{
  "schemaVersion": "artifactExample.v2",
  "artifactId": "DAL",
  "title": "Decision and Action Log",
  "definitionRef": {
    "artifactId": "DAL",
    "definitionSchemaVersion": "artifactDefinition.v2",
    "definitionId": "DAL.artifactDefinition.v2",
    "title": "Decision and Action Log"
  },
  "organization": "Arcfield",
  "sections": [
    {
      "id": "title_page",
      "title": "Title Page",
      "values": {
        "Register Title": "Decision and Action Log",
        "Register ID": "DAL-REG-001",
        "Version": "1.1",
        "Status": "Approved",
        "Organization": "Arcfield",
        "Owner": "ISMS Manager",
        "Approver": "Top Management",
        "Classification": "Internal",
        "Effective Date": "2026-09-11",
        "Next Review Date": "2027-09-11"
      },
      "items": [
        "Register Title: Decision and Action Log",
        "Register ID: DAL-REG-001",
        "Version: 1.1",
        "Status: Approved",
        "Organization: Arcfield",
        "Owner: ISMS Manager",
        "Approver: Top Management",
        "Classification: Internal",
        "Effective Date: 2026-09-11",
        "Next Review Date: 2027-09-11"
      ],
      "contentType": "metadata"
    },
    {
      "id": "abstract",
      "title": "Abstract",
      "text": "This example records Arcfield leadership, governance and management-review decisions with rationale, affected ISMS topic, action owner, due date, status, closure evidence and follow-up review. Entries are the dated Arcfield Platform operating log sampled on the 11 September 2026 freeze in the surveillance cycle after certificate ARC-ISMS-2025-001.",
      "contentType": "narrative"
    },
    {
      "id": "document_control",
      "title": "Document Control",
      "rows": [
        {
          "Property": "Purpose",
          "Value": "Track ISMS decisions and follow-up actions to closure."
        },
        {
          "Property": "Used by",
          "Value": "Top Management, ISMS Manager, Control Owners, Internal Auditor"
        },
        {
          "Property": "Maintained by",
          "Value": "ISMS Manager"
        },
        {
          "Property": "Evidence role",
          "Value": "Governance, management review and leadership evidence"
        },
        {
          "Property": "ISO reference",
          "Value": "ISO/IEC 27001:2022 Clauses 5.1, 9.3 and 10.2"
        },
        {
          "Property": "Review cadence",
          "Value": "Monthly and before management review"
        }
      ],
      "contentType": "control_table"
    },
    {
      "id": "instructions",
      "title": "Instructions",
      "items": [
        "Record each leadership, governance or management-review decision.",
        "Include decision date, source, statement and rationale.",
        "Assign an action owner and due date where follow-up is required.",
        "Link closure evidence before closing the action.",
        "Review open actions before management review and internal audit.",
        "Use sheets ending in “Ex” as read-only examples. Enter live data only on the matching “Wk” (Working) sheets.",
        "Every operative list is an Excel Table with frozen headers and filters. Add new rows on the next empty worksheet row beneath the table so Excel expands it — do not leave blank rows inside the table.",
        "Where a column offers a dropdown, choose a value from the list (Status, Owner role, Priority, Severity, Likelihood, Impact, Applicability, Evidence Status, Review Result). Do not invent free-text variants.",
        "Enter dates as YYYY-MM-DD. Date columns are validated and formatted accordingly.",
        "Review the Flag columns (Overdue, Review Due, Missing Owner, Missing Evidence). They calculate automatically and highlight gaps for follow-up.",
        "Keep Cover, Legal, Book, Lists and Metadata unchanged. System sheets are protected on purpose."
      ],
      "contentType": "ordered_list"
    },
    {
      "id": "decision_action_log",
      "title": "Decision and action log",
      "schemaRef": {
        "definitionId": "DAL.artifactDefinition.v2",
        "sectionId": "decision_action_log",
        "columnsRef": "sections.decision_action_log.columns"
      },
      "rows": [
        {
          "Decision ID": "DAL-001",
          "Decision Date": "2026-08-12",
          "Meeting or Source": "Management review",
          "Decision Statement": "Approve ISO 27001 certification readiness plan for Q4.",
          "Decision Rationale": "Customer renewals increasingly require independent certification evidence.",
          "Affected ISMS Topic": "Certification readiness",
          "Related Clause or Control": "Clause 5.1; Clause 9.3",
          "Action Required": "Finalize internal audit and corrective action closure plan.",
          "Action Owner": "ISMS Manager",
          "Due Date": "2026-09-30",
          "Status": "In progress",
          "Closure Evidence": "IAP-2026 and CAR-REVIEW-2026-Q3",
          "Closure Date": "",
          "Next Review Date": "2026-09-30",
          "Notes": "Reviewed weekly in readiness stand-up."
        },
        {
          "Decision ID": "DAL-002",
          "Decision Date": "2026-08-12",
          "Meeting or Source": "Management review",
          "Decision Statement": "Accept residual risk for temporary privileged access exception.",
          "Decision Rationale": "Break-glass coverage is required until privileged access workflow is fully automated.",
          "Affected ISMS Topic": "Access control",
          "Related Clause or Control": "A.5.18; A.8.2",
          "Action Required": "Review exception by end of September and remove standing admin where possible.",
          "Action Owner": "IT Operations Manager",
          "Due Date": "2026-09-30",
          "Status": "Open",
          "Closure Evidence": "PAM-EXC-2026-Q3-003",
          "Closure Date": "",
          "Next Review Date": "2026-09-30",
          "Notes": "Linked to ARR-003."
        },
        {
          "Decision ID": "DAL-003",
          "Decision Date": "2026-08-20",
          "Meeting or Source": "Risk review",
          "Decision Statement": "Prioritize supplier exit-readiness improvement for cloud hosting.",
          "Decision Rationale": "Cloud hosting dependency is a high-impact context and continuity risk.",
          "Affected ISMS Topic": "Supplier and continuity management",
          "Related Clause or Control": "A.5.19; A.5.20; A.5.30",
          "Action Required": "Update supplier inventory and exit plan evidence.",
          "Action Owner": "Supplier Manager",
          "Due Date": "2026-10-15",
          "Status": "In progress",
          "Closure Evidence": "SINV-CLOUDHOST-2026-Q3",
          "Closure Date": "",
          "Next Review Date": "2026-10-15",
          "Notes": "Linked to CIL-002."
        },
        {
          "Decision ID": "DAL-004",
          "Decision Date": "2026-07-25",
          "Meeting or Source": "Security steering",
          "Decision Statement": "Retire recruiting CV screener pilot.",
          "Decision Rationale": "Employment context creates high-risk AI obligations outside current operating scope.",
          "Affected ISMS Topic": "AI governance",
          "Related Clause or Control": "Clause 6.1; A.5.12",
          "Action Required": "Retain pilot assessment and update AI governance file.",
          "Action Owner": "HR Manager",
          "Due Date": "2026-08-15",
          "Status": "Closed",
          "Closure Evidence": "AISGF-AI-003-RETIRE-2026",
          "Closure Date": "2026-08-15",
          "Next Review Date": "2026-11-29",
          "Notes": "No production deployment occurred."
        },
        {
          "Decision ID": "DAL-005",
          "Decision Date": "2026-07-10",
          "Meeting or Source": "Internal audit planning",
          "Decision Statement": "Audit access control and vulnerability management as priority topics.",
          "Decision Rationale": "Both topics have partial evidence and direct Annex A relevance.",
          "Affected ISMS Topic": "Internal audit programme",
          "Related Clause or Control": "Clause 9.2; A.5.18; A.8.8",
          "Action Required": "Update audit plan and sample selection.",
          "Action Owner": "Internal Auditor",
          "Due Date": "2026-08-01",
          "Status": "Closed",
          "Closure Evidence": "IAP-2026",
          "Closure Date": "2026-08-01",
          "Next Review Date": "2026-11-25",
          "Notes": "Samples added to audit plan."
        },
        {
          "Decision ID": "DAL-006",
          "Decision Date": "2026-06-28",
          "Meeting or Source": "ISMS operations meeting",
          "Decision Statement": "Add vulnerability SLA trend to monthly measurement dashboard.",
          "Decision Rationale": "Management needs trend visibility to confirm treatment effectiveness.",
          "Affected ISMS Topic": "Monitoring and measurement",
          "Related Clause or Control": "Clause 9.1; A.8.8",
          "Action Required": "Add metric and review it monthly.",
          "Action Owner": "Security Lead",
          "Due Date": "2026-08-31",
          "Status": "Closed",
          "Closure Evidence": "MME-2026-Q3",
          "Closure Date": "2026-08-31",
          "Next Review Date": "2026-09-30",
          "Notes": "Linked to CIL-003."
        }
      ],
      "contentType": "register_table"
    },
    {
      "id": "decision_review",
      "title": "Decision review",
      "values": {
        "Review result": "Controlled with three closed actions and three open or in-progress actions",
        "Decisions logged": 6,
        "Open actions": 3,
        "Overdue actions": 0,
        "Closed actions": 3,
        "Reviewed by": "ISMS Manager",
        "Decision date": "2026-08-29",
        "Evidence reference": "DAL-REVIEW-2026-Q3"
      },
      "rows": [
        {
          "Field": "Review result",
          "Value": "Controlled with three closed actions and three open or in-progress actions"
        },
        {
          "Field": "Decisions logged",
          "Value": "6"
        },
        {
          "Field": "Open actions",
          "Value": "3"
        },
        {
          "Field": "Overdue actions",
          "Value": "0"
        },
        {
          "Field": "Closed actions",
          "Value": "3"
        },
        {
          "Field": "Reviewed by",
          "Value": "ISMS Manager"
        },
        {
          "Field": "Decision date",
          "Value": "2026-08-29"
        },
        {
          "Field": "Evidence reference",
          "Value": "DAL-REVIEW-2026-Q3"
        }
      ],
      "contentType": "decision_table"
    },
    {
      "id": "external_references",
      "title": "References",
      "groups": [
        {
          "text": "Cite these sources from workshops and audits. This list names ISO clauses, book chapters and companion artifacts used by this file."
        },
        {
          "rows": [
            {
              "Kind": "ISO",
              "Reference": "ISO/IEC 27001:2022",
              "How this document uses it": "Normative source this artifact implements or cites.",
              "href": "https://www.iso.org/standard/82875.html"
            },
            {
              "Kind": "Book",
              "Reference": "Building the ISMS, Leadership & Management (Clause 5)",
              "How this document uses it": "Primary operating chapter for this companion artifact.",
              "href": "https://www.amazon.com/dp/9789908983448"
            },
            {
              "Kind": "Artifact",
              "Reference": "AI Asset Inventory (Implementation & Certification, Asset Management & Information Classification)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/s?k=ISO+27001+for+Software+Companies+Implementation+and+Certification"
            },
            {
              "Kind": "Artifact",
              "Reference": "ISO Information Security Objectives (Building the ISMS, Information Security Policies & Risk Management)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/dp/9789908983448"
            },
            {
              "Kind": "Artifact",
              "Reference": "CIL Continual Improvement Log (Building the ISMS, Continual Improvement (Clause 10))",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/dp/9789908983448"
            },
            {
              "Kind": "Artifact",
              "Reference": "IAP Internal Audit Plan (Implementation & Certification, Internal Audit & Management Review)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/s?k=ISO+27001+for+Software+Companies+Implementation+and+Certification"
            }
          ]
        }
      ],
      "contentType": "reference_table"
    }
  ],
  "enrichment": {
    "source": "Example.json",
    "method": "curated-json",
    "note": "Completes Example JSON with renderer-native sections and generalized groups; no mdSource helper fields."
  },
  "snapshotRef": {
    "snapshotId": "arcfield.platform.surv.2026-09-11",
    "schemaVersion": "evidenceSnapshot.v1"
  },
  "scenarioRef": {
    "githubIssue": 64,
    "crId": "CR-TYPE-ARCFIELD-001",
    "family": "Log",
    "role": "Dated operating log sampled on the freeze"
  }
}
