{
  "schemaVersion": "artifactExample.v2",
  "artifactId": "ISOCTRL",
  "title": "ISO 27001:2022 Controls",
  "definitionRef": {
    "artifactId": "ISOCTRL",
    "definitionSchemaVersion": "artifactDefinition.v2",
    "definitionId": "ISOCTRL.artifactDefinition.v2",
    "title": "ISO 27001:2022 Controls"
  },
  "organization": "Arcfield",
  "examplePurpose": "Complete curated Annex A control register fixture with all 93 ISO/IEC 27001:2022 controls.",
  "coverage": {
    "coverageType": "ISO/IEC 27001:2022 Annex A",
    "requiredControlCount": 93,
    "currentControlCount": 93,
    "coverageStatus": "Complete"
  },
  "sections": [
    {
      "id": "title_page",
      "title": "Title Page",
      "values": {
        "Register Title": "ISO 27001:2022 Controls",
        "Register ID": "ISOCTRL-REG-001",
        "Version": "1.1",
        "Status": "Approved",
        "Organization": "Arcfield",
        "Owner": "ISMS Manager",
        "Approver": "Top Management",
        "Classification": "Internal",
        "Effective Date": "2026-09-11",
        "Next Review Date": "2027-09-11"
      },
      "items": [
        "Register Title: ISO 27001:2022 Controls",
        "Register ID: ISOCTRL-REG-001",
        "Version: 1.1",
        "Status: Approved",
        "Organization: Arcfield",
        "Owner: ISMS Manager",
        "Approver: Top Management",
        "Classification: Internal",
        "Effective Date: 2026-09-11",
        "Next Review Date: 2027-09-11"
      ],
      "contentType": "metadata"
    },
    {
      "id": "abstract",
      "title": "Abstract",
      "text": "This example is the complete Arcfield Annex A control register fixture. It preserves all 93 ISO/IEC 27001:2022 Annex A controls and records applicability, ownership, implementation, evidence, operating effectiveness, SoA linkage, risk linkage and review dates. This coverage view belongs to the certified Arcfield Platform SoA in the surveillance cycle after certificate ARC-ISMS-2025-001.",
      "contentType": "narrative"
    },
    {
      "id": "document_control",
      "title": "Document Control",
      "rows": [
        {
          "Property": "Purpose",
          "Value": "Maintain a complete structured register of all ISO/IEC 27001:2022 Annex A controls."
        },
        {
          "Property": "Used by",
          "Value": "ISMS Manager, Control Owners, Internal Auditor, External Auditor, Top Management"
        },
        {
          "Property": "Maintained by",
          "Value": "ISMS Manager"
        },
        {
          "Property": "Evidence role",
          "Value": "Supporting tool for SoA, control implementation, review and audit evidence"
        },
        {
          "Property": "ISO reference",
          "Value": "ISO/IEC 27001:2022 Annex A controls A.5.1-A.8.34"
        },
        {
          "Property": "Review cadence",
          "Value": "Quarterly and before internal or certification audits"
        }
      ],
      "contentType": "control_table"
    },
    {
      "id": "instructions",
      "title": "Instructions",
      "items": [
        "Maintain one row for every Annex A control from A.5.1 through A.8.34.",
        "Do not remove non-applicable controls; keep the catalogue complete and record applicability decisions in the SoA.",
        "Keep control owners role-based and aligned with the SoA.",
        "Link implementation evidence, review results, gaps and corrective actions.",
        "Validate completeness before generating SoA or audit packs.",
        "Use sheets ending in “Ex” as read-only examples. Enter live data only on the matching “Wk” (Working) sheets.",
        "Every operative list is an Excel Table with frozen headers and filters. Add new rows on the next empty worksheet row beneath the table so Excel expands it — do not leave blank rows inside the table.",
        "Where a column offers a dropdown, choose a value from the list (Status, Owner role, Priority, Severity, Likelihood, Impact, Applicability, Evidence Status, Review Result). Do not invent free-text variants.",
        "Enter dates as YYYY-MM-DD. Date columns are validated and formatted accordingly.",
        "Review the Flag columns (Overdue, Review Due, Missing Owner, Missing Evidence). They calculate automatically and highlight gaps for follow-up.",
        "Keep Cover, Legal, Book, Lists and Metadata unchanged. System sheets are protected on purpose."
      ],
      "contentType": "ordered_list"
    },
    {
      "id": "control_register_schema",
      "title": "Control register schema",
      "schemaRef": {
        "definitionId": "ISOCTRL.artifactDefinition.v2",
        "sectionId": "control_register_schema",
        "requiredColumnsRef": "sections.control_register_schema.requiredColumns"
      },
      "rows": [
        {
          "Column": "Control ID",
          "Type": "text",
          "Required": "yes",
          "Description": "ISO/IEC 27001:2022 Annex A control identifier.",
          "Example": "A.5.9"
        },
        {
          "Column": "Control name",
          "Type": "text",
          "Required": "yes",
          "Description": "Control name.",
          "Example": "Inventory of information and other associated assets"
        },
        {
          "Column": "Theme",
          "Type": "select",
          "Required": "yes",
          "Description": "Organizational, People, Physical or Technological.",
          "Example": "Organizational"
        },
        {
          "Column": "Control owner",
          "Type": "text",
          "Required": "yes",
          "Description": "Role accountable for control implementation and evidence.",
          "Example": "Asset Manager"
        },
        {
          "Column": "Implementation status",
          "Type": "select",
          "Required": "yes",
          "Description": "Not started, Planned, In progress, Implemented or Not applicable.",
          "Example": "Implemented"
        },
        {
          "Column": "Evidence status",
          "Type": "select",
          "Required": "yes",
          "Description": "Complete, Partial, Missing or Not applicable.",
          "Example": "Complete"
        },
        {
          "Column": "Evidence reference",
          "Type": "text",
          "Required": "conditional",
          "Description": "Linked evidence record, document or register.",
          "Example": "AI-REG-001"
        },
        {
          "Column": "SoA linkage",
          "Type": "text",
          "Required": "yes",
          "Description": "SoA row reference for applicability decision.",
          "Example": "SOA-A.5.9"
        },
        {
          "Column": "Next review",
          "Type": "date",
          "Required": "yes",
          "Description": "Planned next review date.",
          "Example": "2026-11-29"
        }
      ],
      "contentType": "schema_table"
    },
    {
      "id": "control_register_entries",
      "title": "Control register entries",
      "schemaRef": {
        "definitionId": "ISOCTRL.artifactDefinition.v2",
        "sectionId": "control_register_entries",
        "columnsRef": "sections.control_register_entries.columns"
      },
      "rows": [
        {
          "Control ID": "A.5.1",
          "Control name": "Policies for information security",
          "Theme": "Organizational",
          "Applicability": "Applicable",
          "Applicability justification": "Required for ISMS governance and policy direction.",
          "Control owner": "ISMS Manager",
          "Implementation status": "Implemented",
          "Evidence status": "Complete",
          "Operating effectiveness": "Effective",
          "Evidence reference": "ISP-001",
          "SoA linkage": "SOA-A.5.1",
          "Risk linkage": "REQT-5.2",
          "Open actions": "None",
          "Last review date": "2026-08-29",
          "Next review date": "2026-11-29",
          "Notes": "Policy approved and communicated."
        },
        {
          "Control ID": "A.5.2",
          "Control name": "Information security roles and responsibilities",
          "Theme": "Organizational",
          "Applicability": "Applicable",
          "Applicability justification": "Required to assign ISMS accountability.",
          "Control owner": "ISMS Manager",
          "Implementation status": "Implemented",
          "Evidence status": "Complete",
          "Operating effectiveness": "Effective",
          "Evidence reference": "RACI-2026-Q3",
          "SoA linkage": "SOA-A.5.2",
          "Risk linkage": "REQT-5.3",
          "Open actions": "None",
          "Last review date": "2026-08-29",
          "Next review date": "2026-11-29",
          "Notes": "Role model aligned with RACI."
        },
        {
          "Control ID": "A.5.3",
          "Control name": "Segregation of duties",
          "Theme": "Organizational",
          "Applicability": "Applicable",
          "Applicability justification": "Required for privileged and financial-impacting activities.",
          "Control owner": "IT Operations",
          "Implementation status": "In progress",
          "Evidence status": "Partial",
          "Operating effectiveness": "Partially effective",
          "Evidence reference": "SOD-CHK-2026-Q3",
          "SoA linkage": "SOA-A.5.3",
          "Risk linkage": "RISK-2026-014",
          "Open actions": "Complete Q3 privileged role conflict review",
          "Last review date": "2026-08-29",
          "Next review date": "2026-10-29",
          "Notes": "Linked to access review."
        },
        {
          "Control ID": "A.5.4",
          "Control name": "Management responsibilities",
          "Theme": "Organizational",
          "Applicability": "Applicable",
          "Applicability justification": "Required for management oversight of security responsibilities.",
          "Control owner": "Top Management",
          "Implementation status": "Implemented",
          "Evidence status": "Complete",
          "Operating effectiveness": "Effective",
          "Evidence reference": "MR-2026-Q3",
          "SoA linkage": "SOA-A.5.4",
          "Risk linkage": "REQT-5.1",
          "Open actions": "None",
          "Last review date": "2026-08-29",
          "Next review date": "2026-11-29",
          "Notes": "Reviewed in management review."
        },
        {
          "Control ID": "A.5.5",
          "Control name": "Contact with authorities",
          "Theme": "Organizational",
          "Applicability": "Applicable",
          "Applicability justification": "Required for incident and regulatory communication.",
          "Control owner": "Compliance Manager",
          "Implementation status": "Implemented",
          "Evidence status": "Partial",
          "Operating effectiveness": "Not assessed",
          "Evidence reference": "COMM-P-2026",
          "SoA linkage": "SOA-A.5.5",
          "Risk linkage": "IRP-2026",
          "Open actions": "Validate authority contact list",
          "Last review date": "2026-08-20",
          "Next review date": "2026-11-20",
          "Notes": "Part of communication plan."
        },
        {
          "Control ID": "A.5.6",
          "Control name": "Contact with special interest groups",
          "Theme": "Organizational",
          "Applicability": "Applicable",
          "Applicability justification": "Relevant for threat intelligence and professional security updates.",
          "Control owner": "Security Lead",
          "Implementation status": "Implemented",
          "Evidence status": "Partial",
          "Operating effectiveness": "Not assessed",
          "Evidence reference": "TI-SUB-2026",
          "SoA linkage": "SOA-A.5.6",
          "Risk linkage": "RISK-2026-027",
          "Open actions": "Document participation evidence",
          "Last review date": "2026-08-20",
          "Next review date": "2026-11-20",
          "Notes": "Security mailing lists and vendor advisories."
        },
        {
          "Control ID": "A.5.7",
          "Control name": "Threat intelligence",
          "Theme": "Organizational",
          "Applicability": "Applicable",
          "Applicability justification": "Required to identify relevant threats to software and cloud services.",
          "Control owner": "Security Lead",
          "Implementation status": "In progress",
          "Evidence status": "Partial",
          "Operating effectiveness": "Partially effective",
          "Evidence reference": "TI-LOG-2026-Q3",
          "SoA linkage": "SOA-A.5.7",
          "Risk linkage": "RISK-2026-027",
          "Open actions": "Link advisories to vulnerability management evidence",
          "Last review date": "2026-08-27",
          "Next review date": "2026-10-31",
          "Notes": "Feeds used for vulnerability triage."
        },
        {
          "Control ID": "A.5.8",
          "Control name": "Information security in project management",
          "Theme": "Organizational",
          "Applicability": "Applicable",
          "Applicability justification": "Required for product and ISMS implementation projects.",
          "Control owner": "Project Manager",
          "Implementation status": "Implemented",
          "Evidence status": "Partial",
          "Operating effectiveness": "Partially effective",
          "Evidence reference": "SSDLC-REL-2026-014",
          "SoA linkage": "SOA-A.5.8",
          "Risk linkage": "RISK-2026-027",
          "Open actions": "Add security gate evidence to all releases",
          "Last review date": "2026-08-27",
          "Next review date": "2026-11-27",
          "Notes": "Linked to S-SDLC."
        },
        {
          "Control ID": "A.5.9",
          "Control name": "Inventory of information and other associated assets",
          "Theme": "Organizational",
          "Applicability": "Applicable",
          "Applicability justification": "Required because in-scope assets support customer, HR, code, identity, and evidence processes.",
          "Control owner": "Asset Manager",
          "Implementation status": "Implemented",
          "Evidence status": "Complete",
          "Operating effectiveness": "Effective",
          "Evidence reference": "AI-REG-001",
          "SoA linkage": "SOA-A.5.9",
          "Risk linkage": "RISK-2026-014",
          "Open actions": "Supplier contact update pending for AST-001",
          "Last review date": "2026-08-29",
          "Next review date": "2026-11-29",
          "Notes": "AI is reference register."
        },
        {
          "Control ID": "A.5.10",
          "Control name": "Acceptable use of information and other associated assets",
          "Theme": "Organizational",
          "Applicability": "Applicable",
          "Applicability justification": "Required for user obligations on company assets and services.",
          "Control owner": "HR Manager",
          "Implementation status": "Implemented",
          "Evidence status": "Complete",
          "Operating effectiveness": "Effective",
          "Evidence reference": "AUP-ACK-2026-Q3",
          "SoA linkage": "SOA-A.5.10",
          "Risk linkage": "HR-ONB-2026-023",
          "Open actions": "None",
          "Last review date": "2026-08-20",
          "Next review date": "2026-11-20",
          "Notes": "Acknowledgement collected during onboarding."
        },
        {
          "Control ID": "A.5.11",
          "Control name": "Return of assets",
          "Theme": "Organizational",
          "Applicability": "Applicable",
          "Applicability justification": "Required during offboarding and role changes.",
          "Control owner": "HR Manager",
          "Implementation status": "Implemented",
          "Evidence status": "Complete",
          "Operating effectiveness": "Effective",
          "Evidence reference": "OFC-2026-018",
          "SoA linkage": "SOA-A.5.11",
          "Risk linkage": "RISK-2026-033",
          "Open actions": "None",
          "Last review date": "2026-08-20",
          "Next review date": "2026-11-20",
          "Notes": "Linked to offboarding checklist."
        },
        {
          "Control ID": "A.5.12",
          "Control name": "Classification of information",
          "Theme": "Organizational",
          "Applicability": "Applicable",
          "Applicability justification": "Required for confidentiality and handling decisions.",
          "Control owner": "ISMS Manager",
          "Implementation status": "Implemented",
          "Evidence status": "Complete",
          "Operating effectiveness": "Effective",
          "Evidence reference": "CLASS-STD-2026",
          "SoA linkage": "SOA-A.5.12",
          "Risk linkage": "AI-REG-001",
          "Open actions": "None",
          "Last review date": "2026-08-29",
          "Next review date": "2026-11-29",
          "Notes": "Classification values used in AI."
        },
        {
          "Control ID": "A.5.13",
          "Control name": "Labelling of information",
          "Theme": "Organizational",
          "Applicability": "Applicable",
          "Applicability justification": "Required to communicate classification handling.",
          "Control owner": "Document Owner",
          "Implementation status": "Implemented",
          "Evidence status": "Partial",
          "Operating effectiveness": "Partially effective",
          "Evidence reference": "DR-2026-Q3",
          "SoA linkage": "SOA-A.5.13",
          "Risk linkage": "RISK-2026-021",
          "Open actions": "Confirm labels on exported templates",
          "Last review date": "2026-08-28",
          "Next review date": "2026-11-28",
          "Notes": "Applies to documents and repositories."
        },
        {
          "Control ID": "A.5.14",
          "Control name": "Information transfer",
          "Theme": "Organizational",
          "Applicability": "Applicable",
          "Applicability justification": "Required for customer, supplier, and audit information transfer.",
          "Control owner": "IT Operations",
          "Implementation status": "Implemented",
          "Evidence status": "Partial",
          "Operating effectiveness": "Partially effective",
          "Evidence reference": "ITR-2026-Q3",
          "SoA linkage": "SOA-A.5.14",
          "Risk linkage": "RISK-2026-018",
          "Open actions": "Update supplier transfer procedure evidence",
          "Last review date": "2026-08-29",
          "Next review date": "2026-11-29",
          "Notes": "Relevant to supplier portals."
        },
        {
          "Control ID": "A.5.15",
          "Control name": "Access control",
          "Theme": "Organizational",
          "Applicability": "Applicable",
          "Applicability justification": "Required to protect production, identity, HR, and evidence systems.",
          "Control owner": "IT Operations",
          "Implementation status": "Implemented",
          "Evidence status": "Partial",
          "Operating effectiveness": "Partially effective",
          "Evidence reference": "ACM-APP-CRM-001",
          "SoA linkage": "SOA-A.5.15",
          "Risk linkage": "RISK-2026-014",
          "Open actions": "Q3 privileged-access evidence pack in progress",
          "Last review date": "2026-08-29",
          "Next review date": "2026-10-29",
          "Notes": "Linked to ARR and UAI. Re-sampled after IL-005; less robust than the Stage 2 sample; evidence Partial."
        },
        {
          "Control ID": "A.5.16",
          "Control name": "Identity management",
          "Theme": "Organizational",
          "Applicability": "Applicable",
          "Applicability justification": "Required for lifecycle management of identities.",
          "Control owner": "IT Operations",
          "Implementation status": "Implemented",
          "Evidence status": "Partial",
          "Operating effectiveness": "Partially effective",
          "Evidence reference": "IAM-CTRL-2026-Q3",
          "SoA linkage": "SOA-A.5.16",
          "Risk linkage": "RISK-2026-014",
          "Open actions": "Complete joiner-mover-leaver sample",
          "Last review date": "2026-08-29",
          "Next review date": "2026-10-29",
          "Notes": "Identity provider tenant is AST-005."
        },
        {
          "Control ID": "A.5.17",
          "Control name": "Authentication information",
          "Theme": "Organizational",
          "Applicability": "Applicable",
          "Applicability justification": "Required for authentication secrets and recovery.",
          "Control owner": "IT Operations",
          "Implementation status": "Implemented",
          "Evidence status": "Partial",
          "Operating effectiveness": "Partially effective",
          "Evidence reference": "IAM-CTRL-2026-Q3",
          "SoA linkage": "SOA-A.5.17",
          "Risk linkage": "RISK-2026-031",
          "Open actions": "Document break-glass credential review",
          "Last review date": "2026-08-29",
          "Next review date": "2026-09-30",
          "Notes": "Monthly review required."
        },
        {
          "Control ID": "A.5.18",
          "Control name": "Access rights",
          "Theme": "Organizational",
          "Applicability": "Applicable",
          "Applicability justification": "Required to manage and review assigned rights.",
          "Control owner": "IT Operations",
          "Implementation status": "Implemented",
          "Evidence status": "Partial",
          "Operating effectiveness": "Partially effective",
          "Evidence reference": "ARR-2026-Q3",
          "SoA linkage": "SOA-A.5.18",
          "Risk linkage": "RISK-2026-014",
          "Open actions": "Complete privileged sample review",
          "Last review date": "2026-08-29",
          "Next review date": "2026-10-29",
          "Notes": "Linked to access matrix."
        },
        {
          "Control ID": "A.5.19",
          "Control name": "Information security in supplier relationships",
          "Theme": "Organizational",
          "Applicability": "Applicable",
          "Applicability justification": "Required for cloud and SaaS suppliers.",
          "Control owner": "Supplier Manager",
          "Implementation status": "In progress",
          "Evidence status": "Partial",
          "Operating effectiveness": "Partially effective",
          "Evidence reference": "SINV-CLOUDHOST-2026-Q3",
          "SoA linkage": "SOA-A.5.19",
          "Risk linkage": "RISK-2026-018",
          "Open actions": "Supplier contact update pending",
          "Last review date": "2026-08-29",
          "Next review date": "2026-10-15",
          "Notes": "CloudHost EU dependency."
        },
        {
          "Control ID": "A.5.20",
          "Control name": "Addressing information security within supplier agreements",
          "Theme": "Organizational",
          "Applicability": "Applicable",
          "Applicability justification": "Required for supplier contract security terms.",
          "Control owner": "Supplier Manager",
          "Implementation status": "In progress",
          "Evidence status": "Partial",
          "Operating effectiveness": "Not assessed",
          "Evidence reference": "CSS-2026-001",
          "SoA linkage": "SOA-A.5.20",
          "Risk linkage": "RISK-2026-018",
          "Open actions": "Confirm exit support clause",
          "Last review date": "2026-08-29",
          "Next review date": "2026-10-15",
          "Notes": "Linked to treatment RTP-2026-018."
        },
        {
          "Control ID": "A.5.21",
          "Control name": "Managing information security in the ICT supply chain",
          "Theme": "Organizational",
          "Applicability": "Applicable",
          "Applicability justification": "Required for SaaS, repository, identity, and hosting chain.",
          "Control owner": "Supplier Manager",
          "Implementation status": "Planned",
          "Evidence status": "Partial",
          "Operating effectiveness": "Not assessed",
          "Evidence reference": "SINV-2026-Q3",
          "SoA linkage": "SOA-A.5.21",
          "Risk linkage": "RISK-2026-018",
          "Open actions": "Map subprocessor and ICT dependency chain",
          "Last review date": "2026-08-29",
          "Next review date": "2026-11-29",
          "Notes": "Premium supplier review input. STALL-2026-Q3: still Planned from the 2025 improvement programme."
        },
        {
          "Control ID": "A.5.22",
          "Control name": "Monitoring, review and change management of supplier services",
          "Theme": "Organizational",
          "Applicability": "Applicable",
          "Applicability justification": "Required for supplier performance and service change risk.",
          "Control owner": "Supplier Manager",
          "Implementation status": "In progress",
          "Evidence status": "Partial",
          "Operating effectiveness": "Partially effective",
          "Evidence reference": "SINV-CLOUDHOST-2026-Q3",
          "SoA linkage": "SOA-A.5.22",
          "Risk linkage": "RISK-2026-018",
          "Open actions": "Add quarterly service review note",
          "Last review date": "2026-08-29",
          "Next review date": "2026-11-29",
          "Notes": "Service changes monitored."
        },
        {
          "Control ID": "A.5.23",
          "Control name": "Information security for use of cloud services",
          "Theme": "Organizational",
          "Applicability": "Applicable",
          "Applicability justification": "Required because core services are cloud and SaaS based.",
          "Control owner": "Cloud Service Owner",
          "Implementation status": "In progress",
          "Evidence status": "Partial",
          "Operating effectiveness": "Partially effective",
          "Evidence reference": "CLOUD-CTRL-2026-Q3",
          "SoA linkage": "SOA-A.5.23",
          "Risk linkage": "RISK-2026-018",
          "Open actions": "Confirm shared responsibility matrix",
          "Last review date": "2026-08-29",
          "Next review date": "2026-10-15",
          "Notes": "Linked to CSRM."
        },
        {
          "Control ID": "A.5.24",
          "Control name": "Information security incident management planning and preparation",
          "Theme": "Organizational",
          "Applicability": "Applicable",
          "Applicability justification": "Required for incident readiness.",
          "Control owner": "Incident Manager",
          "Implementation status": "Implemented",
          "Evidence status": "Complete",
          "Operating effectiveness": "Effective",
          "Evidence reference": "IRP-2026",
          "SoA linkage": "SOA-A.5.24",
          "Risk linkage": "IRRT-2026-Q3",
          "Open actions": "None",
          "Last review date": "2026-08-25",
          "Next review date": "2026-11-25",
          "Notes": "Runbooks linked."
        },
        {
          "Control ID": "A.5.25",
          "Control name": "Assessment and decision on information security events",
          "Theme": "Organizational",
          "Applicability": "Applicable",
          "Applicability justification": "Required for event triage.",
          "Control owner": "Incident Manager",
          "Implementation status": "Implemented",
          "Evidence status": "Partial",
          "Operating effectiveness": "Partially effective",
          "Evidence reference": "SIR-2026-Q3",
          "SoA linkage": "SOA-A.5.25",
          "Risk linkage": "IRRT-2026-Q3",
          "Open actions": "Add event decision sample",
          "Last review date": "2026-08-25",
          "Next review date": "2026-11-25",
          "Notes": "Operational record."
        },
        {
          "Control ID": "A.5.26",
          "Control name": "Response to information security incidents",
          "Theme": "Organizational",
          "Applicability": "Applicable",
          "Applicability justification": "Required for incident handling.",
          "Control owner": "Incident Manager",
          "Implementation status": "Implemented",
          "Evidence status": "Partial",
          "Operating effectiveness": "Partially effective",
          "Evidence reference": "IR-RB-2026",
          "SoA linkage": "SOA-A.5.26",
          "Risk linkage": "IRRT-2026-Q3",
          "Open actions": "Complete tabletop exercise evidence",
          "Last review date": "2026-08-25",
          "Next review date": "2026-11-25",
          "Notes": "Linked to runbooks."
        },
        {
          "Control ID": "A.5.27",
          "Control name": "Learning from information security incidents",
          "Theme": "Organizational",
          "Applicability": "Applicable",
          "Applicability justification": "Required for improvement after incidents.",
          "Control owner": "Incident Manager",
          "Implementation status": "Planned",
          "Evidence status": "Partial",
          "Operating effectiveness": "Not assessed",
          "Evidence reference": "CIL-2026-Q3",
          "SoA linkage": "SOA-A.5.27",
          "Risk linkage": "SIR-2026-Q3",
          "Open actions": "Add lessons-learned workflow",
          "Last review date": "2026-08-25",
          "Next review date": "2026-11-25",
          "Notes": "Feeds continual improvement. STALL-2026-Q3: still Planned from the 2025 improvement programme."
        },
        {
          "Control ID": "A.5.28",
          "Control name": "Collection of evidence",
          "Theme": "Organizational",
          "Applicability": "Applicable",
          "Applicability justification": "Required for audit and incident evidence.",
          "Control owner": "ISMS Manager",
          "Implementation status": "Implemented",
          "Evidence status": "Complete",
          "Operating effectiveness": "Effective",
          "Evidence reference": "ELAI-2026-Q3",
          "SoA linkage": "SOA-A.5.28",
          "Risk linkage": "RISK-2026-021",
          "Open actions": "None",
          "Last review date": "2026-08-28",
          "Next review date": "2026-11-28",
          "Notes": "Evidence log maintained."
        },
        {
          "Control ID": "A.5.29",
          "Control name": "Information security during disruption",
          "Theme": "Organizational",
          "Applicability": "Applicable",
          "Applicability justification": "Required for continuity of critical services.",
          "Control owner": "Business Continuity Manager",
          "Implementation status": "Implemented",
          "Evidence status": "Partial",
          "Operating effectiveness": "Partially effective",
          "Evidence reference": "BCP-CUSTPORTAL-2026",
          "SoA linkage": "SOA-A.5.29",
          "Risk linkage": "RISK-2026-018",
          "Open actions": "Schedule continuity test",
          "Last review date": "2026-08-29",
          "Next review date": "2026-11-29",
          "Notes": "Linked to Customer Portal."
        },
        {
          "Control ID": "A.5.30",
          "Control name": "ICT readiness for business continuity",
          "Theme": "Organizational",
          "Applicability": "Applicable",
          "Applicability justification": "Required for ICT continuity readiness.",
          "Control owner": "IT Operations",
          "Implementation status": "In progress",
          "Evidence status": "Partial",
          "Operating effectiveness": "Partially effective",
          "Evidence reference": "DRP-CUSTPORTAL-001",
          "SoA linkage": "SOA-A.5.30",
          "Risk linkage": "RISK-2026-018",
          "Open actions": "Complete restore-test record",
          "Last review date": "2026-08-29",
          "Next review date": "2026-10-31",
          "Notes": "Linked to DRP."
        },
        {
          "Control ID": "A.5.31",
          "Control name": "Legal, statutory, regulatory and contractual requirements",
          "Theme": "Organizational",
          "Applicability": "Applicable",
          "Applicability justification": "Required for legal and contractual obligations.",
          "Control owner": "Compliance Manager",
          "Implementation status": "Implemented",
          "Evidence status": "Partial",
          "Operating effectiveness": "Partially effective",
          "Evidence reference": "LRR-2026-Q3",
          "SoA linkage": "SOA-A.5.31",
          "Risk linkage": "RISK-2026-033",
          "Open actions": "Update customer DPA evidence reference",
          "Last review date": "2026-08-20",
          "Next review date": "2026-11-20",
          "Notes": "Linked to legal register."
        },
        {
          "Control ID": "A.5.32",
          "Control name": "Intellectual property rights",
          "Theme": "Organizational",
          "Applicability": "Applicable",
          "Applicability justification": "Required for software, content, and third-party licenses.",
          "Control owner": "Legal Counsel",
          "Implementation status": "Planned",
          "Evidence status": "Partial",
          "Operating effectiveness": "Not assessed",
          "Evidence reference": "IPR-2026-Q3",
          "SoA linkage": "SOA-A.5.32",
          "Risk linkage": "REQT-7.5",
          "Open actions": "Review open-source notices",
          "Last review date": "2026-08-27",
          "Next review date": "2026-11-27",
          "Notes": "Linked to software inventory. STALL-2026-Q3: still Planned from the 2025 improvement programme."
        },
        {
          "Control ID": "A.5.33",
          "Control name": "Protection of records",
          "Theme": "Organizational",
          "Applicability": "Applicable",
          "Applicability justification": "Required to protect ISMS and operational records.",
          "Control owner": "Document Owner",
          "Implementation status": "Implemented",
          "Evidence status": "Complete",
          "Operating effectiveness": "Effective",
          "Evidence reference": "RRS-2026-Q3",
          "SoA linkage": "SOA-A.5.33",
          "Risk linkage": "RISK-2026-021",
          "Open actions": "None",
          "Last review date": "2026-08-28",
          "Next review date": "2026-11-28",
          "Notes": "Retention schedule maintained."
        },
        {
          "Control ID": "A.5.34",
          "Control name": "Privacy and protection of PII",
          "Theme": "Organizational",
          "Applicability": "Applicable",
          "Applicability justification": "Required because HR and customer personal data are processed.",
          "Control owner": "Privacy Lead",
          "Implementation status": "Implemented",
          "Evidence status": "Partial",
          "Operating effectiveness": "Partially effective",
          "Evidence reference": "DPAR-2026-Q3",
          "SoA linkage": "SOA-A.5.34",
          "Risk linkage": "RISK-2026-033",
          "Open actions": "Complete HR retention mapping",
          "Last review date": "2026-08-20",
          "Next review date": "2026-11-20",
          "Notes": "Linked to GDPR records."
        },
        {
          "Control ID": "A.5.35",
          "Control name": "Independent review of information security",
          "Theme": "Organizational",
          "Applicability": "Applicable",
          "Applicability justification": "Required to independently review ISMS effectiveness.",
          "Control owner": "Internal Auditor",
          "Implementation status": "Implemented",
          "Evidence status": "Complete",
          "Operating effectiveness": "Effective",
          "Evidence reference": "IAP-2026",
          "SoA linkage": "SOA-A.5.35",
          "Risk linkage": "REQT-9.2",
          "Open actions": "None",
          "Last review date": "2026-08-25",
          "Next review date": "2026-11-25",
          "Notes": "Internal audit programme active."
        },
        {
          "Control ID": "A.5.36",
          "Control name": "Compliance with policies, rules and standards for information security",
          "Theme": "Organizational",
          "Applicability": "Applicable",
          "Applicability justification": "Required to verify compliance with ISMS requirements.",
          "Control owner": "ISMS Manager",
          "Implementation status": "Implemented",
          "Evidence status": "Partial",
          "Operating effectiveness": "Partially effective",
          "Evidence reference": "REQT-2026-Q3",
          "SoA linkage": "SOA-A.5.36",
          "Risk linkage": "RR-2026-Q3",
          "Open actions": "Update evidence mapping for Q4",
          "Last review date": "2026-08-29",
          "Next review date": "2026-11-29",
          "Notes": "Linked to REQT."
        },
        {
          "Control ID": "A.5.37",
          "Control name": "Documented operating procedures",
          "Theme": "Organizational",
          "Applicability": "Applicable",
          "Applicability justification": "Required for repeatable ISMS and IT operations.",
          "Control owner": "Process Owner",
          "Implementation status": "In progress",
          "Evidence status": "Partial",
          "Operating effectiveness": "Partially effective",
          "Evidence reference": "DOP-2026",
          "SoA linkage": "SOA-A.5.37",
          "Risk linkage": "REQT-8.1",
          "Open actions": "Approve two operating procedures",
          "Last review date": "2026-08-29",
          "Next review date": "2026-11-29",
          "Notes": "Procedure template used. Re-sampled after IL-005; less robust than the Stage 2 sample; evidence Partial."
        },
        {
          "Control ID": "A.6.1",
          "Control name": "Screening",
          "Theme": "People",
          "Applicability": "Applicable",
          "Applicability justification": "Required for relevant roles before employment.",
          "Control owner": "HR Manager",
          "Implementation status": "Implemented",
          "Evidence status": "Partial",
          "Operating effectiveness": "Partially effective",
          "Evidence reference": "HR-ONB-2026-023",
          "SoA linkage": "SOA-A.6.1",
          "Risk linkage": "ONC-2026",
          "Open actions": "Document screening applicability per role",
          "Last review date": "2026-08-20",
          "Next review date": "2026-11-20",
          "Notes": "Linked to onboarding."
        },
        {
          "Control ID": "A.6.2",
          "Control name": "Terms and conditions of employment",
          "Theme": "People",
          "Applicability": "Applicable",
          "Applicability justification": "Required for contractual security obligations.",
          "Control owner": "HR Manager",
          "Implementation status": "Implemented",
          "Evidence status": "Complete",
          "Operating effectiveness": "Effective",
          "Evidence reference": "HR-ONB-2026-023",
          "SoA linkage": "SOA-A.6.2",
          "Risk linkage": "ONC-2026",
          "Open actions": "None",
          "Last review date": "2026-08-20",
          "Next review date": "2026-11-20",
          "Notes": "Included in onboarding evidence."
        },
        {
          "Control ID": "A.6.3",
          "Control name": "Information security awareness, education and training",
          "Theme": "People",
          "Applicability": "Applicable",
          "Applicability justification": "Required for staff and contractors.",
          "Control owner": "HR Manager",
          "Implementation status": "Implemented",
          "Evidence status": "Complete",
          "Operating effectiveness": "Effective",
          "Evidence reference": "TRAIN-REC-2026-188",
          "SoA linkage": "SOA-A.6.3",
          "Risk linkage": "REQT-7.3",
          "Open actions": "None",
          "Last review date": "2026-08-20",
          "Next review date": "2026-11-20",
          "Notes": "Training evidence captured."
        },
        {
          "Control ID": "A.6.4",
          "Control name": "Disciplinary process",
          "Theme": "People",
          "Applicability": "Applicable",
          "Applicability justification": "Required for security policy violations.",
          "Control owner": "HR Manager",
          "Implementation status": "Planned",
          "Evidence status": "Partial",
          "Operating effectiveness": "Not assessed",
          "Evidence reference": "HRP-2026",
          "SoA linkage": "SOA-A.6.4",
          "Risk linkage": "REQT-7.5",
          "Open actions": "Confirm disciplinary escalation path",
          "Last review date": "2026-08-20",
          "Next review date": "2026-11-20",
          "Notes": "HR policy reference. STALL-2026-Q3: still Planned from the 2025 improvement programme."
        },
        {
          "Control ID": "A.6.5",
          "Control name": "Responsibilities after termination or change of employment",
          "Theme": "People",
          "Applicability": "Applicable",
          "Applicability justification": "Required for offboarding and role changes.",
          "Control owner": "HR Manager",
          "Implementation status": "Implemented",
          "Evidence status": "Complete",
          "Operating effectiveness": "Effective",
          "Evidence reference": "OFC-2026-018",
          "SoA linkage": "SOA-A.6.5",
          "Risk linkage": "RISK-2026-033",
          "Open actions": "None",
          "Last review date": "2026-08-20",
          "Next review date": "2026-11-20",
          "Notes": "Linked to OFC."
        },
        {
          "Control ID": "A.6.6",
          "Control name": "Confidentiality or non-disclosure agreements",
          "Theme": "People",
          "Applicability": "Applicable",
          "Applicability justification": "Required for employees, contractors, and suppliers.",
          "Control owner": "Legal Counsel",
          "Implementation status": "Implemented",
          "Evidence status": "Partial",
          "Operating effectiveness": "Partially effective",
          "Evidence reference": "NDA-REG-2026",
          "SoA linkage": "SOA-A.6.6",
          "Risk linkage": "HR-ONB-2026-023",
          "Open actions": "Add contractor sample",
          "Last review date": "2026-08-20",
          "Next review date": "2026-11-20",
          "Notes": "Contract evidence maintained."
        },
        {
          "Control ID": "A.6.7",
          "Control name": "Remote working",
          "Theme": "People",
          "Applicability": "Applicable",
          "Applicability justification": "Required because staff work remotely.",
          "Control owner": "IT Operations",
          "Implementation status": "Implemented",
          "Evidence status": "Partial",
          "Operating effectiveness": "Partially effective",
          "Evidence reference": "REMOTE-2026",
          "SoA linkage": "SOA-A.6.7",
          "Risk linkage": "RISK-2026-031",
          "Open actions": "Review home-office guidance evidence",
          "Last review date": "2026-08-29",
          "Next review date": "2026-11-29",
          "Notes": "Endpoint controls apply."
        },
        {
          "Control ID": "A.6.8",
          "Control name": "Information security event reporting",
          "Theme": "People",
          "Applicability": "Applicable",
          "Applicability justification": "Required so personnel report security events.",
          "Control owner": "Incident Manager",
          "Implementation status": "Implemented",
          "Evidence status": "Partial",
          "Operating effectiveness": "Partially effective",
          "Evidence reference": "IRP-2026",
          "SoA linkage": "SOA-A.6.8",
          "Risk linkage": "IRRT-2026-Q3",
          "Open actions": "Add reporting drill evidence",
          "Last review date": "2026-08-25",
          "Next review date": "2026-11-25",
          "Notes": "Covered in awareness."
        },
        {
          "Control ID": "A.7.1",
          "Control name": "Physical security perimeters",
          "Theme": "Physical",
          "Applicability": "Applicable",
          "Applicability justification": "Relevant for office and equipment storage.",
          "Control owner": "Facilities Manager",
          "Implementation status": "Implemented",
          "Evidence status": "Partial",
          "Operating effectiveness": "Partially effective",
          "Evidence reference": "PHY-SEC-2026",
          "SoA linkage": "SOA-A.7.1",
          "Risk linkage": "AI-AST-006",
          "Open actions": "Update office perimeter record",
          "Last review date": "2026-08-22",
          "Next review date": "2026-11-22",
          "Notes": "Lightweight office context."
        },
        {
          "Control ID": "A.7.2",
          "Control name": "Physical entry",
          "Theme": "Physical",
          "Applicability": "Applicable",
          "Applicability justification": "Relevant for controlled office access.",
          "Control owner": "Facilities Manager",
          "Implementation status": "Implemented",
          "Evidence status": "Partial",
          "Operating effectiveness": "Partially effective",
          "Evidence reference": "PHY-ACCESS-2026",
          "SoA linkage": "SOA-A.7.2",
          "Risk linkage": "AI-AST-006",
          "Open actions": "Review visitor access logs",
          "Last review date": "2026-08-22",
          "Next review date": "2026-11-22",
          "Notes": "Visitor register maintained."
        },
        {
          "Control ID": "A.7.3",
          "Control name": "Securing offices, rooms and facilities",
          "Theme": "Physical",
          "Applicability": "Applicable",
          "Applicability justification": "Relevant for office workspaces and records.",
          "Control owner": "Facilities Manager",
          "Implementation status": "Implemented",
          "Evidence status": "Partial",
          "Operating effectiveness": "Partially effective",
          "Evidence reference": "PHY-OFFICE-2026",
          "SoA linkage": "SOA-A.7.3",
          "Risk linkage": "AI-AST-006",
          "Open actions": "Add room review record",
          "Last review date": "2026-08-22",
          "Next review date": "2026-11-22",
          "Notes": "Office controls documented."
        },
        {
          "Control ID": "A.7.4",
          "Control name": "Physical security monitoring",
          "Theme": "Physical",
          "Applicability": "Applicable",
          "Applicability justification": "Relevant to office and equipment monitoring.",
          "Control owner": "Facilities Manager",
          "Implementation status": "In progress",
          "Evidence status": "Partial",
          "Operating effectiveness": "Partially effective",
          "Evidence reference": "PHY-MON-2026-Q3",
          "SoA linkage": "SOA-A.7.4",
          "Risk linkage": "AI-AST-006",
          "Open actions": "Confirm monitoring coverage",
          "Last review date": "2026-08-22",
          "Next review date": "2026-10-15",
          "Notes": "Representative physical-control example."
        },
        {
          "Control ID": "A.7.5",
          "Control name": "Protecting against physical and environmental threats",
          "Theme": "Physical",
          "Applicability": "Applicable",
          "Applicability justification": "Relevant to equipment and office availability.",
          "Control owner": "Facilities Manager",
          "Implementation status": "Planned",
          "Evidence status": "Partial",
          "Operating effectiveness": "Not assessed",
          "Evidence reference": "BCP-2026",
          "SoA linkage": "SOA-A.7.5",
          "Risk linkage": "BCP-2026",
          "Open actions": "Document environmental assumptions",
          "Last review date": "2026-08-22",
          "Next review date": "2026-11-22",
          "Notes": "Cloud services reduce datacenter exposure. STALL-2026-Q3: still Planned from the 2025 improvement programme."
        },
        {
          "Control ID": "A.7.6",
          "Control name": "Working in secure areas",
          "Theme": "Physical",
          "Applicability": "Not applicable",
          "Applicability justification": "Excluded because the ISMS scope has no dedicated secure area, laboratory, datacenter, or restricted physical processing room operated by Arcfield.",
          "Control owner": "Facilities Manager",
          "Implementation status": "Not applicable",
          "Evidence status": "Not applicable",
          "Operating effectiveness": "Not assessed",
          "Evidence reference": "SOA-A.7.6",
          "SoA linkage": "SOA-A.7.6",
          "Risk linkage": "Not applicable",
          "Open actions": "None",
          "Last review date": "2026-08-22",
          "Next review date": "2026-11-22",
          "Notes": "Justification retained in SoA. Excluded because the ISMS scope has no dedicated secure area, laboratory, datacenter, or restricted physical processing room operated by Arcfield."
        },
        {
          "Control ID": "A.7.7",
          "Control name": "Clear desk and clear screen",
          "Theme": "Physical",
          "Applicability": "Applicable",
          "Applicability justification": "Relevant for office and remote working.",
          "Control owner": "HR Manager",
          "Implementation status": "Implemented",
          "Evidence status": "Partial",
          "Operating effectiveness": "Partially effective",
          "Evidence reference": "AUP-ACK-2026-Q3",
          "SoA linkage": "SOA-A.7.7",
          "Risk linkage": "RISK-2026-033",
          "Open actions": "Add awareness reminder",
          "Last review date": "2026-08-20",
          "Next review date": "2026-11-20",
          "Notes": "Covered in acceptable use."
        },
        {
          "Control ID": "A.7.8",
          "Control name": "Equipment siting and protection",
          "Theme": "Physical",
          "Applicability": "Applicable",
          "Applicability justification": "Relevant for endpoint and office equipment.",
          "Control owner": "IT Operations",
          "Implementation status": "Implemented",
          "Evidence status": "Partial",
          "Operating effectiveness": "Partially effective",
          "Evidence reference": "AI-AST-006",
          "SoA linkage": "SOA-A.7.8",
          "Risk linkage": "AI-AST-006",
          "Open actions": "Update endpoint inventory sample",
          "Last review date": "2026-08-20",
          "Next review date": "2026-11-20",
          "Notes": "Endpoint fleet controlled."
        },
        {
          "Control ID": "A.7.9",
          "Control name": "Security of assets off-premises",
          "Theme": "Physical",
          "Applicability": "Applicable",
          "Applicability justification": "Required for laptops and remote work.",
          "Control owner": "IT Operations",
          "Implementation status": "Implemented",
          "Evidence status": "Partial",
          "Operating effectiveness": "Partially effective",
          "Evidence reference": "MDM-2026-Q3",
          "SoA linkage": "SOA-A.7.9",
          "Risk linkage": "AI-AST-006",
          "Open actions": "Complete device encryption sample",
          "Last review date": "2026-08-20",
          "Next review date": "2026-11-20",
          "Notes": "Remote device controls."
        },
        {
          "Control ID": "A.7.10",
          "Control name": "Storage media",
          "Theme": "Physical",
          "Applicability": "Applicable",
          "Applicability justification": "Relevant to endpoint media and backups.",
          "Control owner": "IT Operations",
          "Implementation status": "Implemented",
          "Evidence status": "Partial",
          "Operating effectiveness": "Partially effective",
          "Evidence reference": "MDM-2026-Q3",
          "SoA linkage": "SOA-A.7.10",
          "Risk linkage": "AI-AST-006",
          "Open actions": "Document removable media restriction",
          "Last review date": "2026-08-20",
          "Next review date": "2026-11-20",
          "Notes": "Endpoint policy."
        },
        {
          "Control ID": "A.7.11",
          "Control name": "Supporting utilities",
          "Theme": "Physical",
          "Applicability": "Not applicable",
          "Applicability justification": "Excluded because Arcfield does not operate datacenter or server-room utilities in the ISMS scope; production processing relies on cloud-provider facilities covered by supplier assurance.",
          "Control owner": "Facilities Manager",
          "Implementation status": "Not applicable",
          "Evidence status": "Not applicable",
          "Operating effectiveness": "Not assessed",
          "Evidence reference": "SINV-CLOUDHOST-2026-Q3",
          "SoA linkage": "SOA-A.7.11",
          "Risk linkage": "RISK-2026-018",
          "Open actions": "Maintain supplier evidence",
          "Last review date": "2026-08-29",
          "Next review date": "2026-11-29",
          "Notes": "Cloud supplier responsibility. Excluded because Arcfield does not operate datacenter or server-room utilities in the ISMS scope; production processing relies on cloud-provider facilities covered by supplier assurance."
        },
        {
          "Control ID": "A.7.12",
          "Control name": "Cabling security",
          "Theme": "Physical",
          "Applicability": "Not applicable",
          "Applicability justification": "Excluded because Arcfield does not operate managed cabling infrastructure for in-scope production systems; office network cabling is not used for hosting customer services.",
          "Control owner": "Facilities Manager",
          "Implementation status": "Not applicable",
          "Evidence status": "Not applicable",
          "Operating effectiveness": "Not assessed",
          "Evidence reference": "SOA-A.7.12",
          "SoA linkage": "SOA-A.7.12",
          "Risk linkage": "Not applicable",
          "Open actions": "None",
          "Last review date": "2026-08-22",
          "Next review date": "2026-11-22",
          "Notes": "Justification retained. Excluded because Arcfield does not operate managed cabling infrastructure for in-scope production systems; office network cabling is not used for hosting customer services."
        },
        {
          "Control ID": "A.7.13",
          "Control name": "Equipment maintenance",
          "Theme": "Physical",
          "Applicability": "Applicable",
          "Applicability justification": "Relevant to managed endpoint fleet.",
          "Control owner": "IT Operations",
          "Implementation status": "Implemented",
          "Evidence status": "Partial",
          "Operating effectiveness": "Partially effective",
          "Evidence reference": "MDM-2026-Q3",
          "SoA linkage": "SOA-A.7.13",
          "Risk linkage": "AI-AST-006",
          "Open actions": "Add repair/maintenance record sample",
          "Last review date": "2026-08-20",
          "Next review date": "2026-11-20",
          "Notes": "Endpoint lifecycle."
        },
        {
          "Control ID": "A.7.14",
          "Control name": "Secure disposal or re-use of equipment",
          "Theme": "Physical",
          "Applicability": "Applicable",
          "Applicability justification": "Required for endpoint disposal and reuse.",
          "Control owner": "IT Operations",
          "Implementation status": "Implemented",
          "Evidence status": "Partial",
          "Operating effectiveness": "Partially effective",
          "Evidence reference": "OFC-2026-018",
          "SoA linkage": "SOA-A.7.14",
          "Risk linkage": "RISK-2026-033",
          "Open actions": "Attach wipe certificate sample",
          "Last review date": "2026-08-20",
          "Next review date": "2026-11-20",
          "Notes": "Offboarding link."
        },
        {
          "Control ID": "A.8.1",
          "Control name": "User endpoint devices",
          "Theme": "Technological",
          "Applicability": "Applicable",
          "Applicability justification": "Required for managed laptop fleet.",
          "Control owner": "IT Operations",
          "Implementation status": "Implemented",
          "Evidence status": "Partial",
          "Operating effectiveness": "Partially effective",
          "Evidence reference": "MDM-2026-Q3",
          "SoA linkage": "SOA-A.8.1",
          "Risk linkage": "AI-AST-006",
          "Open actions": "Complete device compliance export",
          "Last review date": "2026-08-20",
          "Next review date": "2026-11-20",
          "Notes": "Endpoint fleet tracked."
        },
        {
          "Control ID": "A.8.2",
          "Control name": "Privileged access rights",
          "Theme": "Technological",
          "Applicability": "Applicable",
          "Applicability justification": "Required for production and identity administration.",
          "Control owner": "IT Operations",
          "Implementation status": "In progress",
          "Evidence status": "Partial",
          "Operating effectiveness": "Partially effective",
          "Evidence reference": "ACC-REV-2026-Q3",
          "SoA linkage": "SOA-A.8.2",
          "Risk linkage": "RISK-2026-014",
          "Open actions": "Finish Q3 privileged-access review",
          "Last review date": "2026-08-29",
          "Next review date": "2026-09-30",
          "Notes": "Treatment RTP-2026-014."
        },
        {
          "Control ID": "A.8.3",
          "Control name": "Information access restriction",
          "Theme": "Technological",
          "Applicability": "Applicable",
          "Applicability justification": "Required for restricted repositories and production data.",
          "Control owner": "IT Operations",
          "Implementation status": "Implemented",
          "Evidence status": "Partial",
          "Operating effectiveness": "Partially effective",
          "Evidence reference": "ACM-APP-CRM-001",
          "SoA linkage": "SOA-A.8.3",
          "Risk linkage": "RISK-2026-014",
          "Open actions": "Sample customer portal access groups",
          "Last review date": "2026-08-29",
          "Next review date": "2026-10-29",
          "Notes": "Access matrix evidence."
        },
        {
          "Control ID": "A.8.4",
          "Control name": "Access to source code",
          "Theme": "Technological",
          "Applicability": "Applicable",
          "Applicability justification": "Required for source repositories.",
          "Control owner": "Engineering Lead",
          "Implementation status": "Implemented",
          "Evidence status": "Partial",
          "Operating effectiveness": "Partially effective",
          "Evidence reference": "SI-REPO-2026-014",
          "SoA linkage": "SOA-A.8.4",
          "Risk linkage": "RISK-2026-027",
          "Open actions": "Validate access group export",
          "Last review date": "2026-08-27",
          "Next review date": "2026-11-27",
          "Notes": "Customer portal repository."
        },
        {
          "Control ID": "A.8.5",
          "Control name": "Secure authentication",
          "Theme": "Technological",
          "Applicability": "Applicable",
          "Applicability justification": "Required for cloud, SaaS, and repository access.",
          "Control owner": "IT Operations",
          "Implementation status": "Implemented",
          "Evidence status": "Complete",
          "Operating effectiveness": "Effective",
          "Evidence reference": "IAM-CTRL-2026-Q3",
          "SoA linkage": "SOA-A.8.5",
          "Risk linkage": "RISK-2026-031",
          "Open actions": "None",
          "Last review date": "2026-08-29",
          "Next review date": "2026-09-30",
          "Notes": "MFA enforced."
        },
        {
          "Control ID": "A.8.6",
          "Control name": "Capacity management",
          "Theme": "Technological",
          "Applicability": "Applicable",
          "Applicability justification": "Required for service availability.",
          "Control owner": "IT Operations",
          "Implementation status": "Planned",
          "Evidence status": "Partial",
          "Operating effectiveness": "Not assessed",
          "Evidence reference": "MON-2026-Q3",
          "SoA linkage": "SOA-A.8.6",
          "Risk linkage": "RISK-2026-018",
          "Open actions": "Add capacity threshold evidence",
          "Last review date": "2026-08-29",
          "Next review date": "2026-11-29",
          "Notes": "Customer Portal monitoring. STALL-2026-Q3: still Planned from the 2025 improvement programme."
        },
        {
          "Control ID": "A.8.7",
          "Control name": "Protection against malware",
          "Theme": "Technological",
          "Applicability": "Applicable",
          "Applicability justification": "Required for endpoints and repositories.",
          "Control owner": "IT Operations",
          "Implementation status": "Implemented",
          "Evidence status": "Partial",
          "Operating effectiveness": "Partially effective",
          "Evidence reference": "EDR-2026-Q3",
          "SoA linkage": "SOA-A.8.7",
          "Risk linkage": "AI-AST-006",
          "Open actions": "Attach endpoint coverage report",
          "Last review date": "2026-08-20",
          "Next review date": "2026-11-20",
          "Notes": "EDR monitored."
        },
        {
          "Control ID": "A.8.8",
          "Control name": "Management of technical vulnerabilities",
          "Theme": "Technological",
          "Applicability": "Applicable",
          "Applicability justification": "Required for software and cloud services.",
          "Control owner": "Security Lead",
          "Implementation status": "In progress",
          "Evidence status": "Partial",
          "Operating effectiveness": "Partially effective",
          "Evidence reference": "VULN-2026-Q3",
          "SoA linkage": "SOA-A.8.8",
          "Risk linkage": "RISK-2026-027",
          "Open actions": "Close high vulnerability SLA sample",
          "Last review date": "2026-08-27",
          "Next review date": "2026-10-31",
          "Notes": "Linked to threat intelligence."
        },
        {
          "Control ID": "A.8.9",
          "Control name": "Configuration management",
          "Theme": "Technological",
          "Applicability": "Applicable",
          "Applicability justification": "Required for identity, cloud, endpoint, and application configuration.",
          "Control owner": "IT Operations",
          "Implementation status": "In progress",
          "Evidence status": "Partial",
          "Operating effectiveness": "Partially effective",
          "Evidence reference": "CFG-BASE-2026",
          "SoA linkage": "SOA-A.8.9",
          "Risk linkage": "RISK-2026-031",
          "Open actions": "Complete baseline exception review",
          "Last review date": "2026-08-29",
          "Next review date": "2026-09-30",
          "Notes": "Identity configuration risk. Re-sampled after IL-005; less robust than the Stage 2 sample; evidence Partial."
        },
        {
          "Control ID": "A.8.10",
          "Control name": "Information deletion",
          "Theme": "Technological",
          "Applicability": "Applicable",
          "Applicability justification": "Required for retention and offboarding.",
          "Control owner": "Data Owner",
          "Implementation status": "In progress",
          "Evidence status": "Partial",
          "Operating effectiveness": "Partially effective",
          "Evidence reference": "RRS-HR-001",
          "SoA linkage": "SOA-A.8.10",
          "Risk linkage": "RISK-2026-033",
          "Open actions": "Map HR folder deletion rule",
          "Last review date": "2026-08-20",
          "Next review date": "2026-11-20",
          "Notes": "Linked to retention schedule."
        },
        {
          "Control ID": "A.8.11",
          "Control name": "Data masking",
          "Theme": "Technological",
          "Applicability": "Applicable",
          "Applicability justification": "Relevant to test data and support access.",
          "Control owner": "Engineering Lead",
          "Implementation status": "Planned",
          "Evidence status": "Missing",
          "Operating effectiveness": "Not assessed",
          "Evidence reference": "TBD-DMASK-2026",
          "SoA linkage": "SOA-A.8.11",
          "Risk linkage": "RISK-2026-033",
          "Open actions": "Define masking rule for test datasets",
          "Last review date": "2026-08-27",
          "Next review date": "2026-10-31",
          "Notes": "Open implementation item. STALL-2026-Q3: still Planned from the 2025 improvement programme. No operating sample on this freeze (evidence Missing)."
        },
        {
          "Control ID": "A.8.12",
          "Control name": "Data leakage prevention",
          "Theme": "Technological",
          "Applicability": "Applicable",
          "Applicability justification": "Relevant to customer and HR data transfer.",
          "Control owner": "Security Lead",
          "Implementation status": "Planned",
          "Evidence status": "Partial",
          "Operating effectiveness": "Not assessed",
          "Evidence reference": "DLP-PLAN-2026",
          "SoA linkage": "SOA-A.8.12",
          "Risk linkage": "RISK-2026-033",
          "Open actions": "Decide DLP scope for SaaS tools",
          "Last review date": "2026-08-29",
          "Next review date": "2026-11-29",
          "Notes": "Risk-based implementation. STALL-2026-Q3: still Planned from the 2025 improvement programme."
        },
        {
          "Control ID": "A.8.13",
          "Control name": "Information backup",
          "Theme": "Technological",
          "Applicability": "Applicable",
          "Applicability justification": "Required for availability and evidence integrity.",
          "Control owner": "IT Operations",
          "Implementation status": "Implemented",
          "Evidence status": "Complete",
          "Operating effectiveness": "Effective",
          "Evidence reference": "BKP-CRM-001",
          "SoA linkage": "SOA-A.8.13",
          "Risk linkage": "RISK-2026-021",
          "Open actions": "None",
          "Last review date": "2026-08-28",
          "Next review date": "2026-11-28",
          "Notes": "Backup evidence sampled quarterly."
        },
        {
          "Control ID": "A.8.14",
          "Control name": "Redundancy of information processing facilities",
          "Theme": "Technological",
          "Applicability": "Applicable",
          "Applicability justification": "Required for service availability where supplier redundancy is relied on.",
          "Control owner": "IT Operations",
          "Implementation status": "Implemented",
          "Evidence status": "Partial",
          "Operating effectiveness": "Partially effective",
          "Evidence reference": "SINV-CLOUDHOST-2026-Q3",
          "SoA linkage": "SOA-A.8.14",
          "Risk linkage": "RISK-2026-018",
          "Open actions": "Confirm supplier redundancy statement",
          "Last review date": "2026-08-29",
          "Next review date": "2026-10-15",
          "Notes": "Supplier evidence."
        },
        {
          "Control ID": "A.8.15",
          "Control name": "Logging",
          "Theme": "Technological",
          "Applicability": "Applicable",
          "Applicability justification": "Required for security monitoring and investigation.",
          "Control owner": "Security Lead",
          "Implementation status": "Implemented",
          "Evidence status": "Partial",
          "Operating effectiveness": "Partially effective",
          "Evidence reference": "LOG-2026-Q3",
          "SoA linkage": "SOA-A.8.15",
          "Risk linkage": "RISK-2026-014",
          "Open actions": "Document production log retention",
          "Last review date": "2026-08-29",
          "Next review date": "2026-11-29",
          "Notes": "Logs support incident response."
        },
        {
          "Control ID": "A.8.16",
          "Control name": "Monitoring activities",
          "Theme": "Technological",
          "Applicability": "Applicable",
          "Applicability justification": "Required for detection of security events.",
          "Control owner": "Security Lead",
          "Implementation status": "In progress",
          "Evidence status": "Partial",
          "Operating effectiveness": "Partially effective",
          "Evidence reference": "MON-2026-Q3",
          "SoA linkage": "SOA-A.8.16",
          "Risk linkage": "IRRT-2026-Q3",
          "Open actions": "Add alert sample evidence",
          "Last review date": "2026-08-29",
          "Next review date": "2026-10-31",
          "Notes": "Monitoring use cases in progress."
        },
        {
          "Control ID": "A.8.17",
          "Control name": "Clock synchronization",
          "Theme": "Technological",
          "Applicability": "Applicable",
          "Applicability justification": "Required for reliable logging and investigations.",
          "Control owner": "IT Operations",
          "Implementation status": "Implemented",
          "Evidence status": "Partial",
          "Operating effectiveness": "Effective",
          "Evidence reference": "CFG-BASE-2026",
          "SoA linkage": "SOA-A.8.17",
          "Risk linkage": "A.8.15",
          "Open actions": "Attach NTP baseline evidence",
          "Last review date": "2026-08-29",
          "Next review date": "2026-11-29",
          "Notes": "Baseline evidence."
        },
        {
          "Control ID": "A.8.18",
          "Control name": "Use of privileged utility programs",
          "Theme": "Technological",
          "Applicability": "Applicable",
          "Applicability justification": "Relevant to administrative tooling.",
          "Control owner": "IT Operations",
          "Implementation status": "In progress",
          "Evidence status": "Partial",
          "Operating effectiveness": "Partially effective",
          "Evidence reference": "ACC-REV-2026-Q3",
          "SoA linkage": "SOA-A.8.18",
          "Risk linkage": "RISK-2026-014",
          "Open actions": "Review privileged utility access",
          "Last review date": "2026-08-29",
          "Next review date": "2026-09-30",
          "Notes": "Privileged access control."
        },
        {
          "Control ID": "A.8.19",
          "Control name": "Installation of software on operational systems",
          "Theme": "Technological",
          "Applicability": "Applicable",
          "Applicability justification": "Required for production and endpoint change control.",
          "Control owner": "IT Operations",
          "Implementation status": "Implemented",
          "Evidence status": "Partial",
          "Operating effectiveness": "Partially effective",
          "Evidence reference": "CMP-2026-Q3",
          "SoA linkage": "SOA-A.8.19",
          "Risk linkage": "RISK-2026-027",
          "Open actions": "Add deployment approval sample",
          "Last review date": "2026-08-27",
          "Next review date": "2026-11-27",
          "Notes": "Change management link."
        },
        {
          "Control ID": "A.8.20",
          "Control name": "Networks security",
          "Theme": "Technological",
          "Applicability": "Applicable",
          "Applicability justification": "Required for cloud and office connectivity.",
          "Control owner": "IT Operations",
          "Implementation status": "Implemented",
          "Evidence status": "Partial",
          "Operating effectiveness": "Partially effective",
          "Evidence reference": "NSP-2026",
          "SoA linkage": "SOA-A.8.20",
          "Risk linkage": "RISK-2026-018",
          "Open actions": "Update network diagram evidence",
          "Last review date": "2026-08-29",
          "Next review date": "2026-11-29",
          "Notes": "Network controls documented."
        },
        {
          "Control ID": "A.8.21",
          "Control name": "Security of network services",
          "Theme": "Technological",
          "Applicability": "Applicable",
          "Applicability justification": "Relevant to supplier and cloud network services.",
          "Control owner": "IT Operations",
          "Implementation status": "Implemented",
          "Evidence status": "Partial",
          "Operating effectiveness": "Partially effective",
          "Evidence reference": "SINV-CLOUDHOST-2026-Q3",
          "SoA linkage": "SOA-A.8.21",
          "Risk linkage": "RISK-2026-018",
          "Open actions": "Confirm provider network service evidence",
          "Last review date": "2026-08-29",
          "Next review date": "2026-10-15",
          "Notes": "Supplier service evidence."
        },
        {
          "Control ID": "A.8.22",
          "Control name": "Segregation of networks",
          "Theme": "Technological",
          "Applicability": "Applicable",
          "Applicability justification": "Required for production and management network separation.",
          "Control owner": "IT Operations",
          "Implementation status": "In progress",
          "Evidence status": "Partial",
          "Operating effectiveness": "Partially effective",
          "Evidence reference": "NET-SEG-2026",
          "SoA linkage": "SOA-A.8.22",
          "Risk linkage": "RISK-2026-014",
          "Open actions": "Attach cloud segmentation evidence",
          "Last review date": "2026-08-29",
          "Next review date": "2026-10-31",
          "Notes": "Cloud segmentation."
        },
        {
          "Control ID": "A.8.23",
          "Control name": "Web filtering",
          "Theme": "Technological",
          "Applicability": "Applicable",
          "Applicability justification": "Relevant to endpoint protection and acceptable use.",
          "Control owner": "IT Operations",
          "Implementation status": "Planned",
          "Evidence status": "Missing",
          "Operating effectiveness": "Not assessed",
          "Evidence reference": "TBD-WEBFILTER-2026",
          "SoA linkage": "SOA-A.8.23",
          "Risk linkage": "AUP-ACK-2026-Q3",
          "Open actions": "Decide web-filtering scope",
          "Last review date": "2026-08-20",
          "Next review date": "2026-11-20",
          "Notes": "Risk-based decision pending. STALL-2026-Q3: still Planned from the 2025 improvement programme. No operating sample on this freeze (evidence Missing)."
        },
        {
          "Control ID": "A.8.24",
          "Control name": "Use of cryptography",
          "Theme": "Technological",
          "Applicability": "Applicable",
          "Applicability justification": "Required for confidentiality and integrity.",
          "Control owner": "Security Lead",
          "Implementation status": "Implemented",
          "Evidence status": "Complete",
          "Operating effectiveness": "Effective",
          "Evidence reference": "CKMP-2026-Q3",
          "SoA linkage": "SOA-A.8.24",
          "Risk linkage": "RISK-2026-033",
          "Open actions": "None",
          "Last review date": "2026-08-27",
          "Next review date": "2026-11-27",
          "Notes": "Cryptography policy maintained."
        },
        {
          "Control ID": "A.8.25",
          "Control name": "Secure development life cycle",
          "Theme": "Technological",
          "Applicability": "Applicable",
          "Applicability justification": "Required for customer portal software development.",
          "Control owner": "Engineering Lead",
          "Implementation status": "Implemented",
          "Evidence status": "Partial",
          "Operating effectiveness": "Partially effective",
          "Evidence reference": "SSDLC-REL-2026-014",
          "SoA linkage": "SOA-A.8.25",
          "Risk linkage": "RISK-2026-027",
          "Open actions": "Add release security gate sample",
          "Last review date": "2026-08-27",
          "Next review date": "2026-11-27",
          "Notes": "S-SDLC evidence."
        },
        {
          "Control ID": "A.8.26",
          "Control name": "Application security requirements",
          "Theme": "Technological",
          "Applicability": "Applicable",
          "Applicability justification": "Required for customer portal requirements.",
          "Control owner": "Product Owner",
          "Implementation status": "In progress",
          "Evidence status": "Partial",
          "Operating effectiveness": "Partially effective",
          "Evidence reference": "APPSEC-REQ-2026",
          "SoA linkage": "SOA-A.8.26",
          "Risk linkage": "RISK-2026-027",
          "Open actions": "Update requirement traceability",
          "Last review date": "2026-08-27",
          "Next review date": "2026-11-27",
          "Notes": "Product requirements."
        },
        {
          "Control ID": "A.8.27",
          "Control name": "Secure system architecture and engineering principles",
          "Theme": "Technological",
          "Applicability": "Applicable",
          "Applicability justification": "Required for architecture of in-scope systems.",
          "Control owner": "Engineering Lead",
          "Implementation status": "Planned",
          "Evidence status": "Partial",
          "Operating effectiveness": "Not assessed",
          "Evidence reference": "ARCH-SEC-2026",
          "SoA linkage": "SOA-A.8.27",
          "Risk linkage": "RISK-2026-027",
          "Open actions": "Document architecture decision record",
          "Last review date": "2026-08-27",
          "Next review date": "2026-11-27",
          "Notes": "Architecture evidence pending. STALL-2026-Q3: still Planned from the 2025 improvement programme."
        },
        {
          "Control ID": "A.8.28",
          "Control name": "Secure coding",
          "Theme": "Technological",
          "Applicability": "Applicable",
          "Applicability justification": "Required for developed software.",
          "Control owner": "Engineering Lead",
          "Implementation status": "Implemented",
          "Evidence status": "Partial",
          "Operating effectiveness": "Partially effective",
          "Evidence reference": "SSDLC-REL-2026-014",
          "SoA linkage": "SOA-A.8.28",
          "Risk linkage": "RISK-2026-027",
          "Open actions": "Confirm secret scanning coverage",
          "Last review date": "2026-08-27",
          "Next review date": "2026-09-20",
          "Notes": "Treatment RTP-2026-027."
        },
        {
          "Control ID": "A.8.29",
          "Control name": "Security testing in development and acceptance",
          "Theme": "Technological",
          "Applicability": "Applicable",
          "Applicability justification": "Required before release.",
          "Control owner": "Engineering Lead",
          "Implementation status": "In progress",
          "Evidence status": "Partial",
          "Operating effectiveness": "Partially effective",
          "Evidence reference": "TEST-SEC-2026",
          "SoA linkage": "SOA-A.8.29",
          "Risk linkage": "RISK-2026-027",
          "Open actions": "Add DAST/SAST evidence sample",
          "Last review date": "2026-08-27",
          "Next review date": "2026-11-27",
          "Notes": "Testing evidence."
        },
        {
          "Control ID": "A.8.30",
          "Control name": "Outsourced development",
          "Theme": "Technological",
          "Applicability": "Not applicable",
          "Applicability justification": "Excluded because Arcfield does not outsource software development within the current ISMS scope; all in-scope development is performed by internal engineering staff.",
          "Control owner": "Engineering Lead",
          "Implementation status": "Not applicable",
          "Evidence status": "Not applicable",
          "Operating effectiveness": "Not assessed",
          "Evidence reference": "SOA-A.8.30",
          "SoA linkage": "SOA-A.8.30",
          "Risk linkage": "Not applicable",
          "Open actions": "Reassess if outsourced development starts",
          "Last review date": "2026-08-27",
          "Next review date": "2026-11-27",
          "Notes": "Justification retained in SoA. Excluded because Arcfield does not outsource software development within the current ISMS scope; all in-scope development is performed by internal engineering staff."
        },
        {
          "Control ID": "A.8.31",
          "Control name": "Separation of development, test and production environments",
          "Theme": "Technological",
          "Applicability": "Applicable",
          "Applicability justification": "Required for safe software delivery.",
          "Control owner": "Engineering Lead",
          "Implementation status": "Implemented",
          "Evidence status": "Partial",
          "Operating effectiveness": "Partially effective",
          "Evidence reference": "ENV-SEP-2026",
          "SoA linkage": "SOA-A.8.31",
          "Risk linkage": "RISK-2026-027",
          "Open actions": "Attach environment access export",
          "Last review date": "2026-08-27",
          "Next review date": "2026-11-27",
          "Notes": "Environment separation."
        },
        {
          "Control ID": "A.8.32",
          "Control name": "Change management",
          "Theme": "Technological",
          "Applicability": "Applicable",
          "Applicability justification": "Required for changes to systems and services.",
          "Control owner": "Change Manager",
          "Implementation status": "Implemented",
          "Evidence status": "Partial",
          "Operating effectiveness": "Partially effective",
          "Evidence reference": "CMP-2026-Q3",
          "SoA linkage": "SOA-A.8.32",
          "Risk linkage": "RISK-2026-027",
          "Open actions": "Add emergency change sample",
          "Last review date": "2026-08-27",
          "Next review date": "2026-11-27",
          "Notes": "Change register used. Re-sampled after IL-005; less robust than the Stage 2 sample; evidence Partial."
        },
        {
          "Control ID": "A.8.33",
          "Control name": "Test information",
          "Theme": "Technological",
          "Applicability": "Applicable",
          "Applicability justification": "Required to protect production data in testing.",
          "Control owner": "Engineering Lead",
          "Implementation status": "Planned",
          "Evidence status": "Missing",
          "Operating effectiveness": "Not assessed",
          "Evidence reference": "TBD-TESTDATA-2026",
          "SoA linkage": "SOA-A.8.33",
          "Risk linkage": "RISK-2026-033",
          "Open actions": "Define test-data anonymization rule",
          "Last review date": "2026-08-27",
          "Next review date": "2026-10-31",
          "Notes": "Related to data masking. STALL-2026-Q3: still Planned from the 2025 improvement programme. No operating sample on this freeze (evidence Missing)."
        },
        {
          "Control ID": "A.8.34",
          "Control name": "Protection of information systems during audit testing",
          "Theme": "Technological",
          "Applicability": "Applicable",
          "Applicability justification": "Required to protect systems during internal and external audit testing.",
          "Control owner": "Internal Auditor",
          "Implementation status": "Implemented",
          "Evidence status": "Partial",
          "Operating effectiveness": "Partially effective",
          "Evidence reference": "IAP-2026",
          "SoA linkage": "SOA-A.8.34",
          "Risk linkage": "REQT-9.2",
          "Open actions": "Add audit test authorization sample",
          "Last review date": "2026-08-25",
          "Next review date": "2026-11-25",
          "Notes": "Audit testing controlled."
        }
      ],
      "contentType": "register_table"
    },
    {
      "id": "coverage_decision",
      "title": "Coverage decision",
      "values": {
        "Annex A coverage": "Complete",
        "Required controls": 93,
        "Current controls": 93,
        "Missing controls": 0,
        "Reviewed by": "ISMS Manager",
        "Decision date": "2026-08-29",
        "Evidence reference": "ISOCTRL-COMPLETE-2026-Q3"
      },
      "rows": [
        {
          "Field": "Annex A coverage",
          "Value": "Complete"
        },
        {
          "Field": "Required controls",
          "Value": "93"
        },
        {
          "Field": "Current controls",
          "Value": "93"
        },
        {
          "Field": "Missing controls",
          "Value": "0"
        },
        {
          "Field": "Reviewed by",
          "Value": "ISMS Manager"
        },
        {
          "Field": "Decision date",
          "Value": "2026-08-29"
        },
        {
          "Field": "Evidence reference",
          "Value": "ISOCTRL-COMPLETE-2026-Q3"
        }
      ],
      "contentType": "decision_table"
    },
    {
      "id": "control_register",
      "title": "Control register",
      "rows": [
        {
          "Control ID": "A.5.1",
          "Control name": "Policies for information security",
          "Theme": "Organizational",
          "Control owner": "ISMS Manager",
          "Implementation status": "Implemented",
          "Evidence status": "Complete",
          "Evidence reference": "ISP-001",
          "SoA linkage": "SOA-A.5.1",
          "Next review": "2026-11-29"
        },
        {
          "Control ID": "A.5.2",
          "Control name": "Information security roles and responsibilities",
          "Theme": "Organizational",
          "Control owner": "ISMS Manager",
          "Implementation status": "Implemented",
          "Evidence status": "Complete",
          "Evidence reference": "RACI-2026-Q3",
          "SoA linkage": "SOA-A.5.2",
          "Next review": "2026-11-29"
        },
        {
          "Control ID": "A.5.3",
          "Control name": "Segregation of duties",
          "Theme": "Organizational",
          "Control owner": "IT Operations",
          "Implementation status": "In progress",
          "Evidence status": "Partial",
          "Evidence reference": "SOD-CHK-2026-Q3",
          "SoA linkage": "SOA-A.5.3",
          "Next review": "2026-10-29"
        },
        {
          "Control ID": "A.5.4",
          "Control name": "Management responsibilities",
          "Theme": "Organizational",
          "Control owner": "Top Management",
          "Implementation status": "Implemented",
          "Evidence status": "Complete",
          "Evidence reference": "MR-2026-Q3",
          "SoA linkage": "SOA-A.5.4",
          "Next review": "2026-11-29"
        },
        {
          "Control ID": "A.5.5",
          "Control name": "Contact with authorities",
          "Theme": "Organizational",
          "Control owner": "Compliance Manager",
          "Implementation status": "Implemented",
          "Evidence status": "Partial",
          "Evidence reference": "COMM-P-2026",
          "SoA linkage": "SOA-A.5.5",
          "Next review": "2026-11-20"
        },
        {
          "Control ID": "A.5.6",
          "Control name": "Contact with special interest groups",
          "Theme": "Organizational",
          "Control owner": "Security Lead",
          "Implementation status": "Implemented",
          "Evidence status": "Partial",
          "Evidence reference": "TI-SUB-2026",
          "SoA linkage": "SOA-A.5.6",
          "Next review": "2026-11-20"
        },
        {
          "Control ID": "A.5.7",
          "Control name": "Threat intelligence",
          "Theme": "Organizational",
          "Control owner": "Security Lead",
          "Implementation status": "In progress",
          "Evidence status": "Partial",
          "Evidence reference": "TI-LOG-2026-Q3",
          "SoA linkage": "SOA-A.5.7",
          "Next review": "2026-10-31"
        },
        {
          "Control ID": "A.5.8",
          "Control name": "Information security in project management",
          "Theme": "Organizational",
          "Control owner": "Project Manager",
          "Implementation status": "Implemented",
          "Evidence status": "Partial",
          "Evidence reference": "SSDLC-REL-2026-014",
          "SoA linkage": "SOA-A.5.8",
          "Next review": "2026-11-27"
        },
        {
          "Control ID": "A.5.9",
          "Control name": "Inventory of information and other associated assets",
          "Theme": "Organizational",
          "Control owner": "Asset Manager",
          "Implementation status": "Implemented",
          "Evidence status": "Complete",
          "Evidence reference": "AI-REG-001",
          "SoA linkage": "SOA-A.5.9",
          "Next review": "2026-11-29"
        },
        {
          "Control ID": "A.5.10",
          "Control name": "Acceptable use of information and other associated assets",
          "Theme": "Organizational",
          "Control owner": "HR Manager",
          "Implementation status": "Implemented",
          "Evidence status": "Complete",
          "Evidence reference": "AUP-ACK-2026-Q3",
          "SoA linkage": "SOA-A.5.10",
          "Next review": "2026-11-20"
        },
        {
          "Control ID": "A.5.11",
          "Control name": "Return of assets",
          "Theme": "Organizational",
          "Control owner": "HR Manager",
          "Implementation status": "Implemented",
          "Evidence status": "Complete",
          "Evidence reference": "OFC-2026-018",
          "SoA linkage": "SOA-A.5.11",
          "Next review": "2026-11-20"
        },
        {
          "Control ID": "A.5.12",
          "Control name": "Classification of information",
          "Theme": "Organizational",
          "Control owner": "ISMS Manager",
          "Implementation status": "Implemented",
          "Evidence status": "Complete",
          "Evidence reference": "CLASS-STD-2026",
          "SoA linkage": "SOA-A.5.12",
          "Next review": "2026-11-29"
        },
        {
          "Control ID": "A.5.13",
          "Control name": "Labelling of information",
          "Theme": "Organizational",
          "Control owner": "Document Owner",
          "Implementation status": "Implemented",
          "Evidence status": "Partial",
          "Evidence reference": "DR-2026-Q3",
          "SoA linkage": "SOA-A.5.13",
          "Next review": "2026-11-28"
        },
        {
          "Control ID": "A.5.14",
          "Control name": "Information transfer",
          "Theme": "Organizational",
          "Control owner": "IT Operations",
          "Implementation status": "Implemented",
          "Evidence status": "Partial",
          "Evidence reference": "ITR-2026-Q3",
          "SoA linkage": "SOA-A.5.14",
          "Next review": "2026-11-29"
        },
        {
          "Control ID": "A.5.15",
          "Control name": "Access control",
          "Theme": "Organizational",
          "Control owner": "IT Operations",
          "Implementation status": "Implemented",
          "Evidence status": "Partial",
          "Evidence reference": "ACM-APP-CRM-001",
          "SoA linkage": "SOA-A.5.15",
          "Next review": "2026-10-29",
          "Notes": "Re-sampled after IL-005; less robust than the Stage 2 sample; evidence Partial."
        },
        {
          "Control ID": "A.5.16",
          "Control name": "Identity management",
          "Theme": "Organizational",
          "Control owner": "IT Operations",
          "Implementation status": "Implemented",
          "Evidence status": "Partial",
          "Evidence reference": "IAM-CTRL-2026-Q3",
          "SoA linkage": "SOA-A.5.16",
          "Next review": "2026-10-29"
        },
        {
          "Control ID": "A.5.17",
          "Control name": "Authentication information",
          "Theme": "Organizational",
          "Control owner": "IT Operations",
          "Implementation status": "Implemented",
          "Evidence status": "Partial",
          "Evidence reference": "IAM-CTRL-2026-Q3",
          "SoA linkage": "SOA-A.5.17",
          "Next review": "2026-09-30"
        },
        {
          "Control ID": "A.5.18",
          "Control name": "Access rights",
          "Theme": "Organizational",
          "Control owner": "IT Operations",
          "Implementation status": "Implemented",
          "Evidence status": "Partial",
          "Evidence reference": "ARR-2026-Q3",
          "SoA linkage": "SOA-A.5.18",
          "Next review": "2026-10-29"
        },
        {
          "Control ID": "A.5.19",
          "Control name": "Information security in supplier relationships",
          "Theme": "Organizational",
          "Control owner": "Supplier Manager",
          "Implementation status": "In progress",
          "Evidence status": "Partial",
          "Evidence reference": "SINV-CLOUDHOST-2026-Q3",
          "SoA linkage": "SOA-A.5.19",
          "Next review": "2026-10-15"
        },
        {
          "Control ID": "A.5.20",
          "Control name": "Addressing information security within supplier agreements",
          "Theme": "Organizational",
          "Control owner": "Supplier Manager",
          "Implementation status": "In progress",
          "Evidence status": "Partial",
          "Evidence reference": "CSS-2026-001",
          "SoA linkage": "SOA-A.5.20",
          "Next review": "2026-10-15"
        },
        {
          "Control ID": "A.5.21",
          "Control name": "Managing information security in the ICT supply chain",
          "Theme": "Organizational",
          "Control owner": "Supplier Manager",
          "Implementation status": "Planned",
          "Evidence status": "Partial",
          "Evidence reference": "SINV-2026-Q3",
          "SoA linkage": "SOA-A.5.21",
          "Next review": "2026-11-29",
          "Notes": "STALL-2026-Q3: still Planned from the 2025 improvement programme."
        },
        {
          "Control ID": "A.5.22",
          "Control name": "Monitoring, review and change management of supplier services",
          "Theme": "Organizational",
          "Control owner": "Supplier Manager",
          "Implementation status": "In progress",
          "Evidence status": "Partial",
          "Evidence reference": "SINV-CLOUDHOST-2026-Q3",
          "SoA linkage": "SOA-A.5.22",
          "Next review": "2026-11-29"
        },
        {
          "Control ID": "A.5.23",
          "Control name": "Information security for use of cloud services",
          "Theme": "Organizational",
          "Control owner": "Cloud Service Owner",
          "Implementation status": "In progress",
          "Evidence status": "Partial",
          "Evidence reference": "CLOUD-CTRL-2026-Q3",
          "SoA linkage": "SOA-A.5.23",
          "Next review": "2026-10-15"
        },
        {
          "Control ID": "A.5.24",
          "Control name": "Information security incident management planning and preparation",
          "Theme": "Organizational",
          "Control owner": "Incident Manager",
          "Implementation status": "Implemented",
          "Evidence status": "Complete",
          "Evidence reference": "IRP-2026",
          "SoA linkage": "SOA-A.5.24",
          "Next review": "2026-11-25"
        },
        {
          "Control ID": "A.5.25",
          "Control name": "Assessment and decision on information security events",
          "Theme": "Organizational",
          "Control owner": "Incident Manager",
          "Implementation status": "Implemented",
          "Evidence status": "Partial",
          "Evidence reference": "SIR-2026-Q3",
          "SoA linkage": "SOA-A.5.25",
          "Next review": "2026-11-25"
        },
        {
          "Control ID": "A.5.26",
          "Control name": "Response to information security incidents",
          "Theme": "Organizational",
          "Control owner": "Incident Manager",
          "Implementation status": "Implemented",
          "Evidence status": "Partial",
          "Evidence reference": "IR-RB-2026",
          "SoA linkage": "SOA-A.5.26",
          "Next review": "2026-11-25"
        },
        {
          "Control ID": "A.5.27",
          "Control name": "Learning from information security incidents",
          "Theme": "Organizational",
          "Control owner": "Incident Manager",
          "Implementation status": "Planned",
          "Evidence status": "Partial",
          "Evidence reference": "CIL-2026-Q3",
          "SoA linkage": "SOA-A.5.27",
          "Next review": "2026-11-25",
          "Notes": "STALL-2026-Q3: still Planned from the 2025 improvement programme."
        },
        {
          "Control ID": "A.5.28",
          "Control name": "Collection of evidence",
          "Theme": "Organizational",
          "Control owner": "ISMS Manager",
          "Implementation status": "Implemented",
          "Evidence status": "Complete",
          "Evidence reference": "ELAI-2026-Q3",
          "SoA linkage": "SOA-A.5.28",
          "Next review": "2026-11-28"
        },
        {
          "Control ID": "A.5.29",
          "Control name": "Information security during disruption",
          "Theme": "Organizational",
          "Control owner": "Business Continuity Manager",
          "Implementation status": "Implemented",
          "Evidence status": "Partial",
          "Evidence reference": "BCP-CUSTPORTAL-2026",
          "SoA linkage": "SOA-A.5.29",
          "Next review": "2026-11-29"
        },
        {
          "Control ID": "A.5.30",
          "Control name": "ICT readiness for business continuity",
          "Theme": "Organizational",
          "Control owner": "IT Operations",
          "Implementation status": "In progress",
          "Evidence status": "Partial",
          "Evidence reference": "DRP-CUSTPORTAL-001",
          "SoA linkage": "SOA-A.5.30",
          "Next review": "2026-10-31"
        },
        {
          "Control ID": "A.5.31",
          "Control name": "Legal, statutory, regulatory and contractual requirements",
          "Theme": "Organizational",
          "Control owner": "Compliance Manager",
          "Implementation status": "Implemented",
          "Evidence status": "Partial",
          "Evidence reference": "LRR-2026-Q3",
          "SoA linkage": "SOA-A.5.31",
          "Next review": "2026-11-20"
        },
        {
          "Control ID": "A.5.32",
          "Control name": "Intellectual property rights",
          "Theme": "Organizational",
          "Control owner": "Legal Counsel",
          "Implementation status": "Planned",
          "Evidence status": "Partial",
          "Evidence reference": "IPR-2026-Q3",
          "SoA linkage": "SOA-A.5.32",
          "Next review": "2026-11-27",
          "Notes": "STALL-2026-Q3: still Planned from the 2025 improvement programme."
        },
        {
          "Control ID": "A.5.33",
          "Control name": "Protection of records",
          "Theme": "Organizational",
          "Control owner": "Document Owner",
          "Implementation status": "Implemented",
          "Evidence status": "Complete",
          "Evidence reference": "RRS-2026-Q3",
          "SoA linkage": "SOA-A.5.33",
          "Next review": "2026-11-28"
        },
        {
          "Control ID": "A.5.34",
          "Control name": "Privacy and protection of PII",
          "Theme": "Organizational",
          "Control owner": "Privacy Lead",
          "Implementation status": "Implemented",
          "Evidence status": "Partial",
          "Evidence reference": "DPAR-2026-Q3",
          "SoA linkage": "SOA-A.5.34",
          "Next review": "2026-11-20"
        },
        {
          "Control ID": "A.5.35",
          "Control name": "Independent review of information security",
          "Theme": "Organizational",
          "Control owner": "Internal Auditor",
          "Implementation status": "Implemented",
          "Evidence status": "Complete",
          "Evidence reference": "IAP-2026",
          "SoA linkage": "SOA-A.5.35",
          "Next review": "2026-11-25"
        },
        {
          "Control ID": "A.5.36",
          "Control name": "Compliance with policies, rules and standards for information security",
          "Theme": "Organizational",
          "Control owner": "ISMS Manager",
          "Implementation status": "Implemented",
          "Evidence status": "Partial",
          "Evidence reference": "REQT-2026-Q3",
          "SoA linkage": "SOA-A.5.36",
          "Next review": "2026-11-29"
        },
        {
          "Control ID": "A.5.37",
          "Control name": "Documented operating procedures",
          "Theme": "Organizational",
          "Control owner": "Process Owner",
          "Implementation status": "In progress",
          "Evidence status": "Partial",
          "Evidence reference": "DOP-2026",
          "SoA linkage": "SOA-A.5.37",
          "Next review": "2026-11-29",
          "Notes": "Re-sampled after IL-005; less robust than the Stage 2 sample; evidence Partial."
        },
        {
          "Control ID": "A.6.1",
          "Control name": "Screening",
          "Theme": "People",
          "Control owner": "HR Manager",
          "Implementation status": "Implemented",
          "Evidence status": "Partial",
          "Evidence reference": "HR-ONB-2026-023",
          "SoA linkage": "SOA-A.6.1",
          "Next review": "2026-11-20"
        },
        {
          "Control ID": "A.6.2",
          "Control name": "Terms and conditions of employment",
          "Theme": "People",
          "Control owner": "HR Manager",
          "Implementation status": "Implemented",
          "Evidence status": "Complete",
          "Evidence reference": "HR-ONB-2026-023",
          "SoA linkage": "SOA-A.6.2",
          "Next review": "2026-11-20"
        },
        {
          "Control ID": "A.6.3",
          "Control name": "Information security awareness, education and training",
          "Theme": "People",
          "Control owner": "HR Manager",
          "Implementation status": "Implemented",
          "Evidence status": "Complete",
          "Evidence reference": "TRAIN-REC-2026-188",
          "SoA linkage": "SOA-A.6.3",
          "Next review": "2026-11-20"
        },
        {
          "Control ID": "A.6.4",
          "Control name": "Disciplinary process",
          "Theme": "People",
          "Control owner": "HR Manager",
          "Implementation status": "Planned",
          "Evidence status": "Partial",
          "Evidence reference": "HRP-2026",
          "SoA linkage": "SOA-A.6.4",
          "Next review": "2026-11-20",
          "Notes": "STALL-2026-Q3: still Planned from the 2025 improvement programme."
        },
        {
          "Control ID": "A.6.5",
          "Control name": "Responsibilities after termination or change of employment",
          "Theme": "People",
          "Control owner": "HR Manager",
          "Implementation status": "Implemented",
          "Evidence status": "Complete",
          "Evidence reference": "OFC-2026-018",
          "SoA linkage": "SOA-A.6.5",
          "Next review": "2026-11-20"
        },
        {
          "Control ID": "A.6.6",
          "Control name": "Confidentiality or non-disclosure agreements",
          "Theme": "People",
          "Control owner": "Legal Counsel",
          "Implementation status": "Implemented",
          "Evidence status": "Partial",
          "Evidence reference": "NDA-REG-2026",
          "SoA linkage": "SOA-A.6.6",
          "Next review": "2026-11-20"
        },
        {
          "Control ID": "A.6.7",
          "Control name": "Remote working",
          "Theme": "People",
          "Control owner": "IT Operations",
          "Implementation status": "Implemented",
          "Evidence status": "Partial",
          "Evidence reference": "REMOTE-2026",
          "SoA linkage": "SOA-A.6.7",
          "Next review": "2026-11-29"
        },
        {
          "Control ID": "A.6.8",
          "Control name": "Information security event reporting",
          "Theme": "People",
          "Control owner": "Incident Manager",
          "Implementation status": "Implemented",
          "Evidence status": "Partial",
          "Evidence reference": "IRP-2026",
          "SoA linkage": "SOA-A.6.8",
          "Next review": "2026-11-25"
        },
        {
          "Control ID": "A.7.1",
          "Control name": "Physical security perimeters",
          "Theme": "Physical",
          "Control owner": "Facilities Manager",
          "Implementation status": "Implemented",
          "Evidence status": "Partial",
          "Evidence reference": "PHY-SEC-2026",
          "SoA linkage": "SOA-A.7.1",
          "Next review": "2026-11-22"
        },
        {
          "Control ID": "A.7.2",
          "Control name": "Physical entry",
          "Theme": "Physical",
          "Control owner": "Facilities Manager",
          "Implementation status": "Implemented",
          "Evidence status": "Partial",
          "Evidence reference": "PHY-ACCESS-2026",
          "SoA linkage": "SOA-A.7.2",
          "Next review": "2026-11-22"
        },
        {
          "Control ID": "A.7.3",
          "Control name": "Securing offices, rooms and facilities",
          "Theme": "Physical",
          "Control owner": "Facilities Manager",
          "Implementation status": "Implemented",
          "Evidence status": "Partial",
          "Evidence reference": "PHY-OFFICE-2026",
          "SoA linkage": "SOA-A.7.3",
          "Next review": "2026-11-22"
        },
        {
          "Control ID": "A.7.4",
          "Control name": "Physical security monitoring",
          "Theme": "Physical",
          "Control owner": "Facilities Manager",
          "Implementation status": "In progress",
          "Evidence status": "Partial",
          "Evidence reference": "PHY-MON-2026-Q3",
          "SoA linkage": "SOA-A.7.4",
          "Next review": "2026-10-15"
        },
        {
          "Control ID": "A.7.5",
          "Control name": "Protecting against physical and environmental threats",
          "Theme": "Physical",
          "Control owner": "Facilities Manager",
          "Implementation status": "Planned",
          "Evidence status": "Partial",
          "Evidence reference": "BCP-2026",
          "SoA linkage": "SOA-A.7.5",
          "Next review": "2026-11-22",
          "Notes": "STALL-2026-Q3: still Planned from the 2025 improvement programme."
        },
        {
          "Control ID": "A.7.6",
          "Control name": "Working in secure areas",
          "Theme": "Physical",
          "Control owner": "Facilities Manager",
          "Implementation status": "Not applicable",
          "Evidence status": "Not applicable",
          "Evidence reference": "SOA-A.7.6",
          "SoA linkage": "SOA-A.7.6",
          "Next review": "2026-11-22",
          "Notes": "Excluded because the ISMS scope has no dedicated secure area, laboratory, datacenter, or restricted physical processing room operated by Arcfield.",
          "Applicability justification": "Excluded because the ISMS scope has no dedicated secure area, laboratory, datacenter, or restricted physical processing room operated by Arcfield."
        },
        {
          "Control ID": "A.7.7",
          "Control name": "Clear desk and clear screen",
          "Theme": "Physical",
          "Control owner": "HR Manager",
          "Implementation status": "Implemented",
          "Evidence status": "Partial",
          "Evidence reference": "AUP-ACK-2026-Q3",
          "SoA linkage": "SOA-A.7.7",
          "Next review": "2026-11-20"
        },
        {
          "Control ID": "A.7.8",
          "Control name": "Equipment siting and protection",
          "Theme": "Physical",
          "Control owner": "IT Operations",
          "Implementation status": "Implemented",
          "Evidence status": "Partial",
          "Evidence reference": "AI-AST-006",
          "SoA linkage": "SOA-A.7.8",
          "Next review": "2026-11-20"
        },
        {
          "Control ID": "A.7.9",
          "Control name": "Security of assets off-premises",
          "Theme": "Physical",
          "Control owner": "IT Operations",
          "Implementation status": "Implemented",
          "Evidence status": "Partial",
          "Evidence reference": "MDM-2026-Q3",
          "SoA linkage": "SOA-A.7.9",
          "Next review": "2026-11-20"
        },
        {
          "Control ID": "A.7.10",
          "Control name": "Storage media",
          "Theme": "Physical",
          "Control owner": "IT Operations",
          "Implementation status": "Implemented",
          "Evidence status": "Partial",
          "Evidence reference": "MDM-2026-Q3",
          "SoA linkage": "SOA-A.7.10",
          "Next review": "2026-11-20"
        },
        {
          "Control ID": "A.7.11",
          "Control name": "Supporting utilities",
          "Theme": "Physical",
          "Control owner": "Facilities Manager",
          "Implementation status": "Not applicable",
          "Evidence status": "Not applicable",
          "Evidence reference": "SINV-CLOUDHOST-2026-Q3",
          "SoA linkage": "SOA-A.7.11",
          "Next review": "2026-11-29",
          "Notes": "Excluded because Arcfield does not operate datacenter or server-room utilities in the ISMS scope; production processing relies on cloud-provider facilities covered by supplier assurance.",
          "Applicability justification": "Excluded because Arcfield does not operate datacenter or server-room utilities in the ISMS scope; production processing relies on cloud-provider facilities covered by supplier assurance."
        },
        {
          "Control ID": "A.7.12",
          "Control name": "Cabling security",
          "Theme": "Physical",
          "Control owner": "Facilities Manager",
          "Implementation status": "Not applicable",
          "Evidence status": "Not applicable",
          "Evidence reference": "SOA-A.7.12",
          "SoA linkage": "SOA-A.7.12",
          "Next review": "2026-11-22",
          "Notes": "Excluded because Arcfield does not operate managed cabling infrastructure for in-scope production systems; office network cabling is not used for hosting customer services.",
          "Applicability justification": "Excluded because Arcfield does not operate managed cabling infrastructure for in-scope production systems; office network cabling is not used for hosting customer services."
        },
        {
          "Control ID": "A.7.13",
          "Control name": "Equipment maintenance",
          "Theme": "Physical",
          "Control owner": "IT Operations",
          "Implementation status": "Implemented",
          "Evidence status": "Partial",
          "Evidence reference": "MDM-2026-Q3",
          "SoA linkage": "SOA-A.7.13",
          "Next review": "2026-11-20"
        },
        {
          "Control ID": "A.7.14",
          "Control name": "Secure disposal or re-use of equipment",
          "Theme": "Physical",
          "Control owner": "IT Operations",
          "Implementation status": "Implemented",
          "Evidence status": "Partial",
          "Evidence reference": "OFC-2026-018",
          "SoA linkage": "SOA-A.7.14",
          "Next review": "2026-11-20"
        },
        {
          "Control ID": "A.8.1",
          "Control name": "User endpoint devices",
          "Theme": "Technological",
          "Control owner": "IT Operations",
          "Implementation status": "Implemented",
          "Evidence status": "Partial",
          "Evidence reference": "MDM-2026-Q3",
          "SoA linkage": "SOA-A.8.1",
          "Next review": "2026-11-20"
        },
        {
          "Control ID": "A.8.2",
          "Control name": "Privileged access rights",
          "Theme": "Technological",
          "Control owner": "IT Operations",
          "Implementation status": "In progress",
          "Evidence status": "Partial",
          "Evidence reference": "ACC-REV-2026-Q3",
          "SoA linkage": "SOA-A.8.2",
          "Next review": "2026-09-30"
        },
        {
          "Control ID": "A.8.3",
          "Control name": "Information access restriction",
          "Theme": "Technological",
          "Control owner": "IT Operations",
          "Implementation status": "Implemented",
          "Evidence status": "Partial",
          "Evidence reference": "ACM-APP-CRM-001",
          "SoA linkage": "SOA-A.8.3",
          "Next review": "2026-10-29"
        },
        {
          "Control ID": "A.8.4",
          "Control name": "Access to source code",
          "Theme": "Technological",
          "Control owner": "Engineering Lead",
          "Implementation status": "Implemented",
          "Evidence status": "Partial",
          "Evidence reference": "SI-REPO-2026-014",
          "SoA linkage": "SOA-A.8.4",
          "Next review": "2026-11-27"
        },
        {
          "Control ID": "A.8.5",
          "Control name": "Secure authentication",
          "Theme": "Technological",
          "Control owner": "IT Operations",
          "Implementation status": "Implemented",
          "Evidence status": "Complete",
          "Evidence reference": "IAM-CTRL-2026-Q3",
          "SoA linkage": "SOA-A.8.5",
          "Next review": "2026-09-30"
        },
        {
          "Control ID": "A.8.6",
          "Control name": "Capacity management",
          "Theme": "Technological",
          "Control owner": "IT Operations",
          "Implementation status": "Planned",
          "Evidence status": "Partial",
          "Evidence reference": "MON-2026-Q3",
          "SoA linkage": "SOA-A.8.6",
          "Next review": "2026-11-29",
          "Notes": "STALL-2026-Q3: still Planned from the 2025 improvement programme."
        },
        {
          "Control ID": "A.8.7",
          "Control name": "Protection against malware",
          "Theme": "Technological",
          "Control owner": "IT Operations",
          "Implementation status": "Implemented",
          "Evidence status": "Partial",
          "Evidence reference": "EDR-2026-Q3",
          "SoA linkage": "SOA-A.8.7",
          "Next review": "2026-11-20"
        },
        {
          "Control ID": "A.8.8",
          "Control name": "Management of technical vulnerabilities",
          "Theme": "Technological",
          "Control owner": "Security Lead",
          "Implementation status": "In progress",
          "Evidence status": "Partial",
          "Evidence reference": "VULN-2026-Q3",
          "SoA linkage": "SOA-A.8.8",
          "Next review": "2026-10-31"
        },
        {
          "Control ID": "A.8.9",
          "Control name": "Configuration management",
          "Theme": "Technological",
          "Control owner": "IT Operations",
          "Implementation status": "In progress",
          "Evidence status": "Partial",
          "Evidence reference": "CFG-BASE-2026",
          "SoA linkage": "SOA-A.8.9",
          "Next review": "2026-09-30",
          "Notes": "Re-sampled after IL-005; less robust than the Stage 2 sample; evidence Partial."
        },
        {
          "Control ID": "A.8.10",
          "Control name": "Information deletion",
          "Theme": "Technological",
          "Control owner": "Data Owner",
          "Implementation status": "In progress",
          "Evidence status": "Partial",
          "Evidence reference": "RRS-HR-001",
          "SoA linkage": "SOA-A.8.10",
          "Next review": "2026-11-20"
        },
        {
          "Control ID": "A.8.11",
          "Control name": "Data masking",
          "Theme": "Technological",
          "Control owner": "Engineering Lead",
          "Implementation status": "Planned",
          "Evidence status": "Missing",
          "Evidence reference": "TBD-DMASK-2026",
          "SoA linkage": "SOA-A.8.11",
          "Next review": "2026-10-31",
          "Notes": "STALL-2026-Q3: still Planned from the 2025 improvement programme. No operating sample on this freeze (evidence Missing)."
        },
        {
          "Control ID": "A.8.12",
          "Control name": "Data leakage prevention",
          "Theme": "Technological",
          "Control owner": "Security Lead",
          "Implementation status": "Planned",
          "Evidence status": "Partial",
          "Evidence reference": "DLP-PLAN-2026",
          "SoA linkage": "SOA-A.8.12",
          "Next review": "2026-11-29",
          "Notes": "STALL-2026-Q3: still Planned from the 2025 improvement programme."
        },
        {
          "Control ID": "A.8.13",
          "Control name": "Information backup",
          "Theme": "Technological",
          "Control owner": "IT Operations",
          "Implementation status": "Implemented",
          "Evidence status": "Complete",
          "Evidence reference": "BKP-CRM-001",
          "SoA linkage": "SOA-A.8.13",
          "Next review": "2026-11-28"
        },
        {
          "Control ID": "A.8.14",
          "Control name": "Redundancy of information processing facilities",
          "Theme": "Technological",
          "Control owner": "IT Operations",
          "Implementation status": "Implemented",
          "Evidence status": "Partial",
          "Evidence reference": "SINV-CLOUDHOST-2026-Q3",
          "SoA linkage": "SOA-A.8.14",
          "Next review": "2026-10-15"
        },
        {
          "Control ID": "A.8.15",
          "Control name": "Logging",
          "Theme": "Technological",
          "Control owner": "Security Lead",
          "Implementation status": "Implemented",
          "Evidence status": "Partial",
          "Evidence reference": "LOG-2026-Q3",
          "SoA linkage": "SOA-A.8.15",
          "Next review": "2026-11-29"
        },
        {
          "Control ID": "A.8.16",
          "Control name": "Monitoring activities",
          "Theme": "Technological",
          "Control owner": "Security Lead",
          "Implementation status": "In progress",
          "Evidence status": "Partial",
          "Evidence reference": "MON-2026-Q3",
          "SoA linkage": "SOA-A.8.16",
          "Next review": "2026-10-31"
        },
        {
          "Control ID": "A.8.17",
          "Control name": "Clock synchronization",
          "Theme": "Technological",
          "Control owner": "IT Operations",
          "Implementation status": "Implemented",
          "Evidence status": "Partial",
          "Evidence reference": "CFG-BASE-2026",
          "SoA linkage": "SOA-A.8.17",
          "Next review": "2026-11-29"
        },
        {
          "Control ID": "A.8.18",
          "Control name": "Use of privileged utility programs",
          "Theme": "Technological",
          "Control owner": "IT Operations",
          "Implementation status": "In progress",
          "Evidence status": "Partial",
          "Evidence reference": "ACC-REV-2026-Q3",
          "SoA linkage": "SOA-A.8.18",
          "Next review": "2026-09-30"
        },
        {
          "Control ID": "A.8.19",
          "Control name": "Installation of software on operational systems",
          "Theme": "Technological",
          "Control owner": "IT Operations",
          "Implementation status": "Implemented",
          "Evidence status": "Partial",
          "Evidence reference": "CMP-2026-Q3",
          "SoA linkage": "SOA-A.8.19",
          "Next review": "2026-11-27"
        },
        {
          "Control ID": "A.8.20",
          "Control name": "Networks security",
          "Theme": "Technological",
          "Control owner": "IT Operations",
          "Implementation status": "Implemented",
          "Evidence status": "Partial",
          "Evidence reference": "NSP-2026",
          "SoA linkage": "SOA-A.8.20",
          "Next review": "2026-11-29"
        },
        {
          "Control ID": "A.8.21",
          "Control name": "Security of network services",
          "Theme": "Technological",
          "Control owner": "IT Operations",
          "Implementation status": "Implemented",
          "Evidence status": "Partial",
          "Evidence reference": "SINV-CLOUDHOST-2026-Q3",
          "SoA linkage": "SOA-A.8.21",
          "Next review": "2026-10-15"
        },
        {
          "Control ID": "A.8.22",
          "Control name": "Segregation of networks",
          "Theme": "Technological",
          "Control owner": "IT Operations",
          "Implementation status": "In progress",
          "Evidence status": "Partial",
          "Evidence reference": "NET-SEG-2026",
          "SoA linkage": "SOA-A.8.22",
          "Next review": "2026-10-31"
        },
        {
          "Control ID": "A.8.23",
          "Control name": "Web filtering",
          "Theme": "Technological",
          "Control owner": "IT Operations",
          "Implementation status": "Planned",
          "Evidence status": "Missing",
          "Evidence reference": "TBD-WEBFILTER-2026",
          "SoA linkage": "SOA-A.8.23",
          "Next review": "2026-11-20",
          "Notes": "STALL-2026-Q3: still Planned from the 2025 improvement programme. No operating sample on this freeze (evidence Missing)."
        },
        {
          "Control ID": "A.8.24",
          "Control name": "Use of cryptography",
          "Theme": "Technological",
          "Control owner": "Security Lead",
          "Implementation status": "Implemented",
          "Evidence status": "Complete",
          "Evidence reference": "CKMP-2026-Q3",
          "SoA linkage": "SOA-A.8.24",
          "Next review": "2026-11-27"
        },
        {
          "Control ID": "A.8.25",
          "Control name": "Secure development life cycle",
          "Theme": "Technological",
          "Control owner": "Engineering Lead",
          "Implementation status": "Implemented",
          "Evidence status": "Partial",
          "Evidence reference": "SSDLC-REL-2026-014",
          "SoA linkage": "SOA-A.8.25",
          "Next review": "2026-11-27"
        },
        {
          "Control ID": "A.8.26",
          "Control name": "Application security requirements",
          "Theme": "Technological",
          "Control owner": "Product Owner",
          "Implementation status": "In progress",
          "Evidence status": "Partial",
          "Evidence reference": "APPSEC-REQ-2026",
          "SoA linkage": "SOA-A.8.26",
          "Next review": "2026-11-27"
        },
        {
          "Control ID": "A.8.27",
          "Control name": "Secure system architecture and engineering principles",
          "Theme": "Technological",
          "Control owner": "Engineering Lead",
          "Implementation status": "Planned",
          "Evidence status": "Partial",
          "Evidence reference": "ARCH-SEC-2026",
          "SoA linkage": "SOA-A.8.27",
          "Next review": "2026-11-27",
          "Notes": "STALL-2026-Q3: still Planned from the 2025 improvement programme."
        },
        {
          "Control ID": "A.8.28",
          "Control name": "Secure coding",
          "Theme": "Technological",
          "Control owner": "Engineering Lead",
          "Implementation status": "Implemented",
          "Evidence status": "Partial",
          "Evidence reference": "SSDLC-REL-2026-014",
          "SoA linkage": "SOA-A.8.28",
          "Next review": "2026-09-20"
        },
        {
          "Control ID": "A.8.29",
          "Control name": "Security testing in development and acceptance",
          "Theme": "Technological",
          "Control owner": "Engineering Lead",
          "Implementation status": "In progress",
          "Evidence status": "Partial",
          "Evidence reference": "TEST-SEC-2026",
          "SoA linkage": "SOA-A.8.29",
          "Next review": "2026-11-27"
        },
        {
          "Control ID": "A.8.30",
          "Control name": "Outsourced development",
          "Theme": "Technological",
          "Control owner": "Engineering Lead",
          "Implementation status": "Not applicable",
          "Evidence status": "Not applicable",
          "Evidence reference": "SOA-A.8.30",
          "SoA linkage": "SOA-A.8.30",
          "Next review": "2026-11-27",
          "Notes": "Excluded because Arcfield does not outsource software development within the current ISMS scope; all in-scope development is performed by internal engineering staff.",
          "Applicability justification": "Excluded because Arcfield does not outsource software development within the current ISMS scope; all in-scope development is performed by internal engineering staff."
        },
        {
          "Control ID": "A.8.31",
          "Control name": "Separation of development, test and production environments",
          "Theme": "Technological",
          "Control owner": "Engineering Lead",
          "Implementation status": "Implemented",
          "Evidence status": "Partial",
          "Evidence reference": "ENV-SEP-2026",
          "SoA linkage": "SOA-A.8.31",
          "Next review": "2026-11-27"
        },
        {
          "Control ID": "A.8.32",
          "Control name": "Change management",
          "Theme": "Technological",
          "Control owner": "Change Manager",
          "Implementation status": "Implemented",
          "Evidence status": "Partial",
          "Evidence reference": "CMP-2026-Q3",
          "SoA linkage": "SOA-A.8.32",
          "Next review": "2026-11-27",
          "Notes": "Re-sampled after IL-005; less robust than the Stage 2 sample; evidence Partial."
        },
        {
          "Control ID": "A.8.33",
          "Control name": "Test information",
          "Theme": "Technological",
          "Control owner": "Engineering Lead",
          "Implementation status": "Planned",
          "Evidence status": "Missing",
          "Evidence reference": "TBD-TESTDATA-2026",
          "SoA linkage": "SOA-A.8.33",
          "Next review": "2026-10-31",
          "Notes": "STALL-2026-Q3: still Planned from the 2025 improvement programme. No operating sample on this freeze (evidence Missing)."
        },
        {
          "Control ID": "A.8.34",
          "Control name": "Protection of information systems during audit testing",
          "Theme": "Technological",
          "Control owner": "Internal Auditor",
          "Implementation status": "Implemented",
          "Evidence status": "Partial",
          "Evidence reference": "IAP-2026",
          "SoA linkage": "SOA-A.8.34",
          "Next review": "2026-11-25"
        }
      ],
      "text": "This section renders the full Annex A control universe. The generated workbook must keep one row for every control below.",
      "contentType": "section"
    },
    {
      "id": "external_references",
      "title": "References",
      "groups": [
        {
          "text": "Cite these sources from workshops and audits. This list names ISO clauses, book chapters and companion artifacts used by this file."
        },
        {
          "rows": [
            {
              "Kind": "ISO",
              "Reference": "ISO/IEC 27001:2022",
              "How this document uses it": "Normative source this artifact implements or cites.",
              "href": "https://www.iso.org/standard/82875.html"
            },
            {
              "Kind": "Book",
              "Reference": "Building the ISMS, Annex A Controls",
              "How this document uses it": "Primary operating chapter for this companion artifact.",
              "href": "https://www.amazon.com/dp/9789908983448"
            },
            {
              "Kind": "Artifact",
              "Reference": "SOA Statement of Applicability (SoA) (Building the ISMS, Context of the Organization (Clause 4))",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/dp/9789908983448"
            },
            {
              "Kind": "Artifact",
              "Reference": "AI Asset Inventory (Implementation & Certification, Asset Management & Information Classification)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/s?k=ISO+27001+for+Software+Companies+Implementation+and+Certification"
            },
            {
              "Kind": "Artifact",
              "Reference": "REQT ISO 27001 Clauses 4-10 Requirements Tracker (Dual Compliance, ISO 27001 & NIS2)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/dp/9789908983479"
            },
            {
              "Kind": "Artifact",
              "Reference": "SINV Supplier Inventory (Building the ISMS, Supplier Security & Third-party Risk Management)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/dp/9789908983448"
            }
          ]
        }
      ],
      "contentType": "reference_table"
    }
  ],
  "enrichment": {
    "source": "Example.json",
    "method": "curated-json",
    "note": "Completes Example JSON with renderer-native sections and generalized groups; no mdSource helper fields."
  },
  "snapshotRef": {
    "snapshotId": "arcfield.platform.surv.2026-09-11",
    "schemaVersion": "evidenceSnapshot.v1"
  },
  "scenarioRef": {
    "githubIssue": 64,
    "crId": "CR-TYPE-ARCFIELD-001",
    "family": "Coverage",
    "role": "Control coverage of the certified SoA"
  }
}
