{
  "schemaVersion": "artifactExample.v2",
  "artifactId": "GS",
  "title": "Gap Statement",
  "definitionRef": {
    "artifactId": "GS",
    "definitionSchemaVersion": "artifactDefinition.v2",
    "definitionId": "GS.artifactDefinition.v2",
    "title": "Gap Statement"
  },
  "organization": "Arcfield",
  "sections": [
    {
      "id": "title_page",
      "title": "Title Page",
      "values": {
        "Document Title": "Gap Statement",
        "Document ID": "GAP-STMT-001",
        "Version": "1.1",
        "Status": "Approved",
        "Organization": "Arcfield",
        "Owner": "ISMS Manager",
        "Approver": "Top Management",
        "Classification": "Internal",
        "Effective Date": "2026-09-11",
        "Next Review Date": "2027-09-11"
      },
      "items": [
        "Document Title: Gap Statement",
        "Document ID: GAP-STMT-001",
        "Version: 1.1",
        "Status: Approved",
        "Organization: Arcfield",
        "Owner: ISMS Manager",
        "Approver: Top Management",
        "Classification: Internal",
        "Effective Date: 2026-09-11",
        "Next Review Date: 2027-09-11"
      ],
      "contentType": "metadata"
    },
    {
      "id": "abstract",
      "title": "Abstract",
      "text": "This Gap Statement records the difference between the organisation’s current ISMS state and the required or target state for a defined scope (ISO/IEC 27001 clauses, Annex A themes, or a regulatory overlay). It turns assessment findings into owned gaps with priority, treatment and evidence expectations. It is not a governance-structure charter. This statement remains binding for the certified Arcfield Platform ISMS in the surveillance cycle after certificate ARC-ISMS-2025-001.",
      "contentType": "narrative"
    },
    {
      "id": "document_control",
      "title": "Document Control",
      "contentType": "control_table"
    },
    {
      "id": "change_log",
      "title": "Revision history",
      "groups": [
        {
          "text": "A published change is a new row. Do not edit an approved version in place."
        },
        {
          "rows": [
            {
              "Version": "1.0",
              "Date": "2026-08-29",
              "Change": "Initial Arcfield Platform publication.",
              "Approved by": "Top Management"
            },
            {
              "Version": "1.1",
              "Date": "2026-09-11",
              "Change": "Approved Arcfield worked example after the 11 September 2026 internal audit.",
              "Approved by": "Top Management"
            }
          ]
        }
      ],
      "contentType": "revision_table"
    },
    {
      "id": "instructions",
      "title": "Instructions",
      "groups": [
        {
          "text": "Copy this file as the controlled Word master for your ISMS. The Arcfield identity fields on the cover are the approved worked example. Complete the steps below when you adopt the file for your organization."
        },
        {
          "items": [
            "Fill the cover identity fields (Organization, Version, Classification, Owner, Approver, Effective Date and Next Review Date) when you adopt this file. The Arcfield values shown here are the approved worked example.",
            "Issue your own version and a new Revision history row. Do not edit an approved version in place.",
            "Cite this approved version from related records. Do not copy this file into those records."
          ]
        }
      ],
      "contentType": "ordered_list"
    },
    {
      "id": "gap_template_content",
      "title": "Gap",
      "groups": [
        {
          "id": "introduction",
          "heading": "What this statement is",
          "level": 1,
          "text": "This document is Arcfield's Gap Statement. Document ISMS gaps between current and target state with owned closure actions. It is not the Information Security Policy, the SoA or a live register. This statement applies to the Arcfield Platform (B2B SaaS for regulated fintech and health customers): production, customer data, CI/CD, privileged access and critical suppliers. Neighbouring records (ISO, CAR, IAP) cite this Document Control version. Do not copy these paragraphs into them."
        },
        {
          "id": "scope",
          "heading": "Scope",
          "level": 1,
          "text": "Use this table before you copy a rule into another record or exclude a duty from this file.",
          "rows": [
            {
              "In this statement": "The rules, roles, worked Arcfield example and the records this file owns.",
              "Not in this statement": "The ISMS boundary (ISS), Annex A selection (SoA) or live rows in ISO, CAR, IAP."
            },
            {
              "In this statement": "Interfaces that must cite this Document Control version, including CI/CD, identity and suppliers where they affect CIA.",
              "Not in this statement": "Live ISS scope rows, SoA applicability decisions, or neighbouring live registers. Those files keep their own approved versions; this file does not duplicate them."
            }
          ]
        },
        {
          "id": "terms",
          "heading": "Terms used here",
          "level": 1,
          "text": "These terms are local to this file. Expand every acronym on first use in the body.",
          "rows": [
            {
              "Term": "Owner",
              "Meaning": "The named role that can be called in an audit for an outcome. A team name is not an owner."
            },
            {
              "Term": "Exception",
              "Meaning": "A time-bound, approved departure with expiry and a compensating control."
            },
            {
              "Term": "CIA",
              "Meaning": "Confidentiality, Integrity and Availability of in-scope information and services."
            },
            {
              "Term": "Document Control version",
              "Meaning": "The approved version cited from neighbouring records. Do not copy this body into those records."
            }
          ]
        },
        {
          "id": "named_registers",
          "heading": "Systems, integrations and data",
          "level": 1,
          "text": "Related inventories live in the companion documents named below. This file cites them by their approved version. It does not copy their content.",
          "items": [
            "[Asset Inventory](AI_Asset_Inventory.xlsx) — In-scope assets with owner, classification, hosting, personal-data flag and related risk.",
            "[Supplier Inventory](SINV_Supplier_Inventory.xlsx) — Security-relevant suppliers with tier, due diligence, contract controls, subprocessors and exit planning.",
            "[Users and Access Inventory](UAI_Users_and_Access_Inventory.xlsx) — Users and accounts with access rights, privileged access, MFA status, reviews and revocations."
          ],
          "ordered": true,
          "relationView": "inventory"
        },
        {
          "id": "scope_of_assessment",
          "heading": "Scope of assessment",
          "level": 1,
          "text": "Scope of assessment is a Arcfield Platform operating rule for Arcfield, not a restatement of this file's purpose. Scope of assessment states the Arcfield rule, the Arcfield Platform system it binds and the evidence a second person can retrieve. Document ISMS gaps between current and target state with owned closure actions. Apply it to Arcfield Platform production, customer data, CI/CD, privileged access and critical suppliers. Name the owner, the live record and the review date. Cite this approved version from neighbouring records; do not copy this chapter into them.",
          "rows": [
            {
              "Arcfield case": "Arcfield Platform production — scope of assessment",
              "Rule applied": "Scope of assessment binds the named production system and a named owner. Document ISMS gaps between current and target state with owned closure actions.",
              "Evidence": "GS-scope_of_assessment-PROD"
            },
            {
              "Arcfield case": "Customer data / support — scope of assessment",
              "Rule applied": "Support attachments and tenant configuration inherit this scope of assessment rule; they are not out of scope because they are temporary.",
              "Evidence": "GS-scope_of_assessment-CUST"
            },
            {
              "Arcfield case": "Supplier or CI/CD — scope of assessment",
              "Rule applied": "Name the shared-responsibility split for scope of assessment on hosting, identity and deploy paths. An unnamed interface is an unnamed audit boundary.",
              "Evidence": "GS-scope_of_assessment-SUP"
            }
          ]
        },
        {
          "id": "gap_register",
          "heading": "Gap register",
          "level": 1,
          "text": "Gap register is a Arcfield Platform operating rule for Arcfield, not a restatement of this file's purpose. Gap register states the Arcfield rule, the Arcfield Platform system it binds and the evidence a second person can retrieve. Document ISMS gaps between current and target state with owned closure actions. Apply it to ISMS evidence that an auditor can retrieve for Arcfield Platform. Name the owner, the live record and the review date. Cite this approved version from neighbouring records; do not copy this chapter into them.",
          "rows": [
            {
              "Arcfield case": "Arcfield Platform production — gap register",
              "Rule applied": "Gap register binds the named production system and a named owner. Document ISMS gaps between current and target state with owned closure actions.",
              "Evidence": "GS-gap_register-PROD"
            },
            {
              "Arcfield case": "Customer data / support — gap register",
              "Rule applied": "Support attachments and tenant configuration inherit this gap register rule; they are not out of scope because they are temporary.",
              "Evidence": "GS-gap_register-CUST"
            },
            {
              "Arcfield case": "Supplier or CI/CD — gap register",
              "Rule applied": "Name the shared-responsibility split for gap register on hosting, identity and deploy paths. An unnamed interface is an unnamed audit boundary.",
              "Evidence": "GS-gap_register-SUP"
            }
          ]
        },
        {
          "id": "prioritisation_rules",
          "heading": "Prioritisation rules",
          "level": 1,
          "text": "Prioritisation rules is a Arcfield Platform operating rule for Arcfield, not a restatement of this file's purpose. Prioritisation rules states the Arcfield rule, the Arcfield Platform system it binds and the evidence a second person can retrieve. Document ISMS gaps between current and target state with owned closure actions. Apply it to Arcfield Platform production, customer data, CI/CD, privileged access and critical suppliers. Name the owner, the live record and the review date. Cite this approved version from neighbouring records; do not copy this chapter into them.",
          "rows": [
            {
              "Arcfield case": "Arcfield Platform production — prioritisation rules",
              "Rule applied": "Prioritisation rules binds the named production system and a named owner. Document ISMS gaps between current and target state with owned closure actions.",
              "Evidence": "GS-prioritisation_rules-PROD"
            },
            {
              "Arcfield case": "Customer data / support — prioritisation rules",
              "Rule applied": "Support attachments and tenant configuration inherit this prioritisation rules rule; they are not out of scope because they are temporary.",
              "Evidence": "GS-prioritisation_rules-CUST"
            },
            {
              "Arcfield case": "Supplier or CI/CD — prioritisation rules",
              "Rule applied": "Name the shared-responsibility split for prioritisation rules on hosting, identity and deploy paths. An unnamed interface is an unnamed audit boundary.",
              "Evidence": "GS-prioritisation_rules-SUP"
            }
          ]
        },
        {
          "id": "closure_and_verification",
          "heading": "Closure and verification",
          "level": 1,
          "text": "Closure and verification is a Arcfield Platform operating rule for Arcfield, not a restatement of this file's purpose. Closure and verification states the Arcfield rule, the Arcfield Platform system it binds and the evidence a second person can retrieve. Document ISMS gaps between current and target state with owned closure actions. Apply it to Arcfield Platform production, customer data, CI/CD, privileged access and critical suppliers. Name the owner, the live record and the review date. Cite this approved version from neighbouring records; do not copy this chapter into them.",
          "rows": [
            {
              "Arcfield case": "Arcfield Platform production — closure and verification",
              "Rule applied": "Closure and verification binds the named production system and a named owner. Document ISMS gaps between current and target state with owned closure actions.",
              "Evidence": "GS-closure_and_verification-PROD"
            },
            {
              "Arcfield case": "Customer data / support — closure and verification",
              "Rule applied": "Support attachments and tenant configuration inherit this closure and verification rule; they are not out of scope because they are temporary.",
              "Evidence": "GS-closure_and_verification-CUST"
            },
            {
              "Arcfield case": "Supplier or CI/CD — closure and verification",
              "Rule applied": "Name the shared-responsibility split for closure and verification on hosting, identity and deploy paths. An unnamed interface is an unnamed audit boundary.",
              "Evidence": "GS-closure_and_verification-SUP"
            }
          ]
        }
      ],
      "contentType": "statement_sections"
    },
    {
      "id": "evidence_and_records",
      "title": "Evidence and records",
      "groups": [
        {
          "text": "Related records live in the companion documents named below. This file cites them by their approved version. It does not copy their content. The Owner named on the cover is accountable for those live records."
        },
        {
          "items": [
            "[Mandatory Documents and Records Register](MDR_Mandatory_Documents_and_Records_Register.xlsx) — The 27 mandatory ISO 27001 documents and records, with owner, required status, approval, review cadence, location and evidence readiness.",
            "[Document Register](DR_Document_Register.xlsx) — Controlled documented information: origin, owner, approver, version, review cycle, retention and location.",
            "[Records Retention Schedule](RRS_Records_Retention_Schedule_Register.xlsx) — Retention rules for ISMS, security, privacy, audit and operational records, with owner, period, disposal method and evidence."
          ],
          "ordered": true,
          "relationView": "evidence"
        }
      ],
      "contentType": "register_table"
    },
    {
      "id": "external_references",
      "title": "References",
      "groups": [
        {
          "id": "linked_documents",
          "heading": "Linked documents",
          "level": 1,
          "text": "These companion files sit next to this document in the unpacked package. This file cites them by their approved version. It does not copy their content.",
          "rows": [
            {
              "Kind": "Artifact",
              "Reference": "AI Asset Inventory",
              "How this document uses it": "In-scope assets with owner, classification, hosting, personal-data flag and related risk.",
              "href": "AI_Asset_Inventory.xlsx"
            },
            {
              "Kind": "Artifact",
              "Reference": "SINV Supplier Inventory",
              "How this document uses it": "Security-relevant suppliers with tier, due diligence, contract controls, subprocessors and exit planning.",
              "href": "SINV_Supplier_Inventory.xlsx"
            },
            {
              "Kind": "Artifact",
              "Reference": "UAI Users and Access Inventory",
              "How this document uses it": "Users and accounts with access rights, privileged access, MFA status, reviews and revocations.",
              "href": "UAI_Users_and_Access_Inventory.xlsx"
            },
            {
              "Kind": "Artifact",
              "Reference": "MDR Mandatory Documents and Records Register",
              "How this document uses it": "The 27 mandatory ISO 27001 documents and records, with owner, required status, approval, review cadence, location and evidence readiness.",
              "href": "MDR_Mandatory_Documents_and_Records_Register.xlsx"
            },
            {
              "Kind": "Artifact",
              "Reference": "DR Document Register",
              "How this document uses it": "Controlled documented information: origin, owner, approver, version, review cycle, retention and location.",
              "href": "DR_Document_Register.xlsx"
            },
            {
              "Kind": "Artifact",
              "Reference": "RRS Records Retention Schedule",
              "How this document uses it": "Retention rules for ISMS, security, privacy, audit and operational records, with owner, period, disposal method and evidence.",
              "href": "RRS_Records_Retention_Schedule_Register.xlsx"
            },
            {
              "Kind": "Artifact",
              "Reference": "CAR Corrective Actions Register (Building the ISMS, Context of the Organization (Clause 4))",
              "href": "CAR_Corrective_Actions_Register.xlsx",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record."
            },
            {
              "Kind": "Artifact",
              "Reference": "IAP Internal Audit Plan (Implementation & Certification, Internal Audit & Management Review)",
              "href": "IAP_Internal_Audit_Plan.docx",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record."
            },
            {
              "Kind": "Artifact",
              "Reference": "ISO Information Security Objectives (Building the ISMS, Information Security Policies & Risk Management)",
              "href": "ISO_Information_Security_Objectives_Register.xlsx",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record."
            },
            {
              "Kind": "Artifact",
              "Reference": "RTP Risk Treatment Plan (Implementation & Certification, Risk Assessment & Risk Treatment Process)",
              "href": "RTP_Risk_Treatment_Plan_Register.xlsx",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record."
            }
          ]
        },
        {
          "id": "external_sources",
          "heading": "External references",
          "level": 1,
          "text": "Cite these ISO clauses and book chapters from workshops and audits.",
          "rows": [
            {
              "Kind": "ISO",
              "Reference": "ISO/IEC 27001:2022",
              "How this document uses it": "Normative ISMS requirements this companion artifact supports.",
              "href": "https://www.iso.org/standard/82875.html"
            },
            {
              "Kind": "Book",
              "Reference": "Building the ISMS, Context of the Organization (Clause 4)",
              "How this document uses it": "Primary operating chapter for this companion artifact.",
              "href": "https://www.amazon.com/dp/9789908983448"
            }
          ]
        }
      ],
      "contentType": "reference_table"
    }
  ],
  "generation": {
    "source": "Example.json",
    "method": "curated-json",
    "note": "Completes Example JSON with renderer-native sections and generalized groups; no mdSource helper fields."
  },
  "snapshotRef": {
    "snapshotId": "arcfield.platform.surv.2026-09-11",
    "schemaVersion": "evidenceSnapshot.v1"
  },
  "scenarioRef": {
    "githubIssue": 64,
    "crId": "CR-TYPE-ARCFIELD-001",
    "family": "Statement",
    "role": "Binding Arcfield Platform ISMS statement in the surveillance window"
  }
}
