{
  "schemaVersion": "artifactExample.v2",
  "artifactId": "ICP",
  "title": "Information Classification Policy",
  "definitionRef": {
    "artifactId": "ICP",
    "definitionSchemaVersion": "artifactDefinition.v2",
    "definitionId": "ICP.artifactDefinition.v2",
    "title": "Information Classification Policy"
  },
  "organization": "Arcfield",
  "sections": [
    {
      "id": "title_page",
      "title": "Title Page",
      "values": {
        "Document Title": "Information Classification Policy",
        "Document ID": "INFO-CLASS-POL-001",
        "Version": "1.1",
        "Status": "Approved",
        "Organization": "Arcfield",
        "Owner": "ISMS Manager",
        "Approver": "Security Lead",
        "Classification": "Internal",
        "Effective Date": "2026-09-11",
        "Next Review Date": "2027-09-11"
      },
      "items": [
        "Document Title: Information Classification Policy",
        "Document ID: INFO-CLASS-POL-001",
        "Version: 1.1",
        "Status: Approved",
        "Organization: Arcfield",
        "Owner: ISMS Manager",
        "Approver: Security Lead",
        "Classification: Internal",
        "Effective Date: 2026-09-11",
        "Next Review Date: 2027-09-11"
      ],
      "contentType": "metadata"
    },
    {
      "id": "abstract",
      "title": "Abstract",
      "text": "This is a fictional Arcfield worked example of INFO-CLASS-POL-001. It states operating rules for Information Classification Policy. The cover status is not a real management-team approval and not a certification statement. New numerical and method choices are EXAMPLE_DECISION and pending review. They are not ISO/IEC 27001:2022 obligations and not a recovered Artifact Candidate page.",
      "contentType": "narrative"
    },
    {
      "id": "document_control",
      "title": "Document Control",
      "contentType": "control_table"
    },
    {
      "id": "change_log",
      "title": "Revision history",
      "groups": [
        {
          "text": "A published change is a new row. Do not edit an approved version in place."
        },
        {
          "rows": [
            {
              "Version": "1.0",
              "Date": "2026-08-29",
              "Change": "Initial Arcfield Platform publication.",
              "Approved by": "Security Lead"
            },
            {
              "Version": "1.1",
              "Date": "2026-09-11",
              "Change": "Approved Arcfield worked example after the 11 September 2026 internal audit.",
              "Approved by": "Security Lead"
            }
          ]
        }
      ],
      "contentType": "revision_table"
    },
    {
      "id": "instructions",
      "title": "Instructions",
      "groups": [
        {
          "text": "This file is a fictional Arcfield example, not your organization's approved policy. Copy this file as the controlled Word master for your ISMS only after you replace Arcfield decisions with your own."
        },
        {
          "items": [
            "Treat INFO-CLASS-POL-001 and the rule IDs as the example identity. Cover status Approved is the Arcfield scenario freeze, not a real management-team sign-off of these new rule sentences.",
            "Replace Arcfield names, methods and owners before you adopt the file.",
            "Cite the Document Control version from related records. Do not copy this body into those records."
          ]
        }
      ],
      "contentType": "ordered_list"
    },
    {
      "id": "policy_content",
      "title": "Policy",
      "groups": [
        {
          "id": "introduction",
          "heading": "What this policy is",
          "level": 1,
          "text": "This document is Arcfield's Information Classification Policy, document ID INFO-CLASS-POL-001. It binds Arcfield Platform classification levels, labelling, handling, ownership, external sharing and exceptions. Public, Internal, Confidential and Restricted are the only approved levels. It is not the ISMS Scope Statement, the Risk Assessment Methodology or the Statement of Applicability. It applies to Arcfield Platform production, customer data, CI/CD, privileged access and critical suppliers. Neighbouring records cite this Document Control version. Do not copy these paragraphs into those records."
        },
        {
          "id": "scope",
          "heading": "Scope",
          "level": 1,
          "text": "Use this table before you copy a rule into another record or exclude a duty from this file.",
          "rows": [
            {
              "In this policy": "The classified rules ICP-CLS-001, ICP-HDL-001, ICP-OWN-001 through ICP-EV-001, roles, the worked Arcfield example and the records this file owns.",
              "Not in this policy": "The ISMS boundary (ISS), Annex A selection (SoA), or live neighbouring registers. Those files keep their own versions."
            },
            {
              "In this policy": "Interfaces that must cite this Document Control version, including CI/CD, identity and suppliers where they affect confidentiality, integrity or availability.",
              "Not in this policy": "Live ISS or SoA decisions. Neighbouring live registers keep their own versions. Those files are named, not copied here."
            }
          ]
        },
        {
          "id": "terms",
          "heading": "Terms used here",
          "level": 1,
          "text": "These terms are local to this file. Expand every acronym on first use in the body. Artefact ID ISO is Information Security Objectives, not the International Organization for Standardization.",
          "rows": [
            {
              "Term": "Owner",
              "Meaning": "The named role that can be called in an audit for an outcome. A team name is not an owner."
            },
            {
              "Term": "Exception",
              "Meaning": "A time-bound, approved departure with expiry and a compensating control. An expired row does not authorise continued deviation."
            },
            {
              "Term": "Document Control version",
              "Meaning": "The version cited from neighbouring records. Do not copy this body into those records."
            },
            {
              "Term": "Enforcement",
              "Meaning": "The named system rejects the unauthorised attempt for the named population. Registration or capability is not enforcement."
            }
          ]
        },
        {
          "id": "named_registers",
          "heading": "Systems, integrations and data",
          "level": 1,
          "text": "Related inventories live in the companion documents named below. Cite the approved version. Do not copy their content. Availability follows the book pack, not this sentence.",
          "items": [
            "[Asset Inventory](AI_Asset_Inventory.xlsx) — In-scope assets with owner, classification, hosting, personal-data flag and related risk.",
            "[Supplier Inventory](SINV_Supplier_Inventory.xlsx) — Security-relevant suppliers with tier, due diligence, contract controls, subprocessors and exit planning.",
            "[Users and Access Inventory](UAI_Users_and_Access_Inventory.xlsx) — Users and accounts with access rights, privileged access, MFA status, reviews and revocations."
          ],
          "ordered": true,
          "relationView": "inventory"
        },
        {
          "id": "classification_levels",
          "heading": "Classification levels",
          "level": 1,
          "text": "Use this table to classify every Arcfield Platform information asset before you store, share or export it. Public, Internal, Confidential and Restricted are the only approved levels. A colour, a folder name or 'sensitive' is not a level. Label the live record; do not copy this table into the risk register, a privacy assessment or the asset inventory.",
          "rows": [
            {
              "Level": "Public",
              "Meaning": "Information Arcfield has approved for public release, such as marketing pages and published status notices.",
              "Arcfield Platform example": "The public status page for Arcfield Platform availability.",
              "Owner": "Communications Owner"
            },
            {
              "Level": "Internal",
              "Meaning": "Information for Arcfield staff and authorised contractors that would not harm a customer if disclosed inside the company.",
              "Arcfield Platform example": "Internal runbooks for the Arcfield Platform support queue.",
              "Owner": "Process Owner"
            },
            {
              "Level": "Confidential",
              "Meaning": "Customer, workforce or ISMS information whose disclosure would harm Arcfield or a customer.",
              "Arcfield Platform example": "Customer configuration, support attachments and ISMS evidence exports.",
              "Owner": "Asset Owner"
            },
            {
              "Level": "Restricted",
              "Meaning": "Secrets, privileged credentials, health data and legal holds. Need-to-know only.",
              "Arcfield Platform example": "Production signing keys, CI/CD secrets and identifiable customer PII.",
              "Owner": "Security Lead"
            }
          ]
        },
        {
          "id": "handling_rules",
          "heading": "Handling rules",
          "level": 1,
          "text": "Apply the handling row for the approved level before you transmit, store or destroy the information. Exports, screenshots and logs inherit the highest level of the data they contain. Support tickets that include customer configuration are Confidential; identifiable customer PII and secrets are Restricted.",
          "rows": [
            {
              "Level": "Public",
              "Store": "Approved public sites and status channels",
              "Share": "No restriction inside the published wording",
              "Destroy": "Withdraw the publication record when the page is retired"
            },
            {
              "Level": "Internal",
              "Store": "Arcfield-managed workspace with single sign-on",
              "Share": "Arcfield staff and named contractors only",
              "Destroy": "Follow the retention schedule for the record type"
            },
            {
              "Level": "Confidential",
              "Store": "Approved Arcfield Platform systems with encryption at rest",
              "Share": "Named roles; no personal email or unapproved software service",
              "Destroy": "Secure delete; cite the deletion record"
            },
            {
              "Level": "Restricted",
              "Store": "Approved secret store or health-data store only",
              "Share": "Need-to-know; recorded access; no local copies",
              "Destroy": "Crypto-shred or certified destruction; dual control"
            }
          ]
        },
        {
          "id": "ownership_and_review",
          "heading": "Ownership and review",
          "level": 1,
          "text": "Every classified Arcfield Platform asset has one named owner. A team name is not an owner. The owner confirms the level at creation, after a significant change, and at least annually. Reclassification is a documented change with the previous level, the new level and the reason. Cite this approved version from the asset inventory.",
          "rows": [
            {
              "Duty": "Assign a named owner",
              "Arcfield rule": "Asset Manager records the owner in the inventory before the asset holds customer data.",
              "Evidence": "Inventory owner field plus this Document ID"
            },
            {
              "Duty": "Review the level",
              "Arcfield rule": "Owner reviews Confidential and Restricted Arcfield Platform assets at least annually or after an incident.",
              "Evidence": "Inventory last-review date"
            },
            {
              "Duty": "Reclassify",
              "Arcfield rule": "Downgrade only with written reason. Upgrade immediately when health data or secrets appear.",
              "Evidence": "Change record citing ICP"
            }
          ]
        },
        {
          "id": "external_sharing",
          "heading": "External sharing",
          "level": 1,
          "text": "Share Arcfield Platform information outside Arcfield only at the approved level, with a named recipient, a purpose and a retrieval or deletion date. Hosting and laboratory suppliers receive Confidential or Restricted data only under a contract that names the split. Public marketing text is not a channel for customer data.",
          "rows": [
            {
              "Channel": "Customer tenant export",
              "Minimum level": "Confidential",
              "Rule": "Customer admin initiates; Arcfield logs the export; no copy into personal mail."
            },
            {
              "Channel": "Supplier support",
              "Minimum level": "Confidential",
              "Rule": "Ticket stays in the approved platform. Restricted secrets go through privileged access, not the ticket body."
            },
            {
              "Channel": "Auditor pack",
              "Minimum level": "Confidential",
              "Rule": "Cite this approved version. Redact Restricted secrets. Do not paste production data into the pack."
            }
          ]
        },
        {
          "id": "exceptions",
          "heading": "Exceptions",
          "level": 1,
          "text": "An exception to these levels or handling rules needs an owner, a compensating control, an expiry date and Top Management or Security Lead approval. An expired exception is a nonconformity, not a silent extension. Record it in the exception register and cite this approved version; do not hide it as a comment on a Arcfield Platform ticket.",
          "rows": [
            {
              "Exception": "Unlabelled historical export",
              "Owner": "ISMS Manager",
              "Expiry": "2026-12-11",
              "Compensating control": "Restricted share folder, no further copies, deletion dated in RRS"
            }
          ]
        },
        {
          "id": "classified_rules",
          "heading": "Classified rules",
          "level": 1,
          "text": "These rows are the EXAMPLE_DECISION rules. The tables above remain the working Arcfield levels and handling scheme.",
          "rows": [
            {
              "Rule ID": "ICP-CLS-001",
              "Statement": "Public, Internal, Confidential and Restricted are the only approved levels. A colour, a folder name or 'sensitive' is not a level.",
              "Scope": "Every Arcfield Platform information asset before it is stored, shared or exported.",
              "Owner": "ISMS Manager",
              "Evidence expectation": "Expected: AI classification equal to one of the four levels. No observation is supplied."
            },
            {
              "Rule ID": "ICP-HDL-001",
              "Statement": "Exports, screenshots and logs inherit the highest level of the data they contain. Support tickets with customer configuration are Confidential; identifiable customer PII and secrets are Restricted.",
              "Scope": "Transmission, storage and destruction of classified information.",
              "Owner": "ISMS Manager",
              "Evidence expectation": "Expected: handling row applied to the live record. No observation is supplied."
            },
            {
              "Rule ID": "ICP-OWN-001",
              "Statement": "Every classified asset has one named owner. The owner confirms the level at creation, after a significant change, and at least annually for Confidential and Restricted.",
              "Scope": "Classified Arcfield Platform assets.",
              "Owner": "ISMS Manager",
              "Evidence expectation": "Expected: AI owner and last-review date. No observation is supplied."
            },
            {
              "Rule ID": "ICP-SHR-001",
              "Statement": "Share outside Arcfield only at the approved level, with a named recipient, a purpose and a retrieval or deletion date. Public marketing text is not a channel for customer data.",
              "Scope": "Customer tenant exports, supplier support and auditor packs.",
              "Owner": "ISMS Manager",
              "Evidence expectation": "Expected: sharing record with recipient and date. No observation is supplied."
            },
            {
              "Rule ID": "ICP-EXC-001",
              "Statement": "An exception to these levels or handling rules needs an owner, a compensating control, an expiry date and Security Lead or Top Management approval. An expired exception is a nonconformity.",
              "Scope": "Deviations from ICP-CLS-001 or ICP-HDL-001.",
              "Owner": "ISMS Manager",
              "Evidence expectation": "Expected: exception row with expiry. This Example names the register; it does not join another book's files. No observation is supplied."
            }
          ]
        },
        {
          "id": "evidence",
          "heading": "Evidence expectations",
          "level": 1,
          "text": "Use this table to see what a named evidence ID can prove. It is not a log of collected observations.",
          "rows": [
            {
              "Rule ID": "ICP-EV-001",
              "Statement": "Each rule above states an evidence expectation. An identifier without a bound dataset is not collected evidence.",
              "Scope": "All ICP rules in this file.",
              "Owner": "ISMS Manager",
              "Evidence expectation": "Expected evidence reference; no evidence supplied. Do not render this row as an observation."
            }
          ]
        }
      ],
      "contentType": "policy_sections"
    },
    {
      "id": "evidence_and_records",
      "title": "Evidence and records",
      "groups": [
        {
          "text": "These companions hold live records. This policy states what evidence it needs; it does not ship observations. An evidence ID without a dataset is an expectation. The Owner on the cover is accountable for those live records when you adopt the file."
        },
        {
          "items": [
            "[Mandatory Documents and Records Register](MDR_Mandatory_Documents_and_Records_Register.xlsx) — The 27 mandatory ISO 27001 documents and records, with owner, required status, approval, review cadence, location and evidence readiness.",
            "[Document Register](DR_Document_Register.xlsx) — Controlled documented information: origin, owner, approver, version, review cycle, retention and location.",
            "[Records Retention Schedule](RRS_Records_Retention_Schedule_Register.xlsx) — Retention rules for ISMS, security, privacy, audit and operational records, with owner, period, disposal method and evidence."
          ],
          "ordered": true,
          "relationView": "evidence"
        }
      ],
      "contentType": "evidence_table"
    },
    {
      "id": "external_references",
      "title": "References",
      "groups": [
        {
          "id": "linked_documents",
          "heading": "Linked documents",
          "level": 1,
          "text": "Availability is by book pack. In-pack files may sit next to this document after unpack. Other-book files are named, not shipped in this Office pack.",
          "rows": [
            {
              "Kind": "Artifact",
              "Reference": "AI Asset Inventory",
              "How this document uses it": "In-scope assets with owner, classification, hosting, personal-data flag and related risk In this book's pack when present.",
              "href": "AI_Asset_Inventory.xlsx",
              "availability": "in-pack"
            },
            {
              "Kind": "Artifact",
              "Reference": "SINV Supplier Inventory",
              "How this document uses it": "Security-relevant suppliers with tier, due diligence, contract controls, subprocessors and exit planning In this book's pack when present.",
              "href": "SINV_Supplier_Inventory.xlsx",
              "availability": "in-pack"
            },
            {
              "Kind": "Artifact",
              "Reference": "UAI Users and Access Inventory",
              "How this document uses it": "Users and accounts with access rights, privileged access, MFA status, reviews and revocations In this book's pack when present.",
              "href": "UAI_Users_and_Access_Inventory.xlsx",
              "availability": "in-pack"
            },
            {
              "Kind": "Artifact",
              "Reference": "MDR Mandatory Documents and Records Register",
              "How this document uses it": "The 27 mandatory ISO 27001 documents and records, with owner, required status, approval, review cadence, location and evidence readiness Another book's pack, not this Office pack.",
              "href": "MDR_Mandatory_Documents_and_Records_Register.xlsx",
              "availability": "other_volume"
            },
            {
              "Kind": "Artifact",
              "Reference": "DR Document Register",
              "How this document uses it": "Controlled documented information: origin, owner, approver, version, review cycle, retention and location In this book's pack when present.",
              "href": "DR_Document_Register.xlsx",
              "availability": "in-pack"
            },
            {
              "Kind": "Artifact",
              "Reference": "RRS Records Retention Schedule",
              "How this document uses it": "Retention rules for ISMS, security, privacy, audit and operational records, with owner, period, disposal method and evidence Another book's pack, not this Office pack.",
              "href": "RRS_Records_Retention_Schedule_Register.xlsx",
              "availability": "other_volume"
            },
            {
              "Kind": "Artifact",
              "Reference": "DCP Document Control Procedure (Secure Engineering, Access Control & Identity Management)",
              "href": "DCP_Document_Control_Procedure.docx",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record Another book's pack, not this Office pack.",
              "availability": "other_volume"
            },
            {
              "Kind": "Artifact",
              "Reference": "MME Monitoring and Measurement Evidence (Implementation & Certification, Monitoring, Measurement & Performance Metrics)",
              "href": "MME_Monitoring_and_Measurement_Evidence_Register.xlsx",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record In this book's pack when present.",
              "availability": "in-pack"
            },
            {
              "Kind": "Artifact",
              "Reference": "SRP Supplier Relationships Policy (Building the ISMS, Supplier Security & Third-party Risk Management)",
              "href": "SRP_Supplier_Relationships_Policy.docx",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record In this book's pack when present.",
              "availability": "in-pack"
            }
          ]
        },
        {
          "id": "external_sources",
          "heading": "External references",
          "level": 1,
          "text": "Cite these ISO clauses and book chapters from workshops and audits.",
          "rows": [
            {
              "Kind": "ISO",
              "Reference": "ISO/IEC 27001:2022",
              "How this document uses it": "Normative ISMS requirements this companion artifact supports.",
              "href": "https://www.iso.org/standard/82875.html"
            },
            {
              "Kind": "Book",
              "Reference": "Building the ISMS, Information Security Policies & Risk Management",
              "How this document uses it": "Primary operating chapter for this companion artifact.",
              "href": "https://www.amazon.com/dp/9789908983448"
            }
          ]
        }
      ],
      "contentType": "reference_table"
    }
  ],
  "enrichment": {
    "source": "Example.json",
    "method": "curated-json",
    "note": "Completes Example JSON with renderer-native sections and generalized groups; no mdSource helper fields."
  },
  "snapshotRef": {
    "snapshotId": "arcfield.platform.surv.2026-09-11",
    "schemaVersion": "evidenceSnapshot.v1"
  },
  "scenarioRef": {
    "crId": "CR-POL-EN-002",
    "dependsOn": [
      106,
      107
    ],
    "family": "Policy",
    "role": "Fictional Arcfield worked example. Not a real management-team approval and not a certification statement.",
    "reviewState": "pending",
    "provenance": "EXAMPLE_DECISION"
  }
}
