Information Security Objectives (Building the ISMS, Information Security Policies & Risk Management)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/dp/9789908983448"
            },
            {
              "Kind": "Artifact",
              "Reference": "BCP Business Continuity Plan (BCP) (Building the ISMS, Business Continuity & Disaster Recovery)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/dp/9789908983448"
            }
          ],
          "text": "Use this table or list as the working record. Name owners, systems and evidence so a second person can apply the same rule."
        }
      ],
      "contentType": "reference_table"
    }
  ],
  "enrichment": {
    "source": "Example.json",
    "method": "curated-json",
    "note": "Completes Example JSON with renderer-native sections and generalized groups; no mdSource helper fields."
  },
  "snapshotRef": {
    "snapshotId": "arcfield.platform.surv.2026-09-11",
    "schemaVersion": "evidenceSnapshot.v1"
  },
  "scenarioRef": {
    "githubIssue": 64,
    "crId": "CR-TYPE-ARCFIELD-001",
    "family": "Form",
    "role": "Blank operating form used with freeze records"
  }
}
