{
  "schemaVersion": "artifactDefinition.v2",
  "definitionId": "ISOCTRL.artifactDefinition.v2",
  "artifactId": "ISOCTRL",
  "title": "ISO 27001:2022 Controls",
  "artifactType": "Coverage",
  "format": "xlsx",
  "productTier": "Premium",
  "definitionRole": "contract",
  "sourceModel": {
    "body": "rendered human-readable register maintained in the Artifact Candidate page",
    "jsonDefinition": "machine-readable complete Annex A control register contract",
    "jsonExample": "curated realistic complete Annex A control register fixture"
  },
  "purpose": "Define the complete ISO/IEC 27001:2022 Annex A control register contract. ISOCTRL must preserve all 93 Annex A controls and provide ownership, applicability, implementation, evidence, review, and SoA linkage fields.",
  "completeCoverage": {
    "coverageType": "ISO/IEC 27001:2022 Annex A",
    "requiredControlCount": 93,
    "requiredControlRanges": [
      "A.5.1-A.5.37",
      "A.6.1-A.6.8",
      "A.7.1-A.7.14",
      "A.8.1-A.8.34"
    ],
    "requiredControlIds": [
      "A.5.1",
      "A.5.2",
      "A.5.3",
      "A.5.4",
      "A.5.5",
      "A.5.6",
      "A.5.7",
      "A.5.8",
      "A.5.9",
      "A.5.10",
      "A.5.11",
      "A.5.12",
      "A.5.13",
      "A.5.14",
      "A.5.15",
      "A.5.16",
      "A.5.17",
      "A.5.18",
      "A.5.19",
      "A.5.20",
      "A.5.21",
      "A.5.22",
      "A.5.23",
      "A.5.24",
      "A.5.25",
      "A.5.26",
      "A.5.27",
      "A.5.28",
      "A.5.29",
      "A.5.30",
      "A.5.31",
      "A.5.32",
      "A.5.33",
      "A.5.34",
      "A.5.35",
      "A.5.36",
      "A.5.37",
      "A.6.1",
      "A.6.2",
      "A.6.3",
      "A.6.4",
      "A.6.5",
      "A.6.6",
      "A.6.7",
      "A.6.8",
      "A.7.1",
      "A.7.2",
      "A.7.3",
      "A.7.4",
      "A.7.5",
      "A.7.6",
      "A.7.7",
      "A.7.8",
      "A.7.9",
      "A.7.10",
      "A.7.11",
      "A.7.12",
      "A.7.13",
      "A.7.14",
      "A.8.1",
      "A.8.2",
      "A.8.3",
      "A.8.4",
      "A.8.5",
      "A.8.6",
      "A.8.7",
      "A.8.8",
      "A.8.9",
      "A.8.10",
      "A.8.11",
      "A.8.12",
      "A.8.13",
      "A.8.14",
      "A.8.15",
      "A.8.16",
      "A.8.17",
      "A.8.18",
      "A.8.19",
      "A.8.20",
      "A.8.21",
      "A.8.22",
      "A.8.23",
      "A.8.24",
      "A.8.25",
      "A.8.26",
      "A.8.27",
      "A.8.28",
      "A.8.29",
      "A.8.30",
      "A.8.31",
      "A.8.32",
      "A.8.33",
      "A.8.34"
    ],
    "rule": "The JSON Example and generated workbook must contain one row for every required control ID."
  },
  "controlledValues": {
    "theme": [
      "Organizational",
      "People",
      "Physical",
      "Technological"
    ],
    "applicability": [
      "Applicable",
      "Not applicable"
    ],
    "implementationStatus": [
      "Not started",
      "Planned",
      "In progress",
      "Implemented",
      "Not applicable"
    ],
    "evidenceStatus": [
      "Complete",
      "Partial",
      "Missing",
      "Not applicable"
    ],
    "operatingEffectiveness": [
      "Not assessed",
      "Ineffective",
      "Partially effective",
      "Effective"
    ],
    "reviewResult": [
      "Confirmed",
      "Updated",
      "Gap identified",
      "Retired",
      "Exception approved"
    ]
  },
  "hintPolicy": {
    "storage": "Each content section stores its hint in this JSON Definition.",
    "visualization": "Generated outputs render each hint as a visually highlighted callout after the section content.",
    "minimumRule": "Every content section except formal title/document-control sections should have one context-specific hint.",
    "format": {
      "requiredParts": [
        "short practical explanation",
        "detailed book reference"
      ]
    }
  },
  "sections": [
    {
      "order": 1,
      "id": "title_page",
      "title": "Title Page",
      "contentType": "metadata",
      "required": true,
      "hint": null
    },
    {
      "order": 2,
      "id": "abstract",
      "title": "Abstract",
      "contentType": "narrative",
      "required": true,
      "hint": {
        "text": "ISOCTRL must contain every Annex A control. The SoA may justify applicability, but ISOCTRL preserves the full control catalogue and operational status.",
        "bookReference": "Volume 1, S-00-08-00 Annex A Controls"
      }
    },
    {
      "order": 3,
      "id": "document_control",
      "title": "Document Control",
      "contentType": "control_table",
      "required": true,
      "hint": null
    },
    {
      "order": 4,
      "id": "instructions",
      "title": "Instructions",
      "contentType": "ordered_list",
      "required": true,
      "hint": {
        "text": "Do not delete non-applicable controls. Preserve every Annex A row and record applicability, owner, status, evidence, and review context.",
        "bookReference": "Volume 1, S-00-08-00 Annex A Controls"
      },
      "intro": "Complete the Working sheets using the example tabs as a model. Follow the workbook usage rules below."
    },
    {
      "order": 5,
      "id": "control_register_schema",
      "title": "Control register schema",
      "contentType": "schema_table",
      "required": true,
      "requiredColumns": [
        "Control ID",
        "Control name",
        "Theme",
        "Applicability",
        "Applicability justification",
        "Control owner",
        "Implementation status",
        "Evidence status",
        "Operating effectiveness",
        "Evidence reference",
        "SoA linkage",
        "Risk linkage",
        "Open actions",
        "Last review date",
        "Next review date",
        "Notes"
      ],
      "hint": {
        "text": "The schema must be strong enough to support SoA linkage, implementation tracking, operating-effectiveness review, and audit sampling.",
        "bookReference": "Volume 1, S-00-08-00 Annex A Controls"
      }
    },
    {
      "order": 6,
      "id": "control_register_entries",
      "title": "Control register entries",
      "contentType": "register_table",
      "required": true,
      "minimumExampleRows": 93,
      "columns": [
        {
          "name": "Control ID",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Control name",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Theme",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Applicability",
          "type": "select",
          "required": "yes",
          "valueSet": "domain.applicability",
          "options": [
            "Applicable",
            "Not Applicable",
            "Partially Applicable"
          ],
          "validation": {
            "allowBlank": false,
            "errorTitle": "Invalid value",
            "error": "Select a value from the list."
          }
        },
        {
          "name": "Applicability justification",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Control owner",
          "type": "select",
          "required": "yes",
          "valueSet": "domain.owner",
          "options": [
            "ISMS Manager",
            "Control Owner",
            "Risk Owner",
            "Process Owner",
            "Asset Owner",
            "IT Security",
            "HR",
            "Legal",
            "Executive Management",
            "Internal Audit"
          ],
          "validation": {
            "allowBlank": false,
            "errorTitle": "Invalid value",
            "error": "Select a value from the list."
          }
        },
        {
          "name": "Implementation status",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Evidence status",
          "type": "select",
          "required": "yes",
          "valueSet": "domain.evidenceStatus",
          "options": [
            "Missing",
            "Requested",
            "Received",
            "Verified",
            "Rejected"
          ],
          "validation": {
            "allowBlank": false,
            "errorTitle": "Invalid value",
            "error": "Select a value from the list."
          }
        },
        {
          "name": "Operating effectiveness",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Evidence reference",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "SoA linkage",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Risk linkage",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Open actions",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Last review date",
          "type": "date",
          "required": "yes"
        },
        {
          "name": "Next review date",
          "type": "date",
          "required": "yes"
        },
        {
          "name": "Notes",
          "type": "text",
          "required": "yes"
        }
      ],
      "hint": {
        "text": "The visible body may show representative rows, but the JSON Example and XLSX output must contain all 93 Annex A controls.",
        "bookReference": "Volume 1, S-00-08-00 Annex A Controls"
      }
    },
    {
      "order": 7,
      "id": "coverage_decision",
      "title": "Coverage decision",
      "contentType": "decision_table",
      "required": true,
      "fields": [
        {
          "name": "Annex A coverage",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Required controls",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Current controls",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Missing controls",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Reviewed by",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Decision date",
          "type": "date",
          "required": "yes"
        },
        {
          "name": "Evidence reference",
          "type": "text",
          "required": "yes"
        }
      ],
      "hint": {
        "text": "The coverage decision confirms that no Annex A control is missing from the control register.",
        "bookReference": "Volume 1, S-00-08-00 Annex A Controls"
      }
    },
    {
      "order": 8,
      "id": "control_register",
      "title": "Control register",
      "contentType": "section",
      "required": true,
      "hint": {
        "text": "Recovered during enrichment."
      }
    },
    {
      "order": 9,
      "id": "external_references",
      "title": "References",
      "contentType": "reference_table",
      "required": true
    }
  ],
  "validationRules": [
    "JSON Example must contain definitionRef pointing to ISOCTRL.artifactDefinition.v2.",
    "JSON Example register sections must contain schemaRef pointing to the matching definition section.",
    "Control register entries must contain exactly 93 rows.",
    "Every control ID listed in completeCoverage.requiredControlIds must be present exactly once.",
    "Every row must include theme, applicability, control owner, implementation status, evidence status, SoA linkage, and review date fields.",
    "No standalone Book reference section and no generic Sample placeholders are allowed."
  ],
  "instructionsForGenerator": [
    "Generate the Artifact Body after JSON Definition and JSON Example are complete.",
    "Render representative rows in Body if needed for readability, but preserve all 93 rows in the XLSX output.",
    "Render hints after section content as callouts with plain labels."
  ],
  "enrichment": {
    "source": "Contract.json",
    "method": "curated-json",
    "note": "Completes Contract JSON from MD-only schema/sections, removes duplicate alias sections, and normalizes string columns into structured column objects."
  },
  "editorialStandard": {
    "isoAnchors": [
      {
        "label": "ISO/IEC 27001:2022",
        "href": "https://www.iso.org/standard/82875.html",
        "role": "Normative source this artifact implements or cites."
      },
      {
        "label": "ISO/IEC 27001:2022 8.1",
        "href": "https://www.iso.org/standard/82875.html",
        "role": "Operational planning and control this register evidences."
      },
      {
        "label": "ISO/IEC 27001:2022 7.5",
        "href": "https://www.iso.org/standard/82875.html",
        "role": "Documented information: identify, review and cite this workbook by version."
      }
    ],
    "bookSources": [
      {
        "series": "ISO 27001 for Software Companies",
        "volume": 1,
        "volumeTitle": "Building the ISMS",
        "chapterId": "S-00-08-00",
        "chapterTitle": "Annex A Controls",
        "primary": true,
        "role": "Primary operating chapter for this companion artifact.",
        "href": "https://www.amazon.com/dp/9789908983448"
      },
      {
        "series": "ISO 27001 for Software Companies",
        "volume": 1,
        "volumeTitle": "Building the ISMS",
        "chapterId": "S-00-03-00",
        "chapterTitle": "Planning, Risk & Objectives (Clause 6)",
        "primary": false,
        "role": "Documented information, review and version discipline.",
        "href": "https://www.amazon.com/dp/9789908983448"
      }
    ],
    "acronyms": [
      {
        "abbr": "ISMS",
        "longForm": "Information Security Management System"
      },
      {
        "abbr": "SaaS",
        "longForm": "Software as a Service"
      },
      {
        "abbr": "CIA",
        "longForm": "Confidentiality, Integrity, and Availability"
      },
      {
        "abbr": "CI/CD",
        "longForm": "Continuous Integration / Continuous Delivery"
      },
      {
        "abbr": "CI",
        "longForm": "Continuous Integration"
      },
      {
        "abbr": "CD",
        "longForm": "Continuous Delivery"
      },
      {
        "abbr": "AI",
        "longForm": "Artificial Intelligence"
      },
      {
        "abbr": "BCP",
        "longForm": "Business Continuity Plan"
      },
      {
        "abbr": "CRM",
        "longForm": "Customer Relationship Management"
      },
      {
        "abbr": "CSS",
        "longForm": "Cascading Style Sheets"
      },
      {
        "abbr": "DAST",
        "longForm": "Dynamic Application Security Testing"
      },
      {
        "abbr": "DLP",
        "longForm": "Data Loss Prevention"
      },
      {
        "abbr": "DPA",
        "longForm": "Data Processing Agreement"
      },
      {
        "abbr": "DR",
        "longForm": "Disaster Recovery"
      },
      {
        "abbr": "DRP",
        "longForm": "Disaster Recovery Plan"
      },
      {
        "abbr": "EDR",
        "longForm": "Endpoint Detection and Response"
      },
      {
        "abbr": "GDPR",
        "longForm": "General Data Protection Regulation"
      },
      {
        "abbr": "HR",
        "longForm": "Human Resources"
      },
      {
        "abbr": "IAM",
        "longForm": "Identity and Access Management"
      },
      {
        "abbr": "ICT",
        "longForm": "Information and Communications Technology"
      },
      {
        "abbr": "IR",
        "longForm": "Incident Response"
      },
      {
        "abbr": "IRP",
        "longForm": "Incident Response Plan"
      },
      {
        "abbr": "ISP",
        "longForm": "Information Security Policy"
      },
      {
        "abbr": "JSON",
        "longForm": "JavaScript Object Notation"
      },
      {
        "abbr": "MDM",
        "longForm": "Mobile Device Management"
      },
      {
        "abbr": "MFA",
        "longForm": "Multi-Factor Authentication"
      },
      {
        "abbr": "NDA",
        "longForm": "Non-Disclosure Agreement"
      },
      {
        "abbr": "PII",
        "longForm": "Personally Identifiable Information"
      },
      {
        "abbr": "RACI",
        "longForm": "Responsible, Accountable, Consulted, and Informed"
      },
      {
        "abbr": "RR",
        "longForm": "Risk Register"
      },
      {
        "abbr": "RTP",
        "longForm": "Risk Treatment Plan"
      },
      {
        "abbr": "SAST",
        "longForm": "Static Application Security Testing"
      },
      {
        "abbr": "SDLC",
        "longForm": "Software Development Life Cycle"
      },
      {
        "abbr": "SLA",
        "longForm": "Service Level Agreement"
      },
      {
        "abbr": "SoA",
        "longForm": "Statement of Applicability"
      }
    ],
    "must": [
      "Keep one live row per record on Working sheets. Do not merge several cases into one row.",
      "Example sheets must contain realistic Arcfield rows for every required sheet. Empty required cells are not an example."
    ],
    "mustNot": [
      "Do not invent live rows in the renderer. Example data lives in the Example JSON.",
      "Do not treat Ex example tabs as working sheets. Do not put live data on system sheets."
    ],
    "softwareCompanyAdaptations": [
      "Use Arcfield as the worked example (cover variant A).",
      "Name SaaS, CI/CD, privileged access or supplier interfaces in example rows where they affect this register."
    ],
    "exampleWorkbook": {
      "workedExampleOrg": "Arcfield",
      "requiredSheets": [
        "control_register_schema",
        "control_register_entries",
        "coverage_decision",
        "control_register"
      ],
      "minExampleRows": 93,
      "coverFromExample": true
    }
  },
  "editorialContractId": "editorial.xlsx.register.v1",
  "contentContractId": "content.register.coverage.v1"
}
