{
  "schemaVersion": "artifactExample.v2",
  "artifactId": "IGC",
  "title": "ISMS Governance Calendar",
  "definitionRef": {
    "artifactId": "IGC",
    "definitionSchemaVersion": "artifactDefinition.v2",
    "definitionId": "IGC.artifactDefinition.v2",
    "title": "ISMS Governance Calendar"
  },
  "organization": "Arcfield",
  "sections": [
    {
      "id": "title_page",
      "title": "Title Page",
      "values": {
        "Register Title": "ISMS Governance Calendar",
        "Register ID": "IGC-REG-001",
        "Version": "1.1",
        "Status": "Approved",
        "Organization": "Arcfield",
        "Owner": "ISMS Manager",
        "Approver": "Top Management",
        "Classification": "Internal",
        "Effective Date": "2026-09-11",
        "Next Review Date": "2027-09-11"
      },
      "items": [
        "Register Title: ISMS Governance Calendar",
        "Register ID: IGC-REG-001",
        "Version: 1.1",
        "Status: Approved",
        "Organization: Arcfield",
        "Owner: ISMS Manager",
        "Approver: Top Management",
        "Classification: Internal",
        "Effective Date: 2026-09-11",
        "Next Review Date: 2027-09-11"
      ],
      "contentType": "metadata"
    },
    {
      "id": "abstract",
      "title": "Abstract",
      "text": "The ISMS Governance Calendar provides a controlled, implementation-ready way to turn governance obligations into owned, scheduled, and traceable activities. It connects accountable work to source-system evidence, review decisions and follow-up actions so that the artifact can support both day-to-day operation and audit sampling. This calendar is the Arcfield Platform cadence in the surveillance cycle after certificate ARC-ISMS-2025-001.",
      "contentType": "narrative"
    },
    {
      "id": "document_control",
      "title": "Document Control",
      "rows": [
        {
          "Property": "Purpose",
          "Value": "Turn governance obligations into owned, scheduled, and traceable activities."
        },
        {
          "Property": "Used by",
          "Value": "ISMS Manager, Control Owners, Top Management"
        },
        {
          "Property": "Maintained by",
          "Value": "ISMS Manager"
        },
        {
          "Property": "Evidence role",
          "Value": "supporting tool"
        },
        {
          "Property": "ISO reference",
          "Value": "ISO/IEC 27001:2022 clauses 5–10"
        },
        {
          "Property": "Review cadence",
          "Value": "During ISMS establishment and annual planning; reviewed monthly."
        }
      ],
      "contentType": "control_table"
    },
    {
      "id": "instructions",
      "title": "Instructions",
      "items": [
        "Enter every recurring governance activity with owner, frequency, due date, dependencies, status, and evidence link.",
        "Review overdue items monthly and retain completed-period exports.",
        "Link every material conclusion to an authoritative and exportable source record.",
        "Assign an accountable owner and due date for each unresolved issue.",
        "Review and approve the completed artifact before it is used as audit evidence.",
        "Use sheets ending in “Ex” as read-only examples. Enter live data only on the matching “Wk” (Working) sheets.",
        "Every operative list is an Excel Table with frozen headers and filters. Add new rows on the next empty worksheet row beneath the table so Excel expands it — do not leave blank rows inside the table.",
        "Where a column offers a dropdown, choose a value from the list (Status, Owner role, Priority, Severity, Likelihood, Impact, Applicability, Evidence Status, Review Result). Do not invent free-text variants.",
        "Enter dates as YYYY-MM-DD. Date columns are validated and formatted accordingly.",
        "Review the Flag columns (Overdue, Review Due, Missing Owner, Missing Evidence). They calculate automatically and highlight gaps for follow-up.",
        "Keep Cover, Legal, Book, Lists and Metadata unchanged. System sheets are protected on purpose."
      ],
      "contentType": "ordered_list"
    },
    {
      "id": "isms_governance_calendar",
      "title": "Isms governance calendar",
      "rows": [
        {
          "Activity ID": "IGC-001",
          "Governance activity": "Production access review",
          "ISO reference": "A.8.29",
          "Owner": "ISMS Manager",
          "Approver": "Top Management",
          "Frequency": "Monthly",
          "Due date": "2026-08-29",
          "Status": "Complete",
          "Evidence reference": "JIRA-SEC-2026-014",
          "Next review": "Defined and evidenced"
        },
        {
          "Activity ID": "IGC-002",
          "Governance activity": "Security evidence validation",
          "ISO reference": "Clause 9.2",
          "Owner": "Security Lead",
          "Approver": "ISMS Manager",
          "Frequency": "Quarterly",
          "Due date": "2026-09-30",
          "Status": "In progress",
          "Evidence reference": "GRC-EVID-2026-Q3",
          "Next review": "Reviewed by accountable owner"
        },
        {
          "Activity ID": "IGC-003",
          "Governance activity": "Quarterly control review",
          "ISO reference": "A.5.18",
          "Owner": "Control Owner",
          "Approver": "Security Lead",
          "Frequency": "Annually",
          "Due date": "2026-11-29",
          "Status": "Pending review",
          "Evidence reference": "REVIEW-2026-Q3",
          "Next review": "See linked source record"
        },
        {
          "Activity ID": "IGC-004",
          "Governance activity": "Supplier control verification",
          "ISO reference": "A.8.29",
          "Owner": "ISMS Manager",
          "Approver": "Top Management",
          "Frequency": "Event-driven",
          "Due date": "2026-08-29",
          "Status": "Complete",
          "Evidence reference": "JIRA-SEC-2026-014",
          "Next review": "Approved with follow-up"
        },
        {
          "Activity ID": "IGC-005",
          "Governance activity": "Release security approval",
          "ISO reference": "Clause 9.2",
          "Owner": "Security Lead",
          "Approver": "ISMS Manager",
          "Frequency": "Per release",
          "Due date": "2026-09-30",
          "Status": "In progress",
          "Evidence reference": "GRC-EVID-2026-Q3",
          "Next review": "Pending independent review"
        }
      ],
      "schemaRef": {
        "definitionId": "IGC.artifactDefinition.v2",
        "sectionId": "isms_governance_calendar",
        "columnsRef": "sections.isms_governance_calendar.columns"
      },
      "contentType": "register_table"
    },
    {
      "id": "isms_governance_calendar_review",
      "title": "ISMS Governance Calendar review",
      "rows": [
        {
          "Field": "Review result",
          "Value": "Approved as an implementation candidate with JSON Definition, JSON Example and rendered-file QA still required."
        },
        {
          "Field": "Records reviewed",
          "Value": "5 example records"
        },
        {
          "Field": "Open issues",
          "Value": "Contract and renderer implementation pending"
        },
        {
          "Field": "Action owner",
          "Value": "ISMS Manager"
        },
        {
          "Field": "Reviewed by",
          "Value": "ISMS Manager"
        },
        {
          "Field": "Decision date",
          "Value": "2026-09-05"
        },
        {
          "Field": "Evidence reference",
          "Value": "IGC-REVIEW-2026-Q3"
        }
      ],
      "contentType": "decision_table"
    },
    {
      "id": "external_references",
      "title": "References",
      "groups": [
        {
          "text": "Cite these sources from workshops and audits. This list names ISO clauses, book chapters and companion artifacts used by this file."
        },
        {
          "rows": [
            {
              "Kind": "ISO",
              "Reference": "ISO/IEC 27001:2022",
              "How this document uses it": "Normative source this artifact implements or cites.",
              "href": "https://www.iso.org/standard/82875.html"
            },
            {
              "Kind": "Book",
              "Reference": "Building the ISMS, Context of the Organization (Clause 4)",
              "How this document uses it": "Primary operating chapter for this companion artifact.",
              "href": "https://www.amazon.com/dp/9789908983448"
            },
            {
              "Kind": "Artifact",
              "Reference": "ISO Information Security Objectives (Building the ISMS, Information Security Policies & Risk Management)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/dp/9789908983448"
            }
          ]
        }
      ],
      "contentType": "reference_table"
    }
  ],
  "generation": {
    "source": "Example.json",
    "method": "curated-json",
    "note": "Completes Example JSON with renderer-native sections and generalized groups; no mdSource helper fields."
  },
  "snapshotRef": {
    "snapshotId": "arcfield.platform.surv.2026-09-11",
    "schemaVersion": "evidenceSnapshot.v1"
  },
  "scenarioRef": {
    "githubIssue": 64,
    "crId": "CR-TYPE-ARCFIELD-001",
    "family": "Calendar",
    "role": "Cadence of the certified ISMS"
  }
}
