{
  "schemaVersion": "artifactExample.v2",
  "artifactId": "IMPL-WB",
  "title": "Operational ISMS Dashboard",
  "definitionRef": {
    "artifactId": "IMPL-WB",
    "definitionSchemaVersion": "artifactDefinition.v2",
    "definitionId": "IMPL-WB.artifactDefinition.v2",
    "title": "ISMS Implementation Workbook"
  },
  "organization": "Arcfield",
  "sections": [
    {
      "id": "title_page",
      "title": "Title Page",
      "values": {
        "Dashboard Title": "Operational ISMS Dashboard",
        "Dashboard ID": "IMPL-WB-XLSX-001",
        "Version": "1.1",
        "Status": "Approved",
        "Organization": "Arcfield",
        "Owner": "ISMS Manager",
        "Approver": "Top Management",
        "Classification": "Internal",
        "Effective Date": "2026-09-11",
        "Next Review Date": "2027-09-11"
      },
      "items": [
        "Dashboard Title: ISMS Implementation Workbook",
        "Dashboard ID: IMPL-WB-XLSX-001",
        "Version: 1.1",
        "Status: Approved",
        "Organization: Arcfield",
        "Owner: ISMS Manager",
        "Approver: Top Management",
        "Classification: Internal",
        "Effective Date: 2026-09-11",
        "Next Review Date: 2027-09-11"
      ],
      "contentType": "metadata"
    },
    {
      "id": "abstract",
      "title": "Abstract",
      "text": "This example is the operational ISMS dashboard for the Arcfield / Arcfield Platform freeze. It shows how the ISMS is running: SoA implementation and evidence, approved mandatory documents, untreated high risks, metrics below target, open CARs, open incidents and improvements, last management review, next internal audit and certificate validity. The next-audit preview is the same 9.2 engine as the internal audit report on this freeze; it is not a recertification decision. KPIs are derived from the 11 September 2026 freeze; this workbook is not a second SoA. It belongs to the surveillance cycle after certificate ARC-ISMS-2025-001.",
      "contentType": "narrative"
    },
    {
      "id": "document_control",
      "title": "Document Control",
      "values": {
        "Document owner": "ISMS Manager",
        "Approved by": "Top Management",
        "Version": "1.0",
        "Status": "Example",
        "Review cadence": "Weekly during audit preparation",
        "Last reviewed": "2026-08-29",
        "Next review": "2026-09-30"
      },
      "rows": [
        {
          "Property": "Purpose",
          "Value": "Provide a central workbook for applying the Book 2 ISMS implementation process and tracking audit readiness."
        },
        {
          "Property": "Used by",
          "Value": "ISMS Manager, Top Management, Process Owners, Internal Auditor"
        },
        {
          "Property": "Maintained by",
          "Value": "ISMS Manager"
        },
        {
          "Property": "Evidence role",
          "Value": "Supporting implementation and readiness dashboard"
        },
        {
          "Property": "ISO reference",
          "Value": "ISO/IEC 27001:2022 Clauses 4.4, 6.1, 6.2, 7.5, 8.1, 9.1, 9.2, 9.3 and 10.1"
        },
        {
          "Property": "Review cadence",
          "Value": "Weekly during implementation, before each audit milestone and before management review"
        }
      ],
      "contentType": "control_table"
    },
    {
      "id": "instructions",
      "title": "Instructions",
      "items": [
        "Use the workbook to track implementation status, not to replace the underlying evidence artifacts.",
        "Keep every sheet tied to an owner, source artifact, output and review cadence.",
        "Update readiness metrics with evidence references.",
        "Convert gaps into owned actions with priority and target date.",
        "Review dashboard status before internal audit, management review and certification milestones.",
        "Keep lookup values aligned with current artifact standards.",
        "Use sheets ending in “Ex” as read-only examples. Enter live data only on the matching “Wk” (Working) sheets.",
        "Every operative list is an Excel Table with frozen headers and filters. Add new rows on the next empty worksheet row beneath the table so Excel expands it — do not leave blank rows inside the table.",
        "Where a column offers a dropdown, choose a value from the list (Status, Owner role, Priority, Severity, Likelihood, Impact, Applicability, Evidence Status, Review Result). Do not invent free-text variants.",
        "Enter dates as YYYY-MM-DD. Date columns are validated and formatted accordingly.",
        "Review the Flag columns (Overdue, Review Due, Missing Owner, Missing Evidence). They calculate automatically and highlight gaps for follow-up.",
        "Keep Cover, Legal, Book, Lists and Metadata unchanged. System sheets are protected on purpose.",
        "Open the Dashboard sheet for automatic KPIs and charts driven by Working-table formulas — do not type KPI values by hand.",
        "Use the Traceability sheet to confirm Risk → Treatment → Control → SoA → Evidence → Action ID columns are present and populated."
      ],
      "contentType": "ordered_list"
    },
    {
      "id": "dashboard_schema",
      "title": "Dashboard schema",
      "schemaRef": {
        "definitionId": "IMPL-WB.artifactDefinition.v2",
        "sectionId": "dashboard_schema"
      },
      "sheets": [
        "Dashboard",
        "Packs",
        "Members",
        "ClauseLinks",
        "ClauseStatus",
        "SoA",
        "Mandatory",
        "HighRisk",
        "MME",
        "OpenActions",
        "Incidents",
        "Phases",
        "Cadence",
        "AuditDates",
        "AuditPreview",
        "AuditFindings"
      ],
      "rows": [
        {
          "Sheet": "Packs",
          "Required output": "clause_pack_existence",
          "Evidence link": "snapshot"
        },
        {
          "Sheet": "Members",
          "Required output": "snapshot_membership",
          "Evidence link": "snapshot"
        },
        {
          "Sheet": "ClauseLinks",
          "Required output": "reqt_linked_in_snapshot",
          "Evidence link": "REQT"
        },
        {
          "Sheet": "ClauseStatus",
          "Required output": "direct",
          "Evidence link": "REQT"
        },
        {
          "Sheet": "SoA",
          "Required output": "direct",
          "Evidence link": "SOA"
        },
        {
          "Sheet": "Mandatory",
          "Required output": "direct",
          "Evidence link": "MDR"
        },
        {
          "Sheet": "HighRisk",
          "Required output": "direct",
          "Evidence link": "RR"
        },
        {
          "Sheet": "MME",
          "Required output": "direct",
          "Evidence link": "MME"
        },
        {
          "Sheet": "OpenActions",
          "Required output": "direct",
          "Evidence link": "CAR, CIL, S1-RDY, REQT"
        },
        {
          "Sheet": "Incidents",
          "Required output": "direct",
          "Evidence link": "IL"
        },
        {
          "Sheet": "Phases",
          "Required output": "direct",
          "Evidence link": "IMPL-P"
        },
        {
          "Sheet": "Cadence",
          "Required output": "review_and_certificate_dates",
          "Evidence link": "MRMT"
        },
        {
          "Sheet": "AuditDates",
          "Required output": "direct",
          "Evidence link": "IAP"
        },
        {
          "Sheet": "AuditPreview",
          "Required output": "iar_score_freeze",
          "Evidence link": "snapshot"
        },
        {
          "Sheet": "AuditFindings",
          "Required output": "iar_score_freeze",
          "Evidence link": "snapshot"
        }
      ],
      "contentType": "dashboard_schema"
    },
    {
      "id": "dashboard_summary",
      "title": "Dashboard summary",
      "schemaRef": {
        "definitionId": "IMPL-WB.artifactDefinition.v2",
        "sectionId": "dashboard_summary",
        "fieldsRef": "sections.dashboard_summary.fields"
      },
      "values": {
        "SoA implemented / applicable": "60/89",
        "SoA evidence complete / recorded": "17/93",
        "Mandatory documents approved": "9/27",
        "MME metrics below target": "4",
        "High risks without treatment ID": "0",
        "Open CARs": "4",
        "Open incidents": "3",
        "Open improvements": "4",
        "Last management review": "2026-08-29",
        "Next internal audit": "2026-09-12",
        "Certificate valid until": "2028-11-27"
      },
      "rows": [
        {
          "Field": "SoA implemented / applicable",
          "Value": "60/89"
        },
        {
          "Field": "SoA evidence complete / recorded",
          "Value": "17/93"
        },
        {
          "Field": "Mandatory documents approved",
          "Value": "9/27"
        },
        {
          "Field": "MME metrics below target",
          "Value": "4"
        },
        {
          "Field": "High risks without treatment ID",
          "Value": "0"
        },
        {
          "Field": "Open CARs",
          "Value": "4"
        },
        {
          "Field": "Open incidents",
          "Value": "3"
        },
        {
          "Field": "Open improvements",
          "Value": "4"
        },
        {
          "Field": "Last management review",
          "Value": "2026-08-29"
        },
        {
          "Field": "Next internal audit",
          "Value": "2026-09-12"
        },
        {
          "Field": "Certificate valid until",
          "Value": "2028-11-27"
        }
      ],
      "contentType": "summary_table"
    },
    {
      "id": "workbook_dashboard_sections",
      "title": "Workbook / dashboard sections",
      "schemaRef": {
        "definitionId": "IMPL-WB.artifactDefinition.v2",
        "sectionId": "workbook_dashboard_sections",
        "columnsRef": "sections.workbook_dashboard_sections.columns"
      },
      "rows": [
        {
          "Sheet ID": "IMPL-WB-P4",
          "Sheet Name": "Context of the organization",
          "Purpose": "Clause pack existence in the evidence snapshot.",
          "Primary Owner": "ISMS Manager",
          "Source Artifact": "OS, ISS",
          "Key Output": "2/2",
          "Review Cadence": "Each freeze",
          "Status": "Ready"
        },
        {
          "Sheet ID": "IMPL-WB-P5",
          "Sheet Name": "Leadership",
          "Purpose": "Clause pack existence in the evidence snapshot.",
          "Primary Owner": "ISMS Manager",
          "Source Artifact": "ISP",
          "Key Output": "1/1",
          "Review Cadence": "Each freeze",
          "Status": "Ready"
        },
        {
          "Sheet ID": "IMPL-WB-P6",
          "Sheet Name": "Planning",
          "Purpose": "Clause pack existence in the evidence snapshot.",
          "Primary Owner": "ISMS Manager",
          "Source Artifact": "RAM, REQT",
          "Key Output": "2/2",
          "Review Cadence": "Each freeze",
          "Status": "Ready"
        },
        {
          "Sheet ID": "IMPL-WB-P7",
          "Sheet Name": "Support",
          "Purpose": "Clause pack existence in the evidence snapshot.",
          "Primary Owner": "ISMS Manager",
          "Source Artifact": "DCP, MDR",
          "Key Output": "2/2",
          "Review Cadence": "Each freeze",
          "Status": "Ready"
        },
        {
          "Sheet ID": "IMPL-WB-P8",
          "Sheet Name": "Operation",
          "Purpose": "Clause pack existence in the evidence snapshot.",
          "Primary Owner": "ISMS Manager",
          "Source Artifact": "ICP, IRPROC",
          "Key Output": "2/2",
          "Review Cadence": "Each freeze",
          "Status": "Ready"
        },
        {
          "Sheet ID": "IMPL-WB-P9",
          "Sheet Name": "Performance evaluation",
          "Purpose": "Clause pack existence in the evidence snapshot.",
          "Primary Owner": "ISMS Manager",
          "Source Artifact": "IAP, MRMT",
          "Key Output": "2/2",
          "Review Cadence": "Each freeze",
          "Status": "Ready"
        },
        {
          "Sheet ID": "IMPL-WB-P10",
          "Sheet Name": "Improvement",
          "Purpose": "Clause pack existence in the evidence snapshot.",
          "Primary Owner": "ISMS Manager",
          "Source Artifact": "NC-RP",
          "Key Output": "1/1",
          "Review Cadence": "Each freeze",
          "Status": "Ready"
        }
      ],
      "contentType": "section_table"
    },
    {
      "id": "key_metrics_readiness_status",
      "title": "Key metrics and readiness status",
      "schemaRef": {
        "definitionId": "IMPL-WB.artifactDefinition.v2",
        "sectionId": "key_metrics_readiness_status",
        "columnsRef": "sections.key_metrics_readiness_status.columns"
      },
      "rows": [
        {
          "Metric ID": "MME-001",
          "Metric": "Security awareness completion rate",
          "Target": ">= 98% within 30 days",
          "Current": "96%",
          "Status": "Below target",
          "Owner": "HR Manager",
          "Evidence Reference": "TR-2026-Q3",
          "Notes": "Related to EXR-005 closure."
        },
        {
          "Metric ID": "MME-002",
          "Metric": "Privileged access review completion",
          "Target": "100% critical systems reviewed monthly",
          "Current": "4 of 5 systems reviewed",
          "Status": "Below target",
          "Owner": "IT Operations Manager",
          "Evidence Reference": "ARR-2026-08",
          "Notes": "Cloud admin exception open."
        },
        {
          "Metric ID": "MME-003",
          "Metric": "High-risk treatment overdue count",
          "Target": "0 overdue high-risk treatments",
          "Current": "1 overdue",
          "Status": "Below target",
          "Owner": "Compliance Lead",
          "Evidence Reference": "RTP-2026-Q3",
          "Notes": "Management review input required."
        },
        {
          "Metric ID": "MME-004",
          "Metric": "Incident closure within SLA",
          "Target": ">= 90% medium/high incidents closed within SLA",
          "Current": "83%",
          "Status": "Below target",
          "Owner": "Incident Manager",
          "Evidence Reference": "IL-REVIEW-2026-08",
          "Notes": "One supplier incident open."
        },
        {
          "Metric ID": "MME-005",
          "Metric": "Evidence pack completeness",
          "Target": ">= 95% complete before freeze",
          "Current": "91%",
          "Status": "In progress",
          "Owner": "Internal Auditor",
          "Evidence Reference": "ELAI-2026-Q3",
          "Notes": "ICL-006 freeze notice sent."
        },
        {
          "Metric ID": "MME-006",
          "Metric": "Critical supplier assurance evidence current",
          "Target": "100% current evidence for critical suppliers",
          "Current": "5 of 6 suppliers current",
          "Status": "In progress",
          "Owner": "Supplier Manager",
          "Evidence Reference": "SINV-CLOUDHOST-2026-Q3",
          "Notes": "Contract addendum pending."
        }
      ],
      "contentType": "metric_table"
    },
    {
      "id": "evidence_gaps_actions",
      "title": "Evidence gaps and actions",
      "schemaRef": {
        "definitionId": "IMPL-WB.artifactDefinition.v2",
        "sectionId": "evidence_gaps_actions",
        "columnsRef": "sections.evidence_gaps_actions.columns"
      },
      "rows": [
        {
          "Action ID": "CAR-001",
          "Gap": "Audit evidence for privileged access review was incomplete for two production systems.",
          "Related Area": "Clause 9.2",
          "Owner": "IT Operations Manager",
          "Priority": "Minor nonconformity",
          "Target Date": "2026-09-15",
          "Evidence Reference": "CAR-001-ACC-REV",
          "Status": "In progress"
        },
        {
          "Action ID": "CAR-003",
          "Gap": "Competence evidence for two control owners was outdated.",
          "Related Area": "Clause 7.2",
          "Owner": "HR Manager",
          "Priority": "Minor nonconformity",
          "Target Date": "2026-08-25",
          "Evidence Reference": "CAR-003-CMTP",
          "Status": "Effectiveness check"
        },
        {
          "Action ID": "CAR-004",
          "Gap": "One critical supplier agreement lacked explicit breach-notification timing.",
          "Related Area": "A.5.20",
          "Owner": "Supplier Manager",
          "Priority": "Improvement",
          "Target Date": "2026-09-30",
          "Evidence Reference": "CAR-004-SUP",
          "Status": "In progress"
        },
        {
          "Action ID": "CAR-2026-027",
          "Gap": "IL-005: Manual change outside the standard deployment workflow. Internal draft articles were world-readable for 12 minutes. No confirmed Arcfield Platform customer PII exposure.",
          "Related Area": "A.8.9, A.8.32, A.5.15, A.5.37",
          "Owner": "Engineering Lead",
          "Priority": "Minor nonconformity",
          "Target Date": "2026-10-15",
          "Evidence Reference": "CHG-POST-2026-0822",
          "Status": "In progress"
        },
        {
          "Action ID": "CIL-001",
          "Gap": "Automate evidence reminders for access reviews.",
          "Related Area": "A.5.18; Clause 9.2",
          "Owner": "IT Operations Manager",
          "Priority": "High",
          "Target Date": "2026-09-30",
          "Evidence Reference": "Linked to CAR-001.",
          "Status": "In progress"
        },
        {
          "Action ID": "CIL-002",
          "Gap": "Add supplier exit-readiness status to the supplier inventory.",
          "Related Area": "A.5.19; A.5.20",
          "Owner": "Supplier Manager",
          "Priority": "Medium",
          "Target Date": "2026-10-15",
          "Evidence Reference": "Prioritize cloud hosting supplier.",
          "Status": "Proposed"
        },
        {
          "Action ID": "CIL-004",
          "Gap": "Create a short secure remote-working refresher.",
          "Related Area": "A.6.7",
          "Owner": "HR Manager",
          "Priority": "Low",
          "Target Date": "2026-12-15",
          "Evidence Reference": "Combine with annual awareness refresh.",
          "Status": "Deferred"
        },
        {
          "Action ID": "CIL-005",
          "Gap": "Introduce data masking for production-like test data.",
          "Related Area": "A.8.11; A.8.33",
          "Owner": "Engineering Lead",
          "Priority": "High",
          "Target Date": "2026-10-31",
          "Evidence Reference": "Aligned with SoA planned controls.",
          "Status": "In progress"
        },
        {
          "Action ID": "S1-RDY-004",
          "Gap": "IL-005 re-sample and stalled A.5.27 still open",
          "Related Area": "Clause 9.2",
          "Owner": "Security Lead",
          "Priority": "P2",
          "Target Date": "2026-10-31",
          "Evidence Reference": "GRC-EVID-2026-Q3",
          "Status": "In progress"
        },
        {
          "Action ID": "S1-RDY-005",
          "Gap": "CB visit not yet held",
          "Related Area": "Clause 9.2 / 9.3",
          "Owner": "ISMS Manager",
          "Priority": "P2",
          "Target Date": "2026-11-30",
          "Evidence Reference": "CB-SEL",
          "Status": "Pending review"
        },
        {
          "Action ID": "8.3",
          "Gap": "Close open treatment effectiveness checks.",
          "Related Area": "Information security risk treatment",
          "Owner": "Risk Manager",
          "Priority": "P2",
          "Target Date": "2026-10-31",
          "Evidence Reference": "RTP-OPEN-2026-Q3",
          "Status": "In progress"
        }
      ],
      "contentType": "action_table"
    },
    {
      "id": "review_and_decision",
      "title": "Review and decision",
      "values": {
        "Decision": "KPI values are Excel formulas over measure slices loaded from the evidence snapshot. This workbook does not store a separate readiness percentage.",
        "Workbook sections reviewed": "7",
        "Metrics reviewed": "6",
        "Open gaps": "11",
        "Next milestone": "2026-09-12",
        "Reviewed by": "ISMS Manager",
        "Decision date": "2026-08-29",
        "Evidence reference": "arcfield.platform.surv.2026-09-11"
      },
      "rows": [
        {
          "Field": "Decision",
          "Value": "KPI values are Excel formulas over measure slices loaded from the evidence snapshot. This workbook does not store a separate readiness percentage."
        },
        {
          "Field": "Workbook sections reviewed",
          "Value": "7"
        },
        {
          "Field": "Metrics reviewed",
          "Value": "6"
        },
        {
          "Field": "Open gaps",
          "Value": "11"
        },
        {
          "Field": "Next milestone",
          "Value": "2026-09-12"
        },
        {
          "Field": "Reviewed by",
          "Value": "ISMS Manager"
        },
        {
          "Field": "Decision date",
          "Value": "2026-08-29"
        },
        {
          "Field": "Evidence reference",
          "Value": "arcfield.platform.surv.2026-09-11"
        }
      ],
      "contentType": "decision_table"
    },
    {
      "id": "external_references",
      "title": "References",
      "groups": [
        {
          "text": "Cite these sources from workshops and audits. This list names ISO clauses, book chapters and companion artifacts used by this file."
        },
        {
          "rows": [
            {
              "Kind": "ISO",
              "Reference": "ISO/IEC 27001:2022",
              "How this document uses it": "Normative source this artifact implements or cites.",
              "href": "https://www.iso.org/standard/82875.html"
            },
            {
              "Kind": "Book",
              "Reference": "Implementation & Certification, Implementation Readiness & Planning",
              "How this document uses it": "Primary operating chapter for this companion artifact.",
              "href": "https://www.amazon.com/s?k=ISO+27001+for+Software+Companies+Implementation+and+Certification"
            },
            {
              "Kind": "Artifact",
              "Reference": "DCP Document Control Procedure (Secure Engineering, Access Control & Identity Management)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/dp/9789908983455"
            },
            {
              "Kind": "Artifact",
              "Reference": "ELAI Evidence Log / Audit Pack Index (Implementation & Certification, Audit Process)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/s?k=ISO+27001+for+Software+Companies+Implementation+and+Certification"
            },
            {
              "Kind": "Artifact",
              "Reference": "MDR Mandatory Documents and Records Register (Implementation & Certification, Asset Management & Information Classification)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/s?k=ISO+27001+for+Software+Companies+Implementation+and+Certification"
            },
            {
              "Kind": "Artifact",
              "Reference": "REQT ISO 27001 Clauses 4-10 Requirements Tracker (Dual Compliance, ISO 27001 & NIS2)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/dp/9789908983479"
            }
          ]
        }
      ],
      "contentType": "reference_table"
    }
  ],
  "enrichment": {
    "source": "Example.json",
    "method": "curated-json",
    "note": "Completes Example JSON with renderer-native sections and generalized groups; no mdSource helper fields."
  },
  "snapshotRef": {
    "snapshotId": "arcfield.platform.surv.2026-09-11",
    "schemaVersion": "evidenceSnapshot.v1"
  },
  "scenarioRef": {
    "githubIssue": 64,
    "crId": "CR-TYPE-ARCFIELD-001",
    "family": "Dashboard",
    "role": "Derived KPIs over the freeze, not a second SoA"
  }
}
