{
  "schemaVersion": "artifactDefinition.v2",
  "definitionId": "ICP.artifactDefinition.v2",
  "artifactId": "ICP",
  "title": "Information Classification Policy",
  "artifactType": "Policy",
  "format": "docx",
  "productTier": "Premium",
  "definitionRole": "contract",
  "sourceModel": {
    "body": "curated Example JSON is the worked Arcfield body; no Artifact Candidate page is in this factory",
    "jsonDefinition": "machine-readable contract and validation model",
    "jsonExample": "curated fictional Arcfield example (EXAMPLE_DECISION, pending review)"
  },
  "editorialStandard": {
    "purpose": "Define classification levels, labeling, handling rules and ownership expectations.",
    "requiredEditorialElements": [
      "introduction as purpose prose",
      "scope of this document versus neighbouring records",
      "terms as a first-class group",
      "worked Arcfield example",
      "practical examples, pitfalls, evidence and external references"
    ],
    "isoAnchors": [
      {
        "label": "ISO/IEC 27001:2022 A.5.12",
        "href": "https://www.iso.org/standard/82875.html",
        "role": "Annex A control this artifact implements."
      },
      {
        "label": "ISO/IEC 27001:2022 A.5.13",
        "href": "https://www.iso.org/standard/82875.html",
        "role": "Annex A control this artifact implements."
      },
      {
        "label": "ISO/IEC 27001:2022",
        "href": "https://www.iso.org/standard/82875.html",
        "role": "Normative source this artifact implements or cites."
      }
    ],
    "bookSources": [
      {
        "series": "ISO 27001 for Software Companies",
        "volume": 2,
        "volumeTitle": "Implementation & Certification",
        "chapterId": "S-07-01-00",
        "chapterTitle": "Asset Management & Information Classification",
        "primary": true,
        "role": "Primary operating chapter for this companion artifact.",
        "href": "https://www.amazon.com/s?k=ISO+27001+for+Software+Companies+Implementation+and+Certification"
      },
      {
        "series": "ISO 27001 for Software Companies",
        "volume": 1,
        "volumeTitle": "Building the ISMS",
        "chapterId": "S-00-03-00",
        "chapterTitle": "Planning, Risk & Objectives (Clause 6)",
        "primary": false,
        "role": "Documented information, review and version discipline.",
        "href": "https://www.amazon.com/dp/9789908983448"
      }
    ],
    "acronyms": [
      {
        "abbr": "ISMS",
        "longForm": "Information Security Management System"
      },
      {
        "abbr": "SaaS",
        "longForm": "Software as a Service"
      },
      {
        "abbr": "CIA",
        "longForm": "Confidentiality, Integrity, and Availability"
      },
      {
        "abbr": "CI/CD",
        "longForm": "Continuous Integration / Continuous Delivery"
      },
      {
        "abbr": "ISO",
        "longForm": "International Organization for Standardization"
      },
      {
        "abbr": "CI",
        "longForm": "Continuous Integration"
      },
      {
        "abbr": "CD",
        "longForm": "Continuous Delivery"
      },
      {
        "abbr": "EV",
        "longForm": "Extended Validation"
      },
      {
        "abbr": "JSON",
        "longForm": "JavaScript Object Notation"
      },
      {
        "abbr": "SoA",
        "longForm": "Statement of Applicability"
      }
    ],
    "must": [
      "This file's function is: Define classification levels, labeling, handling rules and ownership expectations. It must not be rewritten as a generic operating-rules essay.",
      "Classify information by confidentiality, integrity, availability, legal, contractual and customer impact.",
      "Apply handling rules to storage, access, sharing, transmission, retention and disposal.",
      "Treat exports, screenshots, logs and evidence packages as information assets.",
      "Reclassify information after sanitization, publication approval or scope changes.",
      "Record exceptions and external sharing decisions.",
      "Use examples and pitfalls before audit sampling."
    ],
    "mustNot": [
      "Do not replace this artifact's function with a shared family skeleton (operating_rules, systems_and_records)."
    ],
    "softwareCompanyAdaptations": [
      "Use Arcfield as the worked example (cover variant A).",
      "Name SaaS, cloud, CI/CD, privileged access or supplier interfaces where they affect this artifact's function."
    ],
    "exampleBody": {
      "sectionId": "policy_content",
      "workedExampleOrg": "Arcfield",
      "minBodyWords": 400,
      "requiredGroups": [
        {
          "id": "introduction",
          "heading": "What this policy is",
          "mustInclude": [
            "policy"
          ]
        },
        {
          "id": "scope",
          "heading": "Scope",
          "mustInclude": [
            "Scope"
          ]
        },
        {
          "id": "terms",
          "heading": "Terms used here",
          "mustInclude": [
            "Terms"
          ]
        },
        {
          "id": "classification_levels",
          "heading": "Classification levels",
          "mustInclude": [
            "Classification",
            "levels",
            "ICP-CLS-001"
          ]
        },
        {
          "id": "handling_rules",
          "heading": "Handling rules",
          "mustInclude": [
            "Handling",
            "rules",
            "ICP-HDL-001"
          ]
        },
        {
          "id": "ownership_and_review",
          "heading": "Ownership and review",
          "mustInclude": [
            "Ownership",
            "review",
            "ICP-OWN-001"
          ]
        },
        {
          "id": "external_sharing",
          "heading": "External sharing",
          "mustInclude": [
            "External",
            "sharing",
            "ICP-SHR-001"
          ]
        },
        {
          "id": "exceptions",
          "heading": "Exceptions",
          "mustInclude": [
            "Exceptions",
            "ICP-EXC-001"
          ]
        },
        {
          "id": "evidence",
          "heading": "Evidence expectations",
          "mustInclude": [
            "ICP-EV-001",
            "expectation"
          ]
        }
      ],
      "requiredSections": [
        {
          "id": "change_log",
          "title": "Revision history",
          "role": "Versioned freeze log with how-to sentence and rows Version, Date, Change, Approved by. Last Version matches title_page.values.Version."
        },
        {
          "id": "external_references",
          "title": "References",
          "role": "ISO clauses, book chapters and companion artifacts. Not a series catalogue."
        }
      ]
    }
  },
  "sections": [
    {
      "order": 1,
      "id": "title_page",
      "title": "Title Page",
      "contentType": "metadata",
      "required": true
    },
    {
      "order": 2,
      "id": "abstract",
      "title": "Abstract",
      "contentType": "narrative",
      "required": true,
      "hint": {
        "text": "Apply Abstract with named owners, systems and exportable evidence. Do not leave this chapter as a heading plus a bare table.",
        "bookReference": "Volume 1, S-02-01-00 Information Security Policies & Risk"
      }
    },
    {
      "order": 3,
      "id": "document_control",
      "title": "Document Control",
      "contentType": "control_table",
      "required": true
    },
    {
      "order": 4,
      "id": "change_log",
      "title": "Revision history",
      "contentType": "revision_table",
      "required": true
    },
    {
      "order": 5,
      "id": "instructions",
      "title": "Instructions",
      "contentType": "ordered_list",
      "required": true,
      "hint": {
        "text": "Apply Instructions with named owners, systems and exportable evidence. Do not leave this chapter as a heading plus a bare table.",
        "bookReference": "Volume 1, S-02-01-00 Information Security Policies & Risk"
      }
    },
    {
      "order": 6,
      "id": "policy_content",
      "title": "Policy",
      "contentType": "policy_sections",
      "required": true,
      "hint": {
        "text": "Apply Policy with named owners, systems and exportable evidence. Do not leave this chapter as a heading plus a bare table.",
        "bookReference": "Volume 1, S-02-01-00 Information Security Policies & Risk"
      }
    },
    {
      "order": 9,
      "id": "evidence_and_records",
      "title": "Evidence and records",
      "contentType": "evidence_table",
      "required": true,
      "hint": {
        "text": "Apply Evidence and records with named owners, systems and exportable evidence. Do not leave this chapter as a heading plus a bare table.",
        "bookReference": "Volume 1, S-02-01-00 Information Security Policies & Risk"
      }
    },
    {
      "order": 10,
      "id": "external_references",
      "title": "References",
      "contentType": "reference_table",
      "required": true,
      "hint": {
        "text": "Apply References with named owners, systems and exportable evidence. Do not leave this chapter as a heading plus a bare table.",
        "bookReference": "Volume 1, S-02-01-00 Information Security Policies & Risk"
      }
    }
  ],
  "validationRules": [
    "JSON Example must contain definitionRef pointing to ICP.artifactDefinition.v2.",
    "Policy must define classification levels, handling rules, storage, sharing, owner review and exceptions.",
    "Body must include practical examples, common pitfalls and evidence expectations.",
    "No legacy MD references or standalone Book reference section allowed."
  ],
  "enrichment": {
    "source": "Contract.json",
    "method": "curated-json",
    "note": "Completes Contract JSON from MD-only schema/sections, removes duplicate alias sections, and normalizes string columns into structured column objects."
  },
  "purpose": "Define classification levels, labeling, handling rules and ownership expectations.",
  "editorialContractId": "editorial.docx.policy.v1",
  "contentContractId": "content.literary.v1",
  "relations": [
    {
      "kind": "cites",
      "artifactId": "MDR",
      "role": "evidence_register",
      "expectedType": "Register",
      "rank": 30
    },
    {
      "kind": "cites",
      "artifactId": "DR",
      "role": "evidence_register",
      "expectedType": "Register",
      "rank": 31
    },
    {
      "kind": "cites",
      "artifactId": "RRS",
      "role": "evidence_register",
      "expectedType": "Register",
      "rank": 32
    },
    {
      "kind": "cites",
      "artifactId": "AI",
      "role": "inventory",
      "expectedType": "Inventory",
      "rank": 20
    },
    {
      "kind": "cites",
      "artifactId": "SINV",
      "role": "inventory",
      "expectedType": "Inventory",
      "rank": 21
    },
    {
      "kind": "cites",
      "artifactId": "UAI",
      "role": "inventory",
      "expectedType": "Inventory",
      "rank": 22
    }
  ]
}
