{
  "schemaVersion": "artifactExample.v2",
  "artifactId": "ISOCL",
  "title": "ISO 27001:2022 Clauses",
  "definitionRef": {
    "artifactId": "ISOCL",
    "definitionSchemaVersion": "artifactDefinition.v2",
    "definitionId": "ISOCL.artifactDefinition.v2",
    "title": "ISO 27001:2022 Clauses"
  },
  "organization": "Arcfield",
  "sections": [
    {
      "id": "title_page",
      "title": "Title Page",
      "values": {
        "Register Title": "ISO 27001:2022 Clauses",
        "Register ID": "ISOCL-REG-001",
        "Version": "1.1",
        "Status": "Approved",
        "Organization": "Arcfield",
        "Owner": "ISMS Manager",
        "Approver": "Top Management",
        "Classification": "Internal",
        "Effective Date": "2026-09-11",
        "Next Review Date": "2027-09-11"
      },
      "items": [
        "Register Title: ISO 27001:2022 Clauses",
        "Register ID: ISOCL-REG-001",
        "Version: 1.1",
        "Status: Approved",
        "Organization: Arcfield",
        "Owner: ISMS Manager",
        "Approver: Top Management",
        "Classification: Internal",
        "Effective Date: 2026-09-11",
        "Next Review Date: 2027-09-11"
      ],
      "contentType": "metadata"
    },
    {
      "id": "abstract",
      "title": "Abstract",
      "text": "This example provides descriptive reference rows for ISO/IEC 27001:2022 clauses 4.1 through 10.2. It is used as a clause catalogue, not as an implementation tracker: each row explains purpose, typical evidence, responsible role and related implementation artifacts. This coverage view belongs to the certified Arcfield Platform SoA in the surveillance cycle after certificate ARC-ISMS-2025-001.",
      "contentType": "narrative"
    },
    {
      "id": "document_control",
      "title": "Document Control",
      "values": {
        "Document owner": "ISMS Manager",
        "Approved by": "ISMS Manager",
        "Version": "1.1",
        "Status": "Example",
        "Review cadence": "At standard or interpretation change",
        "Last reviewed": "2026-08-29",
        "Next review": "2026-10-31"
      },
      "rows": [
        {
          "Property": "Purpose",
          "Value": "Maintain a complete structured reference register of ISO/IEC 27001:2022 Clauses 4.1-10.2."
        },
        {
          "Property": "Used by",
          "Value": "ISMS Manager, Process Owners, Internal Auditor, External Auditor, Top Management"
        },
        {
          "Property": "Maintained by",
          "Value": "ISMS Manager"
        },
        {
          "Property": "Evidence role",
          "Value": "Supporting tool for implementation, readiness checks and audits"
        },
        {
          "Property": "ISO reference",
          "Value": "ISO/IEC 27001:2022 Clauses 4.1-10.2"
        },
        {
          "Property": "Review cadence",
          "Value": "Quarterly and before internal or certification audits"
        }
      ],
      "contentType": "control_table"
    },
    {
      "id": "instructions",
      "title": "Instructions",
      "items": [
        "Maintain one reference row for every ISO/IEC 27001:2022 management-system clause.",
        "Keep clause summaries concise and implementation-oriented.",
        "Link each clause to typical evidence and implementation registers.",
        "Keep ISOCL synchronized with REQT, the audit programme, management review and evidence log.",
        "Do not delete clause rows.",
        "Use sheets ending in “Ex” as read-only examples. Enter live data only on the matching “Wk” (Working) sheets.",
        "Every operative list is an Excel Table with frozen headers and filters. Add new rows on the next empty worksheet row beneath the table so Excel expands it — do not leave blank rows inside the table.",
        "Where a column offers a dropdown, choose a value from the list (Status, Owner role, Priority, Severity, Likelihood, Impact, Applicability, Evidence Status, Review Result). Do not invent free-text variants.",
        "Enter dates as YYYY-MM-DD. Date columns are validated and formatted accordingly.",
        "Review the Flag columns (Overdue, Review Due, Missing Owner, Missing Evidence). They calculate automatically and highlight gaps for follow-up.",
        "Keep Cover, Legal, Book, Lists and Metadata unchanged. System sheets are protected on purpose."
      ],
      "contentType": "ordered_list"
    },
    {
      "id": "register_schema",
      "title": "Register schema",
      "schemaRef": {
        "definitionId": "ISOCL.artifactDefinition.v2",
        "sectionId": "register_schema"
      },
      "columns": [
        "Clause ID",
        "Clause title",
        "Chapter",
        "Requirement summary",
        "Primary purpose",
        "Typical evidence",
        "Responsible role",
        "Implementation artifact(s)",
        "Review relevance"
      ],
      "contentType": "schema_table"
    },
    {
      "id": "clause_register_entries",
      "title": "Clause register entries",
      "schemaRef": {
        "definitionId": "ISOCL.artifactDefinition.v2",
        "sectionId": "clause_register_entries",
        "columnsRef": "sections.clause_register_entries.columns"
      },
      "rows": [
        {
          "Clause ID": "4.1",
          "Clause title": "Understanding the organization and its context",
          "Chapter": "Context",
          "Requirement summary": "Determine internal and external issues relevant to ISMS purpose and strategic direction.",
          "Primary purpose": "Set context for ISMS scope, risks and opportunities.",
          "Typical evidence": "Context analysis, organization statement, strategic assumptions",
          "Responsible role": "ISMS Manager",
          "Implementation artifact(s)": "OS; GS; ERR",
          "Review relevance": "Reviewed during scope, risk and management review updates."
        },
        {
          "Clause ID": "4.2",
          "Clause title": "Understanding the needs and expectations of interested parties",
          "Chapter": "Context",
          "Requirement summary": "Identify interested parties and requirements relevant to information security.",
          "Primary purpose": "Connect customer, legal, regulatory and supplier expectations to the ISMS.",
          "Typical evidence": "Interested-party list, external requirements register, customer obligations",
          "Responsible role": "Compliance Manager",
          "Implementation artifact(s)": "ERR; SRP; SOC2-SD",
          "Review relevance": "Reviewed after new contracts, legal changes and management review."
        },
        {
          "Clause ID": "4.3",
          "Clause title": "Determining the scope of the ISMS",
          "Chapter": "Context",
          "Requirement summary": "Define ISMS boundaries and applicability considering issues, requirements and interfaces.",
          "Primary purpose": "Create an auditable ISMS boundary.",
          "Typical evidence": "ISMS scope statement, architecture statement, supplier inventory",
          "Responsible role": "ISMS Manager",
          "Implementation artifact(s)": "ISS; SAS; SINV",
          "Review relevance": "Reviewed after service, supplier, architecture or organizational changes."
        },
        {
          "Clause ID": "4.4",
          "Clause title": "Information security management system",
          "Chapter": "Context",
          "Requirement summary": "Establish, implement, maintain and continually improve the ISMS.",
          "Primary purpose": "Operate the management system as an integrated set of processes.",
          "Typical evidence": "ISMS process model, governance records, work instruction records",
          "Responsible role": "ISMS Manager",
          "Implementation artifact(s)": "GS; WIR-S1; IMPL-WB",
          "Review relevance": "Reviewed during management review and improvement planning."
        },
        {
          "Clause ID": "5.1",
          "Clause title": "Leadership and commitment",
          "Chapter": "Leadership",
          "Requirement summary": "Top Management demonstrates leadership and commitment to the ISMS.",
          "Primary purpose": "Ensure ISMS accountability, resources and direction are visible.",
          "Typical evidence": "Management review minutes, policy approval, resource decisions",
          "Responsible role": "Top Management",
          "Implementation artifact(s)": "ISP; MRART; MRMT",
          "Review relevance": "Reviewed during management review and audit interviews."
        },
        {
          "Clause ID": "5.2",
          "Clause title": "Information security policy",
          "Chapter": "Leadership",
          "Requirement summary": "Establish an information security policy that is appropriate, communicated and reviewed.",
          "Primary purpose": "Set the overall information security direction and minimum expectations.",
          "Typical evidence": "Approved ISP, communication and acknowledgement evidence",
          "Responsible role": "ISMS Manager",
          "Implementation artifact(s)": "ISP; TRC",
          "Review relevance": "Reviewed after policy changes and awareness campaigns."
        },
        {
          "Clause ID": "5.3",
          "Clause title": "Organizational roles, responsibilities and authorities",
          "Chapter": "Leadership",
          "Requirement summary": "Assign and communicate ISMS responsibilities and authorities.",
          "Primary purpose": "Make accountability and decision rights clear.",
          "Typical evidence": "RACI, governance structure, organization statement",
          "Responsible role": "ISMS Manager",
          "Implementation artifact(s)": "RACI; GS; OS",
          "Review relevance": "Reviewed after organizational or scope changes."
        },
        {
          "Clause ID": "6.1.1",
          "Clause title": "Actions to address risks and opportunities",
          "Chapter": "Planning",
          "Requirement summary": "Plan actions to address ISMS risks and opportunities.",
          "Primary purpose": "Make planning risk-based and opportunity-aware.",
          "Typical evidence": "Risk register, treatment plan, improvement backlog",
          "Responsible role": "Risk Manager",
          "Implementation artifact(s)": "RR; RTP; CIL",
          "Review relevance": "Reviewed during risk review and management review."
        },
        {
          "Clause ID": "6.1.2",
          "Clause title": "Information security risk assessment",
          "Chapter": "Planning",
          "Requirement summary": "Define and apply risk assessment criteria and process.",
          "Primary purpose": "Ensure risks are identified and assessed consistently.",
          "Typical evidence": "Risk methodology, risk analysis statement, risk register",
          "Responsible role": "Risk Manager",
          "Implementation artifact(s)": "RAM; RAMT; RASM; RR",
          "Review relevance": "Reviewed after incidents, changes and audit findings."
        },
        {
          "Clause ID": "6.1.3",
          "Clause title": "Information security risk treatment",
          "Chapter": "Planning",
          "Requirement summary": "Select risk treatment options, controls and produce a Statement of Applicability.",
          "Primary purpose": "Connect risks, controls, treatment decisions and residual-risk approval.",
          "Typical evidence": "Risk treatment plan, SoA, control implementation evidence",
          "Responsible role": "Risk Manager",
          "Implementation artifact(s)": "RTP; SOA; ISOCTRL",
          "Review relevance": "Reviewed during treatment tracking and management review."
        },
        {
          "Clause ID": "6.2",
          "Clause title": "Information security objectives and planning to achieve them",
          "Chapter": "Planning",
          "Requirement summary": "Set measurable information security objectives and plans.",
          "Primary purpose": "Translate ISMS direction into measurable outcomes.",
          "Typical evidence": "Objectives, metrics, owners, management review decisions",
          "Responsible role": "Top Management",
          "Implementation artifact(s)": "ISP; IMPL-WB; MME",
          "Review relevance": "Reviewed during performance evaluation and management review."
        },
        {
          "Clause ID": "6.3",
          "Clause title": "Planning of changes",
          "Chapter": "Planning",
          "Requirement summary": "Plan ISMS changes in a controlled manner.",
          "Primary purpose": "Prevent unmanaged changes to ISMS scope, process, risk or control operation.",
          "Typical evidence": "Change records, ISMS change log, decision records",
          "Responsible role": "Change Manager",
          "Implementation artifact(s)": "CMP; CR; ISMS-CL",
          "Review relevance": "Reviewed after significant ISMS or operational changes."
        },
        {
          "Clause ID": "7.1",
          "Clause title": "Resources",
          "Chapter": "Support",
          "Requirement summary": "Determine and provide resources needed for the ISMS.",
          "Primary purpose": "Ensure people, tools and budget are adequate for ISMS operation.",
          "Typical evidence": "Resource decisions, management review outputs, action plans",
          "Responsible role": "Top Management",
          "Implementation artifact(s)": "MRART; MRMT; GS",
          "Review relevance": "Reviewed during management review and planning."
        },
        {
          "Clause ID": "7.2",
          "Clause title": "Competence",
          "Chapter": "Support",
          "Requirement summary": "Ensure personnel are competent for work affecting information security performance.",
          "Primary purpose": "Match role risk to skills, training and evidence.",
          "Typical evidence": "Competence matrix, training plan, training records",
          "Responsible role": "HR Manager",
          "Implementation artifact(s)": "CMTP; TR; TRC; HRP",
          "Review relevance": "Reviewed after role changes, incidents and audit findings."
        },
        {
          "Clause ID": "7.3",
          "Clause title": "Awareness",
          "Chapter": "Support",
          "Requirement summary": "Ensure people are aware of policy, contribution and consequences.",
          "Primary purpose": "Make required security behaviors known and evidenced.",
          "Typical evidence": "Awareness records, acknowledgements, campaign metrics",
          "Responsible role": "Security Lead",
          "Implementation artifact(s)": "TRC; HRSP",
          "Review relevance": "Reviewed during training review and incident lessons learned."
        },
        {
          "Clause ID": "7.4",
          "Clause title": "Communication",
          "Chapter": "Support",
          "Requirement summary": "Determine what, when, with whom and how to communicate about the ISMS.",
          "Primary purpose": "Control internal and external ISMS communications.",
          "Typical evidence": "Communication plan, incident communication template, records",
          "Responsible role": "Communications Owner",
          "Implementation artifact(s)": "COMM-P; SICT; IRP",
          "Review relevance": "Reviewed after incidents, customer commitments and management review."
        },
        {
          "Clause ID": "7.5",
          "Clause title": "Documented information",
          "Chapter": "Support",
          "Requirement summary": "Control documented information required by the ISMS and the standard.",
          "Primary purpose": "Ensure documents and records are controlled, available and reliable.",
          "Typical evidence": "Document register, document control procedure, evidence repository",
          "Responsible role": "Document Owner",
          "Implementation artifact(s)": "DCP; DR; WIR-S1",
          "Review relevance": "Reviewed during document control and audit sampling."
        },
        {
          "Clause ID": "8.1",
          "Clause title": "Operational planning and control",
          "Chapter": "Operation",
          "Requirement summary": "Plan, implement and control processes needed to meet ISMS requirements.",
          "Primary purpose": "Operate controls and ISMS processes in a planned way.",
          "Typical evidence": "Operational records, work instructions, change records",
          "Responsible role": "ISMS Manager",
          "Implementation artifact(s)": "WIR-S1; CMP; ISOCTRL",
          "Review relevance": "Reviewed during operational evidence checks."
        },
        {
          "Clause ID": "8.2",
          "Clause title": "Information security risk assessment",
          "Chapter": "Operation",
          "Requirement summary": "Perform risk assessments at planned intervals and when significant changes occur.",
          "Primary purpose": "Keep risk assessment current and responsive to change.",
          "Typical evidence": "Risk review records, updated risk register",
          "Responsible role": "Risk Manager",
          "Implementation artifact(s)": "RR; RAM; ISMS-CL",
          "Review relevance": "Reviewed after changes, incidents and planned cycles."
        },
        {
          "Clause ID": "8.3",
          "Clause title": "Information security risk treatment",
          "Chapter": "Operation",
          "Requirement summary": "Implement the information security risk treatment plan.",
          "Primary purpose": "Turn treatment decisions into implemented controls and residual-risk evidence.",
          "Typical evidence": "Treatment status, implementation evidence, residual-risk decisions",
          "Responsible role": "Risk Manager",
          "Implementation artifact(s)": "RTP; SOA; CAR",
          "Review relevance": "Reviewed until treatment actions are closed and effective."
        },
        {
          "Clause ID": "9.1",
          "Clause title": "Monitoring, measurement, analysis and evaluation",
          "Chapter": "Performance evaluation",
          "Requirement summary": "Evaluate information security performance and ISMS effectiveness.",
          "Primary purpose": "Use metrics and analysis to assess ISMS performance.",
          "Typical evidence": "Metrics, monitoring records, analysis outputs",
          "Responsible role": "Security Lead",
          "Implementation artifact(s)": "MME; IMPL-WB; MRART",
          "Review relevance": "Reviewed during management review and continual improvement."
        },
        {
          "Clause ID": "9.2",
          "Clause title": "Internal audit",
          "Chapter": "Performance evaluation",
          "Requirement summary": "Conduct internal audits at planned intervals.",
          "Primary purpose": "Independently assess conformity and effectiveness.",
          "Typical evidence": "Audit programme, audit plan, sampling records, findings",
          "Responsible role": "Internal Auditor",
          "Implementation artifact(s)": "IAP; CAR; MRMT",
          "Review relevance": "Reviewed during audit follow-up and management review."
        },
        {
          "Clause ID": "9.3",
          "Clause title": "Management review",
          "Chapter": "Performance evaluation",
          "Requirement summary": "Top Management reviews the ISMS for suitability, adequacy and effectiveness.",
          "Primary purpose": "Ensure leadership oversight and decision-grade outputs.",
          "Typical evidence": "Management review agenda, minutes, decisions and actions",
          "Responsible role": "Top Management",
          "Implementation artifact(s)": "MRART; MRMT",
          "Review relevance": "Reviewed at each management review cycle."
        },
        {
          "Clause ID": "10.1",
          "Clause title": "Continual improvement",
          "Chapter": "Improvement",
          "Requirement summary": "Continually improve the suitability, adequacy and effectiveness of the ISMS.",
          "Primary purpose": "Turn learning into prioritized improvement.",
          "Typical evidence": "Improvement log, trend analysis, management decisions",
          "Responsible role": "ISMS Manager",
          "Implementation artifact(s)": "CIL; CAR; WIR-S1",
          "Review relevance": "Reviewed during improvement planning and management review."
        },
        {
          "Clause ID": "10.2",
          "Clause title": "Nonconformity and corrective action",
          "Chapter": "Improvement",
          "Requirement summary": "React to nonconformities, determine causes and implement corrective action.",
          "Primary purpose": "Ensure problems are corrected and recurrence is addressed.",
          "Typical evidence": "Corrective action records, root cause analysis, effectiveness check",
          "Responsible role": "ISMS Manager",
          "Implementation artifact(s)": "CAR; IAP; MRMT",
          "Review relevance": "Reviewed until corrective actions are closed and effective."
        }
      ],
      "contentType": "register_table"
    },
    {
      "id": "register_completeness_decision",
      "title": "Register completeness decision",
      "values": {
        "Completeness result": "Complete",
        "Reviewed by": "ISMS Manager",
        "Clause rows covered": 25,
        "Clauses without summary": 0,
        "Clauses without responsible role": 0,
        "Clauses without implementation artifact": 0,
        "Final status": "Audit-ready",
        "Decision date": "2026-08-29",
        "Evidence reference": "ISOCL-COMPLETE-2026-Q3",
        "Required clause rows": 25,
        "Present unique clause rows": 25,
        "Missing clause IDs": "(none)",
        "Unknown clause IDs": "(none)",
        "Duplicate clause IDs": "(none)",
        "Rejected parent clause IDs": "(none)"
      },
      "contentType": "decision_table"
    },
    {
      "id": "evidence_and_records",
      "title": "Evidence and records",
      "groups": [
        {
          "text": "Related records live in the companion documents named below. This file cites them by their approved version. It does not copy their content. The Owner named on the cover is accountable for those live records."
        },
        {
          "items": [
            "[ISO 27001 Clauses 4–10 Requirements Tracker](REQT_ISO_27001_Clauses_4-10_Requirements_Tracker.xlsx) — Implementation and evidence status per clause.",
            "[Information Security Policy](ISP_Information_Security_Policy.docx) — Leadership and policy freeze."
          ],
          "ordered": true,
          "relationView": "evidence"
        }
      ],
      "contentType": "evidence_table"
    },
    {
      "id": "external_references",
      "title": "References",
      "groups": [
        {
          "text": "Cite these sources from workshops and audits. This list names ISO clauses, book chapters and companion artifacts used by this file."
        },
        {
          "rows": [
            {
              "Kind": "ISO",
              "Reference": "ISO/IEC 27001:2022",
              "How this document uses it": "Normative source this artifact implements or cites.",
              "href": "https://www.iso.org/standard/82875.html"
            },
            {
              "Kind": "Book",
              "Reference": "Building the ISMS, Iso/iec 27002:2022",
              "How this document uses it": "Primary operating chapter for this companion artifact.",
              "href": "https://www.amazon.com/dp/9789908983448"
            },
            {
              "Kind": "Artifact",
              "Reference": "ISO Information Security Objectives (Building the ISMS, Information Security Policies & Risk Management)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/dp/9789908983448"
            },
            {
              "Kind": "Artifact",
              "Reference": "MRMT Management Review Minutes Template (Implementation & Certification, Internal Audit & Management Review)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/s?k=ISO+27001+for+Software+Companies+Implementation+and+Certification"
            },
            {
              "Kind": "Artifact",
              "Reference": "CAR Corrective Actions Register (Building the ISMS, Context of the Organization (Clause 4))",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/dp/9789908983448"
            },
            {
              "Kind": "Artifact",
              "Reference": "GS Gap Statement (Building the ISMS, Context of the Organization (Clause 4))",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/dp/9789908983448"
            }
          ]
        }
      ],
      "contentType": "reference_table"
    }
  ],
  "enrichment": {
    "source": "Example.json",
    "method": "curated-json",
    "note": "Completes Example JSON with renderer-native sections and generalized groups; no mdSource helper fields."
  },
  "snapshotRef": {
    "snapshotId": "arcfield.platform.surv.2026-09-11",
    "schemaVersion": "evidenceSnapshot.v1"
  },
  "scenarioRef": {
    "githubIssue": 64,
    "crId": "CR-TYPE-ARCFIELD-001",
    "family": "Coverage",
    "role": "Control coverage of the certified SoA"
  }
}
