{
  "schemaVersion": "artifactExample.v2",
  "artifactId": "ISO",
  "title": "Information Security Objectives",
  "definitionRef": {
    "artifactId": "ISO",
    "definitionSchemaVersion": "artifactDefinition.v2",
    "definitionId": "ISO.artifactDefinition.v2",
    "title": "Information Security Objectives"
  },
  "organization": "Arcfield",
  "sections": [
    {
      "id": "title_page",
      "title": "Title Page",
      "values": {
        "Register Title": "Information Security Objectives",
        "Register ID": "ISO-REG-001",
        "Version": "1.1",
        "Status": "Approved",
        "Organization": "Arcfield",
        "Owner": "ISMS Manager",
        "Approver": "Top Management",
        "Classification": "Internal",
        "Effective Date": "2026-09-11",
        "Next Review Date": "2027-09-11"
      },
      "items": [
        "Register Title: Information Security Objectives",
        "Register ID: ISO-REG-001",
        "Version: 1.1",
        "Status: Approved",
        "Organization: Arcfield",
        "Owner: ISMS Manager",
        "Approver: Top Management",
        "Classification: Internal",
        "Effective Date: 2026-09-11",
        "Next Review Date: 2027-09-11"
      ],
      "contentType": "metadata"
    },
    {
      "id": "abstract",
      "title": "Abstract",
      "text": "This example defines Arcfield measurable information security objectives with policy alignment, metrics, targets, current values, owners, review frequency, status, evidence and management-review input. Rows are the 11 September 2026 operating sample of the certified Arcfield Platform ISMS in the surveillance cycle after certificate ARC-ISMS-2025-001.",
      "contentType": "narrative"
    },
    {
      "id": "document_control",
      "title": "Document Control",
      "rows": [
        {
          "Property": "Purpose",
          "Value": "Define and track measurable information security objectives."
        },
        {
          "Property": "Used by",
          "Value": "Top Management, ISMS Manager, Control Owners, Internal Auditor"
        },
        {
          "Property": "Maintained by",
          "Value": "ISMS Manager"
        },
        {
          "Property": "Evidence role",
          "Value": "Mandatory Clause 6.2 planning and performance evidence"
        },
        {
          "Property": "ISO reference",
          "Value": "ISO/IEC 27001:2022 Clause 6.2, Clause 9.1 and Clause 9.3"
        },
        {
          "Property": "Review cadence",
          "Value": "Monthly operational review and quarterly management review"
        }
      ],
      "contentType": "control_table"
    },
    {
      "id": "instructions",
      "title": "Instructions",
      "items": [
        "Define objectives that are measurable and aligned with the information security policy.",
        "Assign each objective to an accountable owner.",
        "Record metric, target, current value and measurement method.",
        "Link evidence that proves current status.",
        "Review at-risk objectives before management review.",
        "Update objectives after material scope, risk, control or business changes.",
        "Use sheets ending in “Ex” as read-only examples. Enter live data only on the matching “Wk” (Working) sheets.",
        "Every operative list is an Excel Table with frozen headers and filters. Add new rows on the next empty worksheet row beneath the table so Excel expands it — do not leave blank rows inside the table.",
        "Where a column offers a dropdown, choose a value from the list (Status, Owner role, Priority, Severity, Likelihood, Impact, Applicability, Evidence Status, Review Result). Do not invent free-text variants.",
        "Enter dates as YYYY-MM-DD. Date columns are validated and formatted accordingly.",
        "Review the Flag columns (Overdue, Review Due, Missing Owner, Missing Evidence). They calculate automatically and highlight gaps for follow-up.",
        "Keep Cover, Legal, Book, Lists and Metadata unchanged. System sheets are protected on purpose."
      ],
      "contentType": "ordered_list"
    },
    {
      "id": "information_security_objectives",
      "title": "Information security objectives",
      "schemaRef": {
        "definitionId": "ISO.artifactDefinition.v2",
        "sectionId": "information_security_objectives",
        "columnsRef": "sections.information_security_objectives.columns"
      },
      "rows": [
        {
          "Objective ID": "ISO-001",
          "Objective": "Complete mandatory security awareness for the in-scope workforce.",
          "Policy Alignment": "Security responsibilities and awareness",
          "Metric": "Training completion rate",
          "Target": "\\>= 98% completed within 30 days",
          "Current Value": "96%",
          "Measurement Method": "Monthly training report",
          "Owner": "HR Manager",
          "Review Frequency": "Monthly",
          "Due Date": "2026-09-30",
          "Status": "At risk",
          "Evidence Reference": "TR-2026-Q3",
          "Management Review Input": "Two contractor acknowledgements pending.",
          "Notes": "Linked to EXR-005 closure."
        },
        {
          "Objective ID": "ISO-002",
          "Objective": "Review privileged access for critical systems.",
          "Policy Alignment": "Access control and least privilege",
          "Metric": "Monthly privileged access reviews completed",
          "Target": "100% of critical systems reviewed monthly",
          "Current Value": "4 of 5 systems reviewed",
          "Measurement Method": "Access review register",
          "Owner": "IT Operations Manager",
          "Review Frequency": "Monthly",
          "Due Date": "2026-09-05",
          "Status": "In progress",
          "Evidence Reference": "ARR-2026-08",
          "Management Review Input": "Cloud admin exception remains open.",
          "Notes": "Related to EXR-001."
        },
        {
          "Objective ID": "ISO-003",
          "Objective": "Reduce high-risk treatment overdue items.",
          "Policy Alignment": "Risk-based control implementation",
          "Metric": "High-risk treatments overdue",
          "Target": "0 overdue high-risk treatments",
          "Current Value": "1 overdue",
          "Measurement Method": "Risk treatment plan review",
          "Owner": "Compliance Lead",
          "Review Frequency": "Bi-weekly",
          "Due Date": "2026-09-15",
          "Status": "At risk",
          "Evidence Reference": "RTP-2026-Q3",
          "Management Review Input": "Supplier exit clause follow-up needs escalation.",
          "Notes": "Linked to SINV and LRR. STALL-2026-Q3 includes RTP-2026-021 and RTP-2026-033 still Planned."
        },
        {
          "Objective ID": "ISO-004",
          "Objective": "Maintain incident closure discipline.",
          "Policy Alignment": "Incident management and continual improvement",
          "Metric": "Medium/high incidents closed within target",
          "Target": "\\>= 90% within agreed SLA",
          "Current Value": "83%",
          "Measurement Method": "Incident log trend review",
          "Owner": "Incident Manager",
          "Review Frequency": "Monthly",
          "Due Date": "2026-09-29",
          "Status": "In progress",
          "Evidence Reference": "IL-REVIEW-2026-08",
          "Management Review Input": "Supplier incident remains open pending final report.",
          "Notes": "Supports A.5.24-A.5.28. IL-005 contained; SIR-004 still Open; A.5.27 still Planned."
        },
        {
          "Objective ID": "ISO-005",
          "Objective": "Improve audit-pack evidence completeness.",
          "Policy Alignment": "Documented information, evidence and audit readiness",
          "Metric": "Evidence records complete before freeze date",
          "Target": "\\>= 95% complete",
          "Current Value": "91%",
          "Measurement Method": "Evidence log review",
          "Owner": "Internal Auditor",
          "Review Frequency": "Monthly during audit preparation",
          "Due Date": "2026-09-20",
          "Status": "In progress",
          "Evidence Reference": "ELAI-2026-Q3",
          "Management Review Input": "Evidence freeze communication sent.",
          "Notes": "Related to ICL-006."
        },
        {
          "Objective ID": "ISO-006",
          "Objective": "Resolve critical supplier security evidence gaps.",
          "Policy Alignment": "Supplier relationship security",
          "Metric": "Critical suppliers with current assurance evidence",
          "Target": "100% current evidence",
          "Current Value": "5 of 6 suppliers current",
          "Measurement Method": "Supplier inventory review",
          "Owner": "Supplier Manager",
          "Review Frequency": "Quarterly",
          "Due Date": "2026-10-15",
          "Status": "In progress",
          "Evidence Reference": "SINV-CLOUDHOST-2026-Q3",
          "Management Review Input": "CloudHost notification addendum still pending.",
          "Notes": "Linked to EXR-002 and LRR. SIR-004 / CloudHost; A.5.21 remains Planned (STALL-2026-Q3)."
        },
        {
          "Objective ID": "ISO-007",
          "Objective": "Keep Arcfield Platform records labelled to the approved classification levels.",
          "Policy Alignment": "Classification and handling",
          "Metric": "Sampled records with a correct ICP label",
          "Target": ">= 98% of sampled production, support and evidence records",
          "Current Value": "94%",
          "Measurement Method": "Quarterly classification sample against ICP",
          "Owner": "Asset Manager",
          "Review Frequency": "Quarterly",
          "Due Date": "2026-12-11",
          "Status": "In progress",
          "Evidence Reference": "ICP-SAMPLE-2026-Q3",
          "Management Review Input": "Support attachments remain the main miss.",
          "Notes": "Implements ISP minimum rule on classification. Linked to RISK-2026-046."
        },
        {
          "Objective ID": "ISO-008",
          "Objective": "Keep cryptographic keys and certificates inside the approved Arcfield Platform inventory.",
          "Policy Alignment": "Cryptographic protection",
          "Metric": "Production keys and certificates with owner, expiry and rotation evidence",
          "Target": "100% of production TLS, KMS and CI/CD signing keys",
          "Current Value": "97%",
          "Measurement Method": "Monthly CKMP / CP inventory export",
          "Owner": "Security Lead",
          "Review Frequency": "Monthly",
          "Due Date": "2026-10-31",
          "Status": "On track",
          "Evidence Reference": "CKMP-INV-2026-09",
          "Management Review Input": "One staging certificate owner still a team name.",
          "Notes": "Linked to CP and CKMP. Do not copy key material into ISO."
        },
        {
          "Objective ID": "ISO-009",
          "Objective": "Prove Arcfield Platform restore of customer configuration within the published RTO.",
          "Policy Alignment": "Backup, restore and continuity",
          "Metric": "Successful restore tests including tenant configuration",
          "Target": "1 evidenced restore test per quarter within BIA RTO",
          "Current Value": "Infrastructure restore only (Q3)",
          "Measurement Method": "BRP restore report cited from BCP",
          "Owner": "Business Continuity Owner",
          "Review Frequency": "Quarterly",
          "Due Date": "2026-12-11",
          "Status": "At risk",
          "Evidence Reference": "BRP-RESTORE-2026-Q3",
          "Management Review Input": "Tenant-configuration restore is the open treatment for RISK-2026-045.",
          "Notes": "Linked to BCP, BIA and BRP."
        },
        {
          "Objective ID": "ISO-010",
          "Objective": "Close corrective actions from incidents, audits and management review on due date.",
          "Policy Alignment": "Corrective-action closure",
          "Metric": "Corrective actions overdue",
          "Target": "0 overdue high or audit-raised actions",
          "Current Value": "1 overdue",
          "Measurement Method": "CAR / NC-RP ageing report",
          "Owner": "ISMS Manager",
          "Review Frequency": "Bi-weekly",
          "Due Date": "2026-09-30",
          "Status": "At risk",
          "Evidence Reference": "CAR-AGE-2026-09",
          "Management Review Input": "Supplier-exit action from ISO-006 is the overdue item.",
          "Notes": "ISP typical objective area. Linked to MRART outputs. CAR-2026-027 in progress after IL-005; do not close before effectiveness check."
        },
        {
          "Objective ID": "ISO-011",
          "Objective": "Monitor privileged Arcfield Platform paths with complete, reviewable logs.",
          "Policy Alignment": "Logging and monitoring",
          "Metric": "Privileged production paths with retained logs and a named reviewer",
          "Target": "100% of PAM, IdP admin and production-deploy paths",
          "Current Value": "4 of 5 paths evidenced",
          "Measurement Method": "LMP coverage check vs PAP / CSP",
          "Owner": "IT Operations Manager",
          "Review Frequency": "Monthly",
          "Due Date": "2026-10-31",
          "Status": "In progress",
          "Evidence Reference": "LMP-COV-2026-09",
          "Management Review Input": "Cloud-console recording is RISK-2026-044.",
          "Notes": "Linked to LMP and PAP."
        },
        {
          "Objective ID": "ISO-012",
          "Objective": "Release Arcfield Platform production only through the approved secure-development path.",
          "Policy Alignment": "Secure development and change",
          "Metric": "Production releases with review, test and change-ticket evidence",
          "Target": "100% of production releases",
          "Current Value": "96%",
          "Measurement Method": "SSDP release sample vs change records",
          "Owner": "Secure Development Lead",
          "Review Frequency": "Monthly",
          "Due Date": "2026-10-31",
          "Status": "On track",
          "Evidence Reference": "SSDP-REL-2026-09",
          "Management Review Input": "Emergency hotfix path still needs a two-person after-the-fact review.",
          "Notes": "Linked to SSDP and RISK-2026-042."
        }
      ],
      "contentType": "register_table"
    },
    {
      "id": "objective_review_decision",
      "title": "Objective review decision",
      "values": {
        "Review result": "12 objectives reviewed against the ISP policy landscape; 8 on track or in progress and 4 at risk with named follow-up.",
        "Objectives reviewed": 12,
        "Objectives on track": 8,
        "Objectives at risk": 4,
        "Actions opened": "Training reminder and supplier escalation",
        "Reviewed by": "ISMS Manager",
        "Decision date": "2026-09-11",
        "Evidence reference": "ISO-REVIEW-2026-Q3"
      },
      "rows": [
        {
          "Field": "Review result",
          "Value": "12 objectives reviewed against the ISP policy landscape; 8 on track or in progress and 4 at risk with named follow-up."
        },
        {
          "Field": "Objectives reviewed",
          "Value": "12"
        },
        {
          "Field": "Objectives on track",
          "Value": "8"
        },
        {
          "Field": "Objectives at risk",
          "Value": "4"
        },
        {
          "Field": "Actions opened",
          "Value": "Training reminder and supplier escalation"
        },
        {
          "Field": "Reviewed by",
          "Value": "ISMS Manager"
        },
        {
          "Field": "Decision date",
          "Value": "2026-09-11"
        },
        {
          "Field": "Evidence reference",
          "Value": "ISO-REVIEW-2026-Q3"
        }
      ],
      "contentType": "decision_table"
    },
    {
      "id": "external_references",
      "title": "References",
      "groups": [
        {
          "text": "Cite these sources from workshops and audits. This list names ISO clauses, book chapters and companion artifacts used by this file."
        },
        {
          "rows": [
            {
              "Kind": "ISO",
              "Reference": "ISO/IEC 27001:2022 6.2",
              "How this document uses it": "Normative source this artifact implements or cites.",
              "href": "https://www.iso.org/standard/82875.html"
            },
            {
              "Kind": "Book",
              "Reference": "Building the ISMS, Information Security Policies & Risk Management",
              "How this document uses it": "Primary operating chapter for this companion artifact.",
              "href": "https://www.amazon.com/dp/9789908983448"
            },
            {
              "Kind": "Artifact",
              "Reference": "EXR Exceptions Register (Implementation & Certification, Asset Management & Information Classification)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/s?k=ISO+27001+for+Software+Companies+Implementation+and+Certification"
            },
            {
              "Kind": "Artifact",
              "Reference": "LRR Legal, Regulatory and Contractual Requirements Register (Building the ISMS, Legal, Regulatory & Contractual Requirements)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/dp/9789908983448"
            },
            {
              "Kind": "Artifact",
              "Reference": "SINV Supplier Inventory (Building the ISMS, Supplier Security & Third-party Risk Management)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/dp/9789908983448"
            },
            {
              "Kind": "Artifact",
              "Reference": "ARR Access Rights Register (Secure Engineering, Access Control & Identity Management)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/dp/9789908983455"
            }
          ]
        }
      ],
      "contentType": "reference_table"
    }
  ],
  "enrichment": {
    "source": "Example.json",
    "method": "curated-json",
    "note": "Completes Example JSON with renderer-native sections and generalized groups; no mdSource helper fields."
  },
  "snapshotRef": {
    "snapshotId": "arcfield.platform.surv.2026-09-11",
    "schemaVersion": "evidenceSnapshot.v1"
  },
  "scenarioRef": {
    "githubIssue": 64,
    "crId": "CR-TYPE-ARCFIELD-001",
    "family": "Register",
    "role": "Operating sample of the 11 September 2026 freeze"
  }
}
