{
  "schemaVersion": "artifactDefinition.v2",
  "definitionId": "ISP.artifactDefinition.v2",
  "artifactId": "ISP",
  "title": "Information Security Policy",
  "artifactType": "Policy",
  "format": "docx",
  "productTier": "Basic",
  "definitionRole": "contract",
  "sourceModel": {
    "body": "curated Example JSON is the worked Arcfield body; no Artifact Candidate page is in this factory",
    "jsonDefinition": "machine-readable contract and validation model",
    "jsonExample": "curated fictional Arcfield example (EXAMPLE_DECISION, pending review)"
  },
  "editorialStandard": {
    "purpose": "This policy is Top Management's information-security promise for a software company. It must be testable: every supporting policy, register and procedure can be checked against it. It is not the Scope Statement, not the risk methodology and not the SoA.",
    "requiredEditorialElements": [
      "introduction as purpose prose",
      "scope of this policy versus ISS, RAM and SoA",
      "terms as a first-class group",
      "policy statement and Top Management commitment",
      "minimum security rules with exception expiry",
      "responsibilities table with a how-to sentence",
      "practical examples, pitfalls, evidence and external references"
    ],
    "isoAnchors": [
      {
        "label": "ISO/IEC 27001:2022 5.2",
        "href": "https://www.iso.org/standard/82875.html",
        "role": "Establish an information security policy that is appropriate, includes objectives or a framework, includes a commitment to satisfy applicable requirements and to continual improvement, and is available as documented information."
      },
      {
        "label": "ISO/IEC 27001:2022 5.1",
        "href": "https://www.iso.org/standard/82875.html",
        "role": "Leadership commitment, including directing and supporting the ISMS and promoting continual improvement."
      },
      {
        "label": "ISO/IEC 27001:2022 7.5",
        "href": "https://www.iso.org/standard/82875.html",
        "role": "Documented information control: this policy is identified, reviewed and cited by version from related records."
      }
    ],
    "bookSources": [
      {
        "series": "ISO 27001 for Software Companies",
        "volume": 1,
        "volumeTitle": "Building the ISMS",
        "chapterId": "S-02-01-00",
        "chapterTitle": "Information Security Policies & Risk",
        "primary": true,
        "role": "Policy framework and risk-based operation.",
        "href": "https://www.amazon.com/dp/9789908983448"
      },
      {
        "series": "ISO 27001 for Software Companies",
        "volume": 1,
        "volumeTitle": "Building the ISMS",
        "chapterId": "S-00-02-00",
        "chapterTitle": "Leadership & Management (Clause 5)",
        "primary": false,
        "role": "Management commitment and policy approval.",
        "href": "https://www.amazon.com/dp/9789908983448"
      }
    ],
    "acronyms": [
      {
        "abbr": "CIA",
        "longForm": "Confidentiality, Integrity, and Availability"
      },
      {
        "abbr": "ISMS",
        "longForm": "Information Security Management System"
      },
      {
        "abbr": "ISS",
        "longForm": "ISMS Scope Statement"
      },
      {
        "abbr": "MFA",
        "longForm": "Multi-Factor Authentication"
      },
      {
        "abbr": "RAM",
        "longForm": "Risk Assessment Methodology"
      },
      {
        "abbr": "SoA",
        "longForm": "Statement of Applicability"
      },
      {
        "abbr": "AI",
        "longForm": "Artificial Intelligence"
      },
      {
        "abbr": "API",
        "longForm": "Application Programming Interface"
      },
      {
        "abbr": "CD",
        "longForm": "Continuous Delivery"
      },
      {
        "abbr": "CI",
        "longForm": "Continuous Integration"
      },
      {
        "abbr": "CR",
        "longForm": "Change Request"
      },
      {
        "abbr": "DR",
        "longForm": "Disaster Recovery"
      },
      {
        "abbr": "EP",
        "longForm": "Evidence Pack"
      },
      {
        "abbr": "EV",
        "longForm": "Extended Validation"
      },
      {
        "abbr": "HR",
        "longForm": "Human Resources"
      },
      {
        "abbr": "ISP",
        "longForm": "Information Security Policy"
      },
      {
        "abbr": "JSON",
        "longForm": "JavaScript Object Notation"
      },
      {
        "abbr": "RACI",
        "longForm": "Responsible, Accountable, Consulted, and Informed"
      },
      {
        "abbr": "SSO",
        "longForm": "Single Sign-On"
      },
      {
        "abbr": "MRMT",
        "longForm": "Management Review Minutes Template"
      }
    ],
    "must": [
      "State a binding policy commitment to CIA through a risk-based ISMS aligned with ISO/IEC 27001:2022.",
      "Name Top Management commitment, scope applicability, minimum security rules, exception expiry and acknowledgement.",
      "State the golden thread: this policy → ISS, RAM, RR, SoA and topic policies. This file does not duplicate those records."
    ],
    "mustNot": [
      "Do not select or exclude Annex A controls in this policy. That is the SoA.",
      "Do not copy the risk methodology into this policy. Cite RAM by Document Control version.",
      "Do not replace this artifact's function with a shared family skeleton (operating_rules, systems_and_records)."
    ],
    "softwareCompanyAdaptations": [
      "Include SaaS production, customer data, CI/CD, privileged access and supplier interfaces in the minimum rules.",
      "Use Arcfield as the worked example (cover variant A)."
    ],
    "exampleBody": {
      "sectionId": "policy_content",
      "workedExampleOrg": "Arcfield",
      "minBodyWords": 400,
      "requiredGroups": [
        {
          "id": "introduction",
          "heading": "What this policy is",
          "mustInclude": [
            "top-level promise",
            "not ISS, RAM or SoA",
            "cite Document Control version"
          ]
        },
        {
          "id": "scope",
          "heading": "Scope",
          "mustInclude": [
            "ISS",
            "SoA",
            "how-to"
          ]
        },
        {
          "id": "terms",
          "heading": "Terms used here",
          "mustInclude": [
            "ISMS",
            "exception"
          ]
        },
        {
          "id": "policy_statement",
          "heading": "Policy statement",
          "mustInclude": [
            "CIA",
            "ISO/IEC 27001:2022"
          ]
        },
        {
          "id": "management_commitment",
          "heading": "Management commitment",
          "mustInclude": [
            "Top Management",
            "resources"
          ]
        },
        {
          "id": "minimum_security_rules",
          "heading": "Minimum security rules",
          "mustInclude": [
            "MFA or least privilege",
            "incident reporting",
            "exceptions with expiry",
            "ISP-MIN-001",
            "ISP-MIN-002",
            "ISP-MIN-003",
            "ISP-MIN-004"
          ]
        },
        {
          "id": "evidence",
          "heading": "Evidence expectations",
          "mustInclude": [
            "ISP-EV-001",
            "expectation"
          ]
        }
      ],
      "requiredSections": [
        {
          "id": "change_log",
          "title": "Revision history",
          "role": "Versioned freeze log with how-to sentence and rows Version, Date, Change, Approved by. Last Version matches title_page.values.Version."
        },
        {
          "id": "external_references",
          "title": "References",
          "role": "ISO clauses, book chapters and companion artifacts. Not a series catalogue."
        }
      ]
    }
  },
  "sections": [
    {
      "order": 1,
      "id": "title_page",
      "title": "Title Page",
      "contentType": "metadata",
      "required": true,
      "hint": null
    },
    {
      "order": 2,
      "id": "abstract",
      "title": "Abstract",
      "contentType": "narrative",
      "required": true,
      "hint": {
        "text": "Use the policy as the top-level promise: it should be clear enough that every supporting policy can be tested against it.",
        "bookReference": "Volume 1, S-02-01-00 Information Security Policies & Risk"
      }
    },
    {
      "order": 3,
      "id": "document_control",
      "title": "Document Control",
      "contentType": "control_table",
      "required": true,
      "hint": null
    },
    {
      "order": 4,
      "id": "change_log",
      "title": "Revision history",
      "contentType": "revision_table",
      "required": true
    },
    {
      "order": 5,
      "id": "instructions",
      "title": "Instructions",
      "contentType": "ordered_list",
      "required": true,
      "hint": {
        "text": "Adapt examples, owners and evidence IDs; do not remove the practical examples because they explain how the policy is used.",
        "bookReference": "Volume 1, S-02-01-00 Information Security Policies & Risk"
      }
    },
    {
      "order": 6,
      "id": "policy_content",
      "title": "Policy",
      "contentType": "policy_sections",
      "required": true,
      "requiredElements": [
        "policy statement",
        "management commitment",
        "scope and applicability",
        "measurable security objectives",
        "minimum security rules",
        "responsibilities",
        "compliance",
        "policy framework",
        "risk-based operation",
        "communication and acknowledgement",
        "exceptions and nonconformities"
      ],
      "hint": {
        "text": "Write policy content as practical operating rules, not generic intent statements.",
        "bookReference": "Volume 1, S-02-01-00 Information Security Policies & Risk"
      }
    },
    {
      "order": 7,
      "id": "supporting_policy_framework",
      "title": "Supporting policy framework",
      "contentType": "framework_table",
      "required": true,
      "columns": [
        {
          "name": "Supporting policy / process",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Purpose",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Owner",
          "type": "select",
          "required": "yes",
          "valueSet": "domain.owner",
          "options": [
            "ISMS Manager",
            "Control Owner",
            "Risk Owner",
            "Process Owner",
            "Asset Owner",
            "IT Security",
            "HR",
            "Legal",
            "Executive Management",
            "Internal Audit"
          ],
          "validation": {
            "allowBlank": false,
            "errorTitle": "Invalid value",
            "error": "Select a value from the list."
          }
        },
        {
          "name": "Typical evidence",
          "type": "text",
          "required": "yes"
        }
      ],
      "hint": {
        "text": "The framework table should show how the top-level policy is implemented through operational policies and records.",
        "bookReference": "Volume 1, S-02-01-00 Information Security Policies & Risk"
      }
    },
    {
      "order": 8,
      "id": "exception_approval_matrix",
      "title": "Exception approval matrix",
      "contentType": "approval_matrix",
      "required": true,
      "columns": [
        {
          "name": "Exception type",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Required approval",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Required evidence",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Review rule",
          "type": "text",
          "required": "yes"
        }
      ],
      "hint": {
        "text": "Exceptions are controlled risk decisions; approval level must match impact, legal exposure and residual risk.",
        "bookReference": "Volume 1, S-02-01-00 Information Security Policies & Risk"
      }
    },
    {
      "order": 9,
      "id": "communication_and_acknowledgement",
      "title": "Communication and acknowledgement",
      "contentType": "operating_rules",
      "required": true,
      "requiredElements": [
        "onboarding acknowledgement",
        "annual acknowledgement",
        "material update acknowledgement",
        "contractor coverage",
        "overdue acknowledgement escalation",
        "evidence retention"
      ],
      "hint": {
        "text": "A policy is not operational until the intended audience has received it and acknowledgement gaps are followed up.",
        "bookReference": "Volume 1, S-02-01-00 Information Security Policies & Risk"
      }
    },
    {
      "order": 12,
      "id": "evidence_and_records",
      "title": "Evidence and records",
      "contentType": "evidence_table",
      "required": true,
      "columns": [
        {
          "name": "Evidence ID",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Record type",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Owner",
          "type": "select",
          "required": "yes",
          "valueSet": "domain.owner",
          "options": [
            "ISMS Manager",
            "Control Owner",
            "Risk Owner",
            "Process Owner",
            "Asset Owner",
            "IT Security",
            "HR",
            "Legal",
            "Executive Management",
            "Internal Audit"
          ],
          "validation": {
            "allowBlank": false,
            "errorTitle": "Invalid value",
            "error": "Select a value from the list."
          }
        },
        {
          "name": "Retention / review rule",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Typical issue",
          "type": "text",
          "required": "yes"
        }
      ],
      "hint": {
        "text": "The policy is not implemented until communication, acknowledgement, exception and review evidence can be retrieved.",
        "bookReference": "Volume 1, S-02-01-00 Information Security Policies & Risk"
      }
    },
    {
      "order": 13,
      "id": "external_references",
      "title": "References",
      "contentType": "reference_table",
      "required": true,
      "hint": {
        "text": "Apply References with named owners, systems and exportable evidence. Do not leave this chapter as a heading plus a bare table.",
        "bookReference": "Volume 1, S-02-01-00 Information Security Policies & Risk"
      }
    }
  ],
  "validationRules": [
    "JSON Example must contain definitionRef pointing to ISP.artifactDefinition.v2.",
    "JSON Example sections must use id/title and include schemaRef for structured tables.",
    "Template must contain practical examples and common challenges, not only policy prose.",
    "Policy content must include explicit management commitment, scope applicability, measurable objective governance and minimum security rules.",
    "Supporting policy framework, exception approval matrix and communication/acknowledgement operating rules must be present.",
    "Body must render the policy content, framework mapping, exception model, acknowledgement model, practical examples, pitfalls, evidence.",
    "No mdDefinition, mdExample, requiredStructureAndContent, hintPolicy, instructionsForGenerator, standalone Book reference section or generic placeholder dates are allowed."
  ],
  "enrichment": {
    "source": "Contract.json",
    "method": "curated-json",
    "note": "Completes Contract JSON from MD-only schema/sections, removes duplicate alias sections, and normalizes string columns into structured column objects."
  },
  "editorialContractId": "editorial.docx.policy.v1",
  "contentContractId": "content.literary.v1",
  "relations": [
    {
      "kind": "usesTemplate",
      "artifactId": "MRMT",
      "role": "managementReview",
      "expectedType": "Minutes",
      "rank": 1
    },
    {
      "kind": "cites",
      "artifactId": "MDR",
      "role": "evidence_register",
      "expectedType": "Register",
      "rank": 2
    },
    {
      "kind": "cites",
      "artifactId": "DR",
      "role": "evidence_register",
      "expectedType": "Register",
      "rank": 3
    },
    {
      "kind": "cites",
      "artifactId": "AI",
      "role": "inventory",
      "expectedType": "Inventory",
      "rank": 20
    },
    {
      "kind": "cites",
      "artifactId": "SINV",
      "role": "inventory",
      "expectedType": "Inventory",
      "rank": 21
    },
    {
      "kind": "cites",
      "artifactId": "UAI",
      "role": "inventory",
      "expectedType": "Inventory",
      "rank": 22
    }
  ]
}
