{
  "schemaVersion": "artifactExample.v2",
  "artifactId": "IPR",
  "title": "Interested Parties Register",
  "definitionRef": {
    "artifactId": "IPR",
    "definitionSchemaVersion": "artifactDefinition.v2",
    "definitionId": "IPR.artifactDefinition.v2",
    "title": "Interested Parties Register"
  },
  "organization": "Arcfield",
  "sections": [
    {
      "id": "title_page",
      "title": "Title Page",
      "values": {
        "Register Title": "Interested Parties Register",
        "Register ID": "IPR-REG-001",
        "Version": "1.1",
        "Status": "Approved",
        "Organization": "Arcfield",
        "Owner": "ISMS Manager",
        "Approver": "Top Management",
        "Classification": "Internal",
        "Effective Date": "2026-09-11",
        "Next Review Date": "2027-09-11"
      },
      "items": [
        "Register Title: Interested Parties Register",
        "Register ID: IPR-REG-001",
        "Version: 1.1",
        "Status: Approved",
        "Organization: Arcfield",
        "Owner: ISMS Manager",
        "Approver: Top Management",
        "Classification: Internal",
        "Effective Date: 2026-09-11",
        "Next Review Date: 2027-09-11"
      ],
      "contentType": "metadata"
    },
    {
      "id": "abstract",
      "title": "Abstract",
      "text": "This example identifies Arcfield interested parties, their ISMS-relevant requirements, sources, affected processes or controls, evidence expectations, owners and review cadence. Rows are the 11 September 2026 operating sample of the certified Arcfield Platform ISMS in the surveillance cycle after certificate ARC-ISMS-2025-001.",
      "contentType": "narrative"
    },
    {
      "id": "document_control",
      "title": "Document Control",
      "rows": [
        {
          "Property": "Purpose",
          "Value": "Maintain Clause 4.2 interested-party requirements and evidence expectations."
        },
        {
          "Property": "Used by",
          "Value": "ISMS Manager, Legal, Compliance Lead, Process Owners, Internal Auditor"
        },
        {
          "Property": "Maintained by",
          "Value": "ISMS Manager"
        },
        {
          "Property": "Evidence role",
          "Value": "Mandatory ISMS context evidence"
        },
        {
          "Property": "ISO reference",
          "Value": "ISO/IEC 27001:2022 Clause 4.2"
        },
        {
          "Property": "Review cadence",
          "Value": "Quarterly and after major scope, legal, customer or supplier changes"
        }
      ],
      "contentType": "control_table"
    },
    {
      "id": "instructions",
      "title": "Instructions",
      "items": [
        "List interested parties that can affect or be affected by the ISMS.",
        "Record each party’s relevant requirement and the source of that requirement.",
        "Describe why the requirement matters to the ISMS.",
        "Link the affected process, control or evidence expectation.",
        "Assign an owner and review cadence.",
        "Review changes before management review and after major customer, legal or supplier changes.",
        "Use sheets ending in “Ex” as read-only examples. Enter live data only on the matching “Wk” (Working) sheets.",
        "Every operative list is an Excel Table with frozen headers and filters. Add new rows on the next empty worksheet row beneath the table so Excel expands it — do not leave blank rows inside the table.",
        "Where a column offers a dropdown, choose a value from the list (Status, Owner role, Priority, Severity, Likelihood, Impact, Applicability, Evidence Status, Review Result). Do not invent free-text variants.",
        "Enter dates as YYYY-MM-DD. Date columns are validated and formatted accordingly.",
        "Review the Flag columns (Overdue, Review Due, Missing Owner, Missing Evidence). They calculate automatically and highlight gaps for follow-up.",
        "Keep Cover, Legal, Book, Lists and Metadata unchanged. System sheets are protected on purpose."
      ],
      "contentType": "ordered_list"
    },
    {
      "id": "interested_parties_register",
      "title": "Interested parties register",
      "schemaRef": {
        "definitionId": "IPR.artifactDefinition.v2",
        "sectionId": "interested_parties_register",
        "columnsRef": "sections.interested_parties_register.columns"
      },
      "rows": [
        {
          "Party ID": "IPR-001",
          "Interested Party": "Enterprise customers",
          "Category": "Customer",
          "Relevant Requirement": "Evidence that customer support data is protected and incidents are communicated promptly.",
          "Source": "Master service agreement and security addendum",
          "ISMS Relevance": "Defines assurance evidence, incident communication and access-control expectations.",
          "Affected Process or Control": "A.5.20, A.5.24, A.8.2",
          "Evidence Expectation": "SoA, incident log, access review and audit pack index.",
          "Owner": "Compliance Lead",
          "Review Cadence": "Quarterly and before contract renewal",
          "Status": "Active",
          "Evidence Reference": "ELAI-2026-Q3",
          "Notes": "Strategic customer addendum under review."
        },
        {
          "Party ID": "IPR-002",
          "Interested Party": "Regulators and supervisory authorities",
          "Category": "Regulator",
          "Relevant Requirement": "Security incidents and privacy-relevant events must be handled and evidenced.",
          "Source": "Applicable legal and regulatory register",
          "ISMS Relevance": "Drives incident, breach and evidence-retention requirements.",
          "Affected Process or Control": "A.5.24-A.5.28, Clause 8.1",
          "Evidence Expectation": "Incident records, legal register and corrective actions.",
          "Owner": "Legal Counsel",
          "Review Cadence": "Semi-annually and after regulatory change",
          "Status": "Active",
          "Evidence Reference": "LRR-2026-Q3",
          "Notes": "Privacy owner participates in review."
        },
        {
          "Party ID": "IPR-003",
          "Interested Party": "Employees and contractors",
          "Category": "Internal",
          "Relevant Requirement": "Clear security responsibilities, training and reporting channels.",
          "Source": "Employment agreements, policies and onboarding process",
          "ISMS Relevance": "Supports competence, awareness, acceptable use and incident reporting.",
          "Affected Process or Control": "A.6.3, A.6.8, Clause 7.2, Clause 7.3",
          "Evidence Expectation": "Training records, onboarding checklist and communication log.",
          "Owner": "HR Manager",
          "Review Cadence": "Quarterly",
          "Status": "Active",
          "Evidence Reference": "TR-2026-Q3",
          "Notes": "Contractor onboarding exception closed."
        },
        {
          "Party ID": "IPR-004",
          "Interested Party": "Critical cloud suppliers",
          "Category": "Supplier",
          "Relevant Requirement": "Maintain security commitments, availability evidence and incident notification routes.",
          "Source": "Supplier agreements and due diligence records",
          "ISMS Relevance": "Drives supplier monitoring, continuity and incident dependencies.",
          "Affected Process or Control": "A.5.19-A.5.23, A.5.30",
          "Evidence Expectation": "Supplier inventory, supplier assessment and continuity evidence.",
          "Owner": "Supplier Manager",
          "Review Cadence": "Quarterly for critical suppliers",
          "Status": "Active",
          "Evidence Reference": "SINV-CLOUDHOST-2026-Q3",
          "Notes": "Exit clause follow-up open."
        },
        {
          "Party ID": "IPR-005",
          "Interested Party": "Top management",
          "Category": "Governance",
          "Relevant Requirement": "Visibility into ISMS performance, risk treatment, audit readiness and improvement actions.",
          "Source": "ISO/IEC 27001 governance requirements",
          "ISMS Relevance": "Defines management review and decision evidence.",
          "Affected Process or Control": "Clause 5.1, Clause 9.3, Clause 10.2",
          "Evidence Expectation": "Management review minutes, objectives status and corrective action register.",
          "Owner": "ISMS Manager",
          "Review Cadence": "Quarterly",
          "Status": "Active",
          "Evidence Reference": "MR-2026-Q3",
          "Notes": "Dashboard format agreed."
        },
        {
          "Party ID": "IPR-006",
          "Interested Party": "Internal auditors",
          "Category": "Assurance",
          "Relevant Requirement": "Access to complete, current and traceable ISMS evidence.",
          "Source": "Internal audit programme",
          "ISMS Relevance": "Drives evidence readiness and audit pack completeness.",
          "Affected Process or Control": "Clause 9.2, Clause 7.5",
          "Evidence Expectation": "Evidence log and mandatory document register.",
          "Owner": "Internal Auditor",
          "Review Cadence": "Before each audit cycle",
          "Status": "Active",
          "Evidence Reference": "IAP-2026-Q4",
          "Notes": "Evidence freeze planned."
        },
        {
          "Party ID": "IPR-007",
          "Interested Party": "Product engineering",
          "Category": "Internal",
          "Relevant Requirement": "Security changes must be risk-assessed, tested and traceable.",
          "Source": "Secure development and change management process",
          "ISMS Relevance": "Supports operational planning, change control and secure development.",
          "Affected Process or Control": "A.8.25, A.8.29, Clause 8.1",
          "Evidence Expectation": "Change log, testing evidence and vulnerability remediation records.",
          "Owner": "Engineering Lead",
          "Review Cadence": "Monthly",
          "Status": "Active",
          "Evidence Reference": "CIL-2026-Q3",
          "Notes": "Storage permission change corrective action open."
        }
      ],
      "contentType": "register_table"
    },
    {
      "id": "interested_parties_review",
      "title": "Interested parties review",
      "values": {
        "Review result": "Clause 4.2 requirements reviewed and mapped to active evidence expectations",
        "Parties reviewed": 7,
        "New or changed requirements": "Customer security addendum and supplier exit clause follow-up",
        "Open follow-up actions": "Update legal register and supplier evidence request",
        "Reviewed by": "ISMS Manager",
        "Decision date": "2026-08-29",
        "Evidence reference": "IPR-REVIEW-2026-Q3"
      },
      "rows": [
        {
          "Field": "Review result",
          "Value": "Clause 4.2 requirements reviewed and mapped to active evidence expectations"
        },
        {
          "Field": "Parties reviewed",
          "Value": "7"
        },
        {
          "Field": "New or changed requirements",
          "Value": "Customer security addendum and supplier exit clause follow-up"
        },
        {
          "Field": "Open follow-up actions",
          "Value": "Update legal register and supplier evidence request"
        },
        {
          "Field": "Reviewed by",
          "Value": "ISMS Manager"
        },
        {
          "Field": "Decision date",
          "Value": "2026-08-29"
        },
        {
          "Field": "Evidence reference",
          "Value": "IPR-REVIEW-2026-Q3"
        }
      ],
      "contentType": "decision_table"
    },
    {
      "id": "external_references",
      "title": "References",
      "groups": [
        {
          "text": "Cite these sources from workshops and audits. This list names ISO clauses, book chapters and companion artifacts used by this file."
        },
        {
          "rows": [
            {
              "Kind": "ISO",
              "Reference": "ISO/IEC 27001:2022 4.2",
              "How this document uses it": "Normative source this artifact implements or cites.",
              "href": "https://www.iso.org/standard/82875.html"
            },
            {
              "Kind": "Book",
              "Reference": "Building the ISMS, Annex A Controls",
              "How this document uses it": "Primary operating chapter for this companion artifact.",
              "href": "https://www.amazon.com/dp/9789908983448"
            },
            {
              "Kind": "Artifact",
              "Reference": "ISO Information Security Objectives (Building the ISMS, Information Security Policies & Risk Management)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/dp/9789908983448"
            },
            {
              "Kind": "Artifact",
              "Reference": "CIL Continual Improvement Log (Building the ISMS, Continual Improvement (Clause 10))",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/dp/9789908983448"
            },
            {
              "Kind": "Artifact",
              "Reference": "ELAI Evidence Log / Audit Pack Index (Implementation & Certification, Audit Process)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/s?k=ISO+27001+for+Software+Companies+Implementation+and+Certification"
            },
            {
              "Kind": "Artifact",
              "Reference": "IAP Internal Audit Plan (Implementation & Certification, Internal Audit & Management Review)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/s?k=ISO+27001+for+Software+Companies+Implementation+and+Certification"
            }
          ]
        }
      ],
      "contentType": "reference_table"
    }
  ],
  "enrichment": {
    "source": "Example.json",
    "method": "curated-json",
    "note": "Completes Example JSON with renderer-native sections and generalized groups; no mdSource helper fields."
  },
  "snapshotRef": {
    "snapshotId": "arcfield.platform.surv.2026-09-11",
    "schemaVersion": "evidenceSnapshot.v1"
  },
  "scenarioRef": {
    "githubIssue": 64,
    "crId": "CR-TYPE-ARCFIELD-001",
    "family": "Register",
    "role": "Operating sample of the 11 September 2026 freeze"
  }
}
