{
  "schemaVersion": "artifactDefinition.v2",
  "definitionId": "IRAR.artifactDefinition.v2",
  "artifactId": "IRAR",
  "title": "ISMS Role Appointment Record",
  "artifactType": "Register",
  "format": "xlsx",
  "productTier": "Basic",
  "definitionRole": "contract",
  "sourceModel": {
    "body": "canonical human-readable body in this Contract and the matching Example JSON",
    "jsonDefinition": "machine-readable contract and validation model",
    "jsonExample": "curated realistic example data fixture"
  },
  "purpose": "Provide explicit evidence that ISMS roles and authorities have been assigned and accepted.",
  "sections": [
    {
      "order": 1,
      "id": "title_page",
      "title": "Title Page",
      "contentType": "metadata",
      "required": true,
      "hint": null
    },
    {
      "order": 2,
      "id": "abstract",
      "title": "Abstract",
      "contentType": "narrative",
      "required": true,
      "hint": {
        "text": "Use this artifact as an evidence-backed working record. A completed field without an owner, date or source reference is not audit-ready.",
        "bookReference": "Volume 1, S-00-01-00 Context of the Organization (Clause 4"
      }
    },
    {
      "order": 3,
      "id": "document_control",
      "title": "Document Control",
      "contentType": "control_table",
      "required": true,
      "hint": null
    },
    {
      "order": 4,
      "id": "instructions",
      "title": "Instructions",
      "contentType": "ordered_list",
      "required": true,
      "hint": {
        "text": "Keep the artifact synchronized with its operational system of record and retain review evidence before external use.",
        "bookReference": "Volume 1, S-00-01-00 Context of the Organization (Clause 4"
      },
      "intro": "Complete the Working sheets using the example tabs as a model. Follow the workbook usage rules below."
    },
    {
      "order": 5,
      "id": "isms_role_appointment_register",
      "title": "ISMS role appointment register",
      "contentType": "register_table",
      "required": true,
      "hint": {
        "text": "Example rows demonstrate the expected level of specificity. Replace them with organization-specific records before operational use.",
        "bookReference": "Volume 1, S-00-01-00 Context of the Organization (Clause 4"
      },
      "columns": [
        {
          "name": "Appointment ID",
          "type": "text",
          "required": "yes",
          "description": "Provide explicit evidence that ISMS roles and authorities have been assigned and accepted. Record the appointment id.",
          "example": "IRAR-001"
        },
        {
          "name": "Role",
          "type": "text",
          "required": "yes",
          "description": "Provide explicit evidence that ISMS roles and authorities have been assigned and accepted. Record the role.",
          "example": "Defined and evidenced"
        },
        {
          "name": "Appointee",
          "type": "text",
          "required": "yes",
          "description": "Provide explicit evidence that ISMS roles and authorities have been assigned and accepted. Record the appointee.",
          "example": "Defined and evidenced"
        },
        {
          "name": "Scope",
          "type": "text",
          "required": "yes",
          "description": "Provide explicit evidence that ISMS roles and authorities have been assigned and accepted. Record the scope.",
          "example": "Arcfield SaaS production service"
        },
        {
          "name": "Responsibilities",
          "type": "text",
          "required": "yes",
          "description": "Provide explicit evidence that ISMS roles and authorities have been assigned and accepted. Record the responsibilities.",
          "example": "Defined and evidenced"
        },
        {
          "name": "Authority",
          "type": "text",
          "required": "yes",
          "description": "Provide explicit evidence that ISMS roles and authorities have been assigned and accepted. Record the authority.",
          "example": "Defined and evidenced"
        },
        {
          "name": "Competence requirement",
          "type": "text",
          "required": "yes",
          "description": "Provide explicit evidence that ISMS roles and authorities have been assigned and accepted. Record the competence requirement.",
          "example": "Production access review"
        },
        {
          "name": "Effective date",
          "type": "date",
          "required": "yes",
          "description": "Provide explicit evidence that ISMS roles and authorities have been assigned and accepted. Record the effective date.",
          "example": "2026-08-29"
        },
        {
          "name": "Approver",
          "type": "text",
          "required": "yes",
          "description": "Provide explicit evidence that ISMS roles and authorities have been assigned and accepted. Record the approver.",
          "example": "Top Management"
        },
        {
          "name": "Acceptance evidence",
          "type": "text",
          "required": "yes",
          "description": "Provide explicit evidence that ISMS roles and authorities have been assigned and accepted. Record the acceptance evidence.",
          "example": "JIRA-SEC-2026-014"
        },
        {
          "name": "Review date",
          "type": "date",
          "required": "yes",
          "description": "Provide explicit evidence that ISMS roles and authorities have been assigned and accepted. Record the review date.",
          "example": "2026-08-29"
        },
        {
          "name": "Status",
          "type": "select",
          "required": "yes",
          "description": "Provide explicit evidence that ISMS roles and authorities have been assigned and accepted. Record the status.",
          "example": "Complete",
          "valueSet": "domain.status.generic",
          "options": [
            "Draft",
            "In Progress",
            "Under Review",
            "Approved",
            "Closed",
            "Deferred"
          ],
          "validation": {
            "allowBlank": false,
            "errorTitle": "Invalid value",
            "error": "Select a value from the list."
          }
        }
      ],
      "minimumExampleRows": 5
    },
    {
      "order": 6,
      "id": "external_references",
      "title": "References",
      "contentType": "reference_table",
      "required": true
    }
  ],
  "validationRules": [
    "{'id': 'required-sections-present', 'description': 'All required Contract sections must be present in the Example.'}",
    "{'id': 'example-matches-schema-columns', 'description': 'Example table rows should use the Contract column names for schema-backed sections.'}"
  ],
  "generation": {
    "source": "Contract.json",
    "method": "curated-json",
    "note": "Contract.json and Example.json are SSOT."
  },
  "editorialStandard": {
    "isoAnchors": [
      {
        "label": "ISO/IEC 27001:2022 5.3",
        "href": "https://www.iso.org/standard/82875.html",
        "role": "Normative source this artifact implements or cites."
      },
      {
        "label": "ISO/IEC 27001:2022 7.5",
        "href": "https://www.iso.org/standard/82875.html",
        "role": "Documented information: identify, review and cite this workbook by version."
      }
    ],
    "bookSources": [
      {
        "series": "ISO 27001 for Software Companies",
        "volume": 1,
        "volumeTitle": "Building the ISMS",
        "chapterId": "S-00-01-00",
        "chapterTitle": "Context of the Organization (Clause 4",
        "primary": true,
        "role": "Primary operating chapter for this companion artifact.",
        "href": "https://www.amazon.com/dp/9789908983448"
      },
      {
        "series": "ISO 27001 for Software Companies",
        "volume": 1,
        "volumeTitle": "Building the ISMS",
        "chapterId": "S-00-03-00",
        "chapterTitle": "Planning, Risk & Objectives (Clause 6)",
        "primary": false,
        "role": "Documented information, review and version discipline.",
        "href": "https://www.amazon.com/dp/9789908983448"
      }
    ],
    "acronyms": [
      {
        "abbr": "ISMS",
        "longForm": "Information Security Management System"
      },
      {
        "abbr": "SaaS",
        "longForm": "Software as a Service"
      },
      {
        "abbr": "CIA",
        "longForm": "Confidentiality, Integrity, and Availability"
      },
      {
        "abbr": "CI/CD",
        "longForm": "Continuous Integration / Continuous Delivery"
      },
      {
        "abbr": "CI",
        "longForm": "Continuous Integration"
      },
      {
        "abbr": "CD",
        "longForm": "Continuous Delivery"
      },
      {
        "abbr": "GRC",
        "longForm": "Governance, Risk, and Compliance"
      },
      {
        "abbr": "HR",
        "longForm": "Human Resources"
      }
    ],
    "must": [
      "Keep one live row per record on Working sheets. Do not merge several cases into one row.",
      "Example sheets must contain realistic Arcfield rows for every required sheet. Empty required cells are not an example."
    ],
    "mustNot": [
      "Do not invent live rows in the renderer. Example data lives in the Example JSON.",
      "Do not treat Ex example tabs as working sheets. Do not put live data on system sheets."
    ],
    "softwareCompanyAdaptations": [
      "Use Arcfield as the worked example (cover variant A).",
      "Name SaaS, CI/CD, privileged access or supplier interfaces in example rows where they affect this register."
    ],
    "exampleWorkbook": {
      "workedExampleOrg": "Arcfield",
      "requiredSheets": [
        "isms_role_appointment_register"
      ],
      "minExampleRows": 5,
      "coverFromExample": true
    }
  },
  "editorialContractId": "editorial.xlsx.register.v1",
  "contentContractId": "content.register.items.v1"
}
