{
  "schemaVersion": "artifactExample.v2",
  "artifactId": "ISP",
  "title": "Information Security Policy",
  "definitionRef": {
    "artifactId": "ISP",
    "definitionSchemaVersion": "artifactDefinition.v2",
    "definitionId": "ISP.artifactDefinition.v2",
    "title": "Information Security Policy"
  },
  "organization": "Arcfield",
  "sections": [
    {
      "id": "title_page",
      "title": "Title Page",
      "values": {
        "Document Title": "Information Security Policy",
        "Document ID": "POL-SEC-001",
        "Version": "1.1",
        "Status": "Approved",
        "Organization": "Arcfield",
        "Owner": "ISMS Manager",
        "Approver": "Top Management",
        "Classification": "Internal",
        "Effective Date": "2026-09-11",
        "Next Review Date": "2027-09-11"
      },
      "items": [
        "Document Title: Information Security Policy",
        "Document ID: POL-SEC-001",
        "Version: 1.1",
        "Status: Approved",
        "Organization: Arcfield",
        "Owner: ISMS Manager",
        "Approver: Top Management",
        "Classification: Internal",
        "Effective Date: 2026-09-11",
        "Next Review Date: 2027-09-11"
      ],
      "contentType": "metadata"
    },
    {
      "id": "abstract",
      "title": "Abstract",
      "text": "This example is the top-level Arcfield information security policy. It establishes management commitment, scope, measurable objectives, minimum security rules, the ISO/IEC 27001:2022 certificate issued in 2025, the surveillance cycle, supporting policy framework, exception governance, communication, evidence and approval expectations. The cover status is not a real management-team sign-off of these new rule sentences.",
      "contentType": "narrative"
    },
    {
      "id": "document_control",
      "title": "Document Control",
      "contentType": "control_table"
    },
    {
      "id": "change_log",
      "title": "Revision history",
      "groups": [
        {
          "text": "A published change is a new row. Do not edit an approved version in place."
        },
        {
          "rows": [
            {
              "Version": "1.0",
              "Date": "2026-08-29",
              "Change": "Initial Arcfield Platform publication.",
              "Approved by": "Top Management"
            },
            {
              "Version": "1.1",
              "Date": "2026-09-11",
              "Change": "Approved Arcfield worked example after the 11 September 2026 internal audit; records ISO/IEC 27001:2022 certificate ARC-ISMS-2025-001 (28 November 2025) and the first surveillance cycle.",
              "Approved by": "Top Management"
            }
          ]
        }
      ],
      "contentType": "revision_table"
    },
    {
      "id": "instructions",
      "title": "Instructions",
      "groups": [
        {
          "text": "This file is a fictional Arcfield example, not your organization's approved policy. Copy this file as the controlled Word master for your ISMS only after you replace Arcfield decisions with your own."
        },
        {
          "items": [
            "Treat POL-SEC-001 and the rule IDs as the example identity. Cover status Approved is the Arcfield scenario freeze, not a real management-team sign-off of these new rule sentences.",
            "Replace Arcfield names, methods and owners before you adopt the file.",
            "Cite the Document Control version from related records. Do not copy this body into those records."
          ]
        }
      ],
      "contentType": "ordered_list"
    },
    {
      "id": "policy_content",
      "title": "Policy",
      "values": {
        "Policy statement": "Arcfield protects confidentiality, integrity and availability through a risk-based ISMS aligned with ISO/IEC 27001:2022.",
        "Management commitment": "Top Management commits to providing resources, assigning responsibilities, supporting continual improvement and ensuring that information security objectives remain aligned with business, customer, legal, regulatory and contractual requirements.",
        "Scope applicability": "This policy applies to all personnel, contractors, systems, services, suppliers and processes within the approved ISMS scope.",
        "Measurable objectives": "Measurable information security objectives are maintained separately, reviewed at least annually, monitored through defined metrics and reported to Top Management during management review.",
        "Minimum security rules": [
          "Use approved accounts, systems and storage locations for company information.",
          "Apply least privilege and MFA for privileged, remote and customer-data access.",
          "Classify and handle information according to approved classification rules.",
          "Report suspected incidents, weaknesses, data exposure or lost devices without delay.",
          "Assess security risk before significant supplier, system, architecture or processing changes.",
          "Keep security evidence complete, current and retrievable.",
          "Manage exceptions through documented approval, compensating controls and expiry.",
          "Review policies, risks and controls after major changes or incidents."
        ],
        "Exception rule": "Exceptions require documented justification, risk assessment, owner approval, expiry date and compensating controls."
      },
      "groups": [
        {
          "id": "introduction",
          "heading": "What this policy is",
          "level": 1,
          "text": "This document is Arcfield's Information Security Policy, document ID POL-SEC-001. It is Top Management's top-level promise for a software company and must be testable. It is not ISS, RAM or SoA. Supporting policies, registers and procedures can be checked against it. Cite this Document Control version from those records. Do not copy these paragraphs into them."
        },
        {
          "id": "scope",
          "heading": "Scope",
          "level": 1,
          "text": "Use this table before you copy a rule into another record or exclude a duty from this file.",
          "rows": [
            {
              "In this policy": "The classified rules ISP-MIN-001, ISP-MIN-002, ISP-MIN-003 through ISP-EV-001, roles, the worked Arcfield example and the records this file owns.",
              "Not in this policy": "The ISMS boundary (ISS), Annex A selection (SoA), or live neighbouring registers. Those files keep their own versions."
            },
            {
              "In this policy": "Interfaces that must cite this Document Control version, including CI/CD, identity and suppliers where they affect confidentiality, integrity or availability.",
              "Not in this policy": "Live ISS or SoA decisions. Neighbouring live registers keep their own versions. Those files are named, not copied here."
            }
          ]
        },
        {
          "id": "terms",
          "heading": "Terms used here",
          "level": 1,
          "text": "These terms are local to this file. Expand every acronym on first use in the body. Artefact ID ISO is Information Security Objectives, not the International Organization for Standardization.",
          "rows": [
            {
              "Term": "Owner",
              "Meaning": "The named role that can be called in an audit for an outcome. A team name is not an owner."
            },
            {
              "Term": "Exception",
              "Meaning": "A time-bound, approved departure with expiry and a compensating control. An expired row does not authorise continued deviation."
            },
            {
              "Term": "Document Control version",
              "Meaning": "The version cited from neighbouring records. Do not copy this body into those records."
            },
            {
              "Term": "Enforcement",
              "Meaning": "The named system rejects the unauthorised attempt for the named population. Registration or capability is not enforcement."
            }
          ]
        },
        {
          "id": "named_registers",
          "heading": "Systems, integrations and data",
          "level": 1,
          "text": "Related inventories live in the companion documents named below. Cite the approved version. Do not copy their content. Availability follows the book pack, not this sentence.",
          "items": [
            "[Asset Inventory](AI_Asset_Inventory.xlsx) — In-scope assets with owner, classification, hosting, personal-data flag and related risk.",
            "[Supplier Inventory](SINV_Supplier_Inventory.xlsx) — Security-relevant suppliers with tier, due diligence, contract controls, subprocessors and exit planning.",
            "[Users and Access Inventory](UAI_Users_and_Access_Inventory.xlsx) — Users and accounts with access rights, privileged access, MFA status, reviews and revocations."
          ],
          "ordered": true,
          "relationView": "inventory"
        },
        {
          "heading": "Policy statement",
          "level": 1,
          "text": "Arcfield shall protect the confidentiality, integrity and availability of information assets through a risk-based Information Security Management System aligned with ISO/IEC 27001:2022.",
          "id": "policy_statement"
        },
        {
          "id": "certification_status",
          "heading": "Certification status",
          "level": 1,
          "text": "Arcfield holds an ISO/IEC 27001:2022 certificate for the Arcfield Platform ISMS. Certificate ARC-ISMS-2025-001 was issued on 25 April 2025 after Stage 2 on 8–10 April 2025, and remains valid until 24 April 2028. The ISMS is in the surveillance after first visit window (due April 2026). The status at certificate issue is recorded in CA-ARCFIELD-EN-2025-04-10. This policy is Top Management's binding promise during that cycle. It does not replace the certification-audit report, ISS or the SoA."
        },
        {
          "heading": "Management commitment",
          "level": 1,
          "items": [
            "providing appropriate resources for the ISMS;",
            "assigning and supporting information security responsibilities;",
            "ensuring information security objectives remain aligned with business, customer, legal, regulatory and contractual requirements;",
            "integrating information security into relevant business processes;",
            "supporting continual improvement of the ISMS;",
            "reviewing significant risks, incidents, audit results, exceptions and resource needs;",
            "ensuring that nonconformities and unacceptable residual risks receive appropriate management attention."
          ],
          "text": "Top Management commits to:",
          "id": "management_commitment"
        },
        {
          "heading": "Information security objectives",
          "level": 1,
          "items": [
            "access-review completion;",
            "security awareness and policy acknowledgement;",
            "incident reporting and response timeliness;",
            "risk-treatment progress;",
            "supplier review completion;",
            "evidence readiness;",
            "corrective-action closure."
          ],
          "text": "Measurable information security objectives are maintained separately, reviewed at least annually, monitored through defined metrics and reported to Top Management during management review.\n\nTypical objective areas include:",
          "id": "objectives"
        },
        {
          "heading": "Responsibilities",
          "level": 1,
          "rows": [
            {
              "Role": "Top Management",
              "Responsibility": "Approves policy, objectives, resources and significant risk decisions; confirms policy suitability during management review."
            },
            {
              "Role": "ISMS Manager",
              "Responsibility": "Maintains the ISMS, coordinates policy review, monitors evidence readiness and reports performance."
            },
            {
              "Role": "Risk Manager",
              "Responsibility": "Maintains risk criteria, risk register, treatment tracking and residual-risk acceptance evidence."
            },
            {
              "Role": "Asset Owners",
              "Responsibility": "Protect assigned information assets and provide evidence of ownership and classification."
            },
            {
              "Role": "Control Owners",
              "Responsibility": "Operate controls and report exceptions, incidents, weaknesses and improvement needs."
            },
            {
              "Role": "Supplier Manager",
              "Responsibility": "Ensures relevant suppliers receive and meet applicable security requirements."
            },
            {
              "Role": "HR Manager",
              "Responsibility": "Coordinates onboarding, awareness, acknowledgement and personnel-policy evidence."
            },
            {
              "Role": "Personnel and contractors",
              "Responsibility": "Follow policies, complete training, protect information and report incidents or weaknesses."
            }
          ],
          "id": "responsibilities",
          "text": "Keep one accountable owner per row. Signed appointments live in IRAR; this table does not replace that register."
        },
        {
          "id": "minimum_security_rules",
          "heading": "Minimum security rules",
          "level": 1,
          "text": "These rules are binding inside the approved ISMS scope. They include MFA or least privilege, incident reporting, and exceptions with expiry.",
          "rows": [
            {
              "Rule ID": "ISP-MIN-001",
              "Statement": "Use approved accounts, systems and storage locations for company information. Personal mail and unapproved software services are not authorised stores for Confidential or Restricted data.",
              "Scope": "In-scope Arcfield Platform information.",
              "Owner": "ISMS Manager",
              "Evidence expectation": "Expected: acknowledgement plus a sampled store check. No observation is supplied."
            },
            {
              "Rule ID": "ISP-MIN-002",
              "Statement": "Apply least privilege and MFA for privileged, remote and customer-data access. MFA registration alone does not demonstrate enforcement.",
              "Scope": "Privileged, remote and customer-data access to Arcfield Platform.",
              "Owner": "ISMS Manager",
              "Evidence expectation": "Expected: identity-provider enforcement for that population. No observation is supplied."
            },
            {
              "Rule ID": "ISP-MIN-003",
              "Statement": "Classify and handle information according to the approved classification rules. Report suspected incidents, weaknesses, data exposure or lost devices without delay.",
              "Scope": "All in-scope personnel.",
              "Owner": "ISMS Manager",
              "Evidence expectation": "Expected: classification on the live record plus an incident channel. No observation is supplied."
            },
            {
              "Rule ID": "ISP-MIN-004",
              "Statement": "An exception needs an owner, an expiry date and a compensating control. An expired exception does not authorise continued deviation.",
              "Scope": "Deviations from the minimum security rules.",
              "Owner": "ISMS Manager",
              "Evidence expectation": "Expected: exception row with expiry. No observation is supplied."
            }
          ]
        },
        {
          "id": "compliance",
          "heading": "Compliance",
          "level": 1,
          "text": "Read ISP-CMP-001 as the classified Arcfield rule for this topic. Capability or presence is not enforcement.",
          "rows": [
            {
              "Rule ID": "ISP-CMP-001",
              "Statement": "Personnel and suppliers inside the ISS boundary must follow this policy and the supporting topic policies. This file does not select Annex A controls; that is the SoA.",
              "Scope": "In-scope personnel and suppliers.",
              "Owner": "ISMS Manager",
              "Evidence expectation": "Expected: acknowledgement or contract clause. No observation is supplied."
            }
          ]
        },
        {
          "id": "review",
          "heading": "Review",
          "level": 1,
          "text": "Read ISP-REV-001 as the classified Arcfield rule for this topic. Capability or presence is not enforcement.",
          "rows": [
            {
              "Rule ID": "ISP-REV-001",
              "Statement": "This policy is reviewed at least annually and after a material change to scope or certificate status. Cover status Approved is the Arcfield scenario freeze, not a real management-team sign-off of new rule sentences.",
              "Scope": "This Document Control version.",
              "Owner": "ISMS Manager",
              "Evidence expectation": "Expected: review date on the cover. No observation is supplied."
            }
          ]
        },
        {
          "id": "policy_framework",
          "heading": "Policy framework",
          "level": 1,
          "text": "Read ISP-FW-001 as the classified Arcfield rule for this topic. Capability or presence is not enforcement.",
          "rows": [
            {
              "Rule ID": "ISP-FW-001",
              "Statement": "Supporting topic policies must be checkable against this file. This file does not duplicate ISS, RAM, RR or the SoA.",
              "Scope": "Supporting Arcfield policies named in the framework table.",
              "Owner": "ISMS Manager",
              "Evidence expectation": "Expected: framework table citing those records by Document Control version. No observation is supplied."
            }
          ]
        },
        {
          "id": "risk_based_operation",
          "heading": "Risk-based operation",
          "level": 1,
          "text": "Read ISP-RSK-001 as the classified Arcfield rule for this topic. Capability or presence is not enforcement.",
          "rows": [
            {
              "Rule ID": "ISP-RSK-001",
              "Statement": "Risk treatment decisions live in RAM, RR and the SoA. This policy requires those records to exist; it does not score residual risk.",
              "Scope": "ISMS planning records.",
              "Owner": "ISMS Manager",
              "Evidence expectation": "Expected: citation of RAM/RR/SoA versions. No observation is supplied."
            }
          ]
        },
        {
          "id": "communication_and_acknowledgement",
          "heading": "Communication and acknowledgement",
          "level": 1,
          "text": "Read ISP-ACK-001 as the classified Arcfield rule for this topic. Capability or presence is not enforcement.",
          "rows": [
            {
              "Rule ID": "ISP-ACK-001",
              "Statement": "New personnel and contractors acknowledge this policy before access to Confidential or Restricted information. Overdue acknowledgements are escalated and tracked to closure.",
              "Scope": "Joiners and contractors with Arcfield Platform access.",
              "Owner": "ISMS Manager",
              "Evidence expectation": "Expected: acknowledgement record before access. No observation is supplied."
            }
          ]
        },
        {
          "id": "exceptions_and_nonconformities",
          "heading": "Exceptions and nonconformities",
          "level": 1,
          "text": "Read ISP-EXC-001 as the classified Arcfield rule for this topic. Capability or presence is not enforcement.",
          "rows": [
            {
              "Rule ID": "ISP-EXC-001",
              "Statement": "High or customer-impacting exceptions require Top Management approval and an expiry date. An expired row is a nonconformity.",
              "Scope": "Exceptions that affect production or customers.",
              "Owner": "ISMS Manager",
              "Evidence expectation": "Expected: exception row with the required approval. No observation is supplied."
            }
          ]
        },
        {
          "id": "classified_rules",
          "heading": "Classified rules for retained tables",
          "level": 1,
          "text": "These EXAMPLE_DECISION rows bind the retained Top Management tables. They are not a second SoA.",
          "rows": [
            {
              "Rule ID": "ISP-RRS-001",
              "Statement": "Top Management is accountable for this promise. ISMS Manager maintains the file. Control owners run the supporting policies. A title without a named person is not a responsibility.",
              "Scope": "Roles listed in this file.",
              "Owner": "ISMS Manager",
              "Evidence expectation": "Expected: named people in the responsibilities table. No observation is supplied."
            }
          ]
        },
        {
          "id": "evidence",
          "heading": "Evidence expectations",
          "level": 1,
          "text": "Use this table to see what a named evidence ID can prove. It is not a log of collected observations.",
          "rows": [
            {
              "Rule ID": "ISP-EV-001",
              "Statement": "Each rule above states an evidence expectation. An identifier without a bound dataset is not collected evidence.",
              "Scope": "All ISP rules in this file.",
              "Owner": "ISMS Manager",
              "Evidence expectation": "Expected evidence reference; no evidence supplied. Do not render this row as an observation."
            }
          ]
        }
      ],
      "contentType": "policy_sections"
    },
    {
      "id": "supporting_policy_framework",
      "title": "Supporting policy framework",
      "schemaRef": {
        "definitionId": "ISP.artifactDefinition.v2",
        "sectionId": "supporting_policy_framework",
        "columnsRef": "sections.supporting_policy_framework.columns"
      },
      "groups": [
        {
          "text": "Use this table or list as the working record. Name owners, systems and evidence so a second person can apply the same rule."
        },
        {
          "rows": [
            {
              "Supporting policy / process": "Access Control Policy",
              "Purpose": "Define least privilege, MFA, access approval, access review and revocation rules.",
              "Owner": "IT Operations Manager",
              "Typical evidence": "UAI, ARR, access-review records"
            },
            {
              "Supporting policy / process": "Asset Management Policy",
              "Purpose": "Define asset ownership, classification, handling and lifecycle expectations.",
              "Owner": "ISMS Manager",
              "Typical evidence": "AI, IAS, classification records"
            },
            {
              "Supporting policy / process": "Supplier Relationships Policy",
              "Purpose": "Define supplier selection, contracting, monitoring, incident handling and termination security requirements.",
              "Owner": "Supplier Manager",
              "Typical evidence": "SINV, SSAQ, CSSAQ, supplier contracts"
            },
            {
              "Supporting policy / process": "Incident Management Policy",
              "Purpose": "Define reporting, triage, response, communication and lessons-learned expectations.",
              "Owner": "Security Lead",
              "Typical evidence": "SIR, IRRT, ICL, IRPROC"
            },
            {
              "Supporting policy / process": "Backup & Recovery Policy",
              "Purpose": "Define backup, restore testing, recovery validation and exception handling.",
              "Owner": "Operations Lead",
              "Typical evidence": "BRPROC, restore tests, recovery actions"
            },
            {
              "Supporting policy / process": "Human Resources Security Policy",
              "Purpose": "Define security responsibilities before, during and after employment or engagement.",
              "Owner": "HR Manager",
              "Typical evidence": "TRC, onboarding, offboarding, acknowledgement records"
            },
            {
              "Supporting policy / process": "Secure Software Development Policy",
              "Purpose": "Define secure development, code review, testing and deployment requirements.",
              "Owner": "Engineering Lead",
              "Typical evidence": "CR, vulnerability records, deployment evidence"
            },
            {
              "Supporting policy / process": "Logging and Monitoring Policy",
              "Purpose": "Define log collection, monitoring, alerting, review and retention.",
              "Owner": "Security Lead",
              "Typical evidence": "MME, monitoring records, alert reviews"
            },
            {
              "Supporting policy / process": "Physical and Environmental Security Policy",
              "Purpose": "Define physical access, visitor, equipment and workspace security.",
              "Owner": "Office Manager",
              "Typical evidence": "visitor logs, physical access reviews, EP records"
            },
            {
              "Supporting policy / process": "Document Control Procedure",
              "Purpose": "Define document approval, versioning, review and retention.",
              "Owner": "ISMS Manager",
              "Typical evidence": "DR, DCP review records"
            }
          ]
        }
      ],
      "contentType": "framework_table"
    },
    {
      "id": "exception_approval_matrix",
      "title": "Exception approval matrix",
      "schemaRef": {
        "definitionId": "ISP.artifactDefinition.v2",
        "sectionId": "exception_approval_matrix",
        "columnsRef": "sections.exception_approval_matrix.columns"
      },
      "groups": [
        {
          "text": "Use this table or list as the working record. Name owners, systems and evidence so a second person can apply the same rule."
        },
        {
          "rows": [
            {
              "Exception type": "Low operational exception",
              "Required approval": "Control Owner and ISMS Manager",
              "Required evidence": "Exception record with rationale, compensating control and expiry",
              "Review rule": "Review before expiry or after control change"
            },
            {
              "Exception type": "Medium residual risk",
              "Required approval": "Risk Owner and ISMS Manager",
              "Required evidence": "Risk assessment, treatment decision and acceptance rationale",
              "Review rule": "Review at least quarterly while open"
            },
            {
              "Exception type": "High or Critical residual risk",
              "Required approval": "Top Management",
              "Required evidence": "Management approval, treatment plan, monitoring rule and expiry",
              "Review rule": "Review monthly or at management review"
            },
            {
              "Exception type": "Legal, privacy or customer-impacting exception",
              "Required approval": "Legal or Privacy Lead and Top Management",
              "Required evidence": "Impact assessment, customer or regulatory decision record and mitigation plan",
              "Review rule": "Review before implementation and after impact changes"
            },
            {
              "Exception type": "Supplier exception affecting customer or production security",
              "Required approval": "Supplier Manager, Risk Manager and ISMS Manager; Top Management if High/Critical",
              "Required evidence": "Supplier risk assessment, contract review, compensating controls and target date",
              "Review rule": "Review at supplier-monitoring cadence and before renewal"
            }
          ]
        }
      ],
      "contentType": "approval_matrix"
    },
    {
      "id": "communication_and_acknowledgement",
      "title": "Communication and acknowledgement",
      "items": [
        "New personnel and contractors must acknowledge the policy before access to sensitive information is granted.",
        "All in-scope personnel must complete annual acknowledgement or awareness confirmation.",
        "Material updates require targeted communication to affected roles.",
        "Contractors with access to Arcfield information must be included in acknowledgement evidence.",
        "Overdue acknowledgements must be escalated to managers and tracked to closure.",
        "Acknowledgement records must be retained as audit evidence."
      ],
      "groups": [
        {
          "text": "Use this table or list as the working record. Name owners, systems and evidence so a second person can apply the same rule."
        },
        {
          "rows": [
            {
              "Audience / trigger": "New employee onboarding",
              "Requirement": "Policy must be assigned and acknowledged before broad access is granted.",
              "Owner": "HR Manager",
              "Evidence": "TRC-ONBOARDING-POLICY",
              "Escalation": "Manager and ISMS Manager if overdue"
            },
            {
              "Audience / trigger": "New contractor onboarding",
              "Requirement": "Applicable policy obligations must be communicated before system access.",
              "Owner": "HR Manager / Supplier Manager",
              "Evidence": "contractor acknowledgement or contractual clause",
              "Escalation": "Access withheld or limited"
            },
            {
              "Audience / trigger": "Annual policy cycle",
              "Requirement": "Active personnel must re-acknowledge current policy.",
              "Owner": "HR Manager",
              "Evidence": "TRC-POL-ACK-ANNUAL",
              "Escalation": "Overdue list to management"
            },
            {
              "Audience / trigger": "Material policy update",
              "Requirement": "Affected personnel and suppliers must receive update notice and acknowledgement request.",
              "Owner": "ISMS Manager",
              "Evidence": "DCP-POLICY-UPDATE-LOG",
              "Escalation": "ISMS Manager follow-up"
            },
            {
              "Audience / trigger": "Role change into privileged or customer-data access",
              "Requirement": "Policy acknowledgement and role-specific training must be checked.",
              "Owner": "Manager / IT Operations Manager",
              "Evidence": "UAI-ROLECHANGE, TRC role training",
              "Escalation": "Access delayed until complete"
            },
            {
              "Audience / trigger": "Overdue acknowledgement",
              "Requirement": "Non-responders must be tracked and escalated.",
              "Owner": "HR Manager",
              "Evidence": "overdue acknowledgement report",
              "Escalation": "Manager, HR and ISMS Manager"
            }
          ]
        }
      ],
      "contentType": "operating_rules"
    },
    {
      "id": "evidence_and_records",
      "title": "Evidence and records",
      "groups": [
        {
          "text": "These companions hold live records. This policy states what evidence it needs; it does not ship observations. An evidence ID without a dataset is an expectation. The Owner on the cover is accountable for those live records when you adopt the file."
        },
        {
          "items": [
            "[Management Review Minutes Template](MRMT_Management_Review_Minutes_Template.docx) — Management-review inputs, decisions, outputs and action items.",
            "[Mandatory Documents and Records Register](MDR_Mandatory_Documents_and_Records_Register.xlsx) — The 27 mandatory ISO 27001 documents and records, with owner, required status, approval, review cadence, location and evidence readiness.",
            "[Document Register](DR_Document_Register.xlsx) — Controlled documented information: origin, owner, approver, version, review cycle, retention and location."
          ],
          "ordered": true,
          "relationView": "evidence"
        }
      ],
      "contentType": "evidence_table"
    },
    {
      "id": "external_references",
      "title": "References",
      "groups": [
        {
          "id": "linked_documents",
          "heading": "Linked documents",
          "level": 1,
          "text": "Availability is by book pack. In-pack files may sit next to this document after unpack. Other-book files are named, not shipped in this Office pack.",
          "rows": [
            {
              "Kind": "Artifact",
              "Reference": "MDR Mandatory Documents and Records Register",
              "How this document uses it": "The 27 mandatory ISO 27001 documents and records, with owner, required status, approval, review cadence, location and evidence readiness Another book's pack, not this Office pack.",
              "href": "MDR_Mandatory_Documents_and_Records_Register.xlsx",
              "availability": "other_volume"
            },
            {
              "Kind": "Artifact",
              "Reference": "DR Document Register",
              "How this document uses it": "Controlled documented information: origin, owner, approver, version, review cycle, retention and location In this book's pack when present.",
              "href": "DR_Document_Register.xlsx",
              "availability": "in-pack"
            },
            {
              "Kind": "Artifact",
              "Reference": "AI Asset Inventory",
              "How this document uses it": "In-scope assets with owner, classification, hosting, personal-data flag and related risk In this book's pack when present.",
              "href": "AI_Asset_Inventory.xlsx",
              "availability": "in-pack"
            },
            {
              "Kind": "Artifact",
              "Reference": "SINV Supplier Inventory",
              "How this document uses it": "Security-relevant suppliers with tier, due diligence, contract controls, subprocessors and exit planning In this book's pack when present.",
              "href": "SINV_Supplier_Inventory.xlsx",
              "availability": "in-pack"
            },
            {
              "Kind": "Artifact",
              "Reference": "UAI Users and Access Inventory",
              "How this document uses it": "Users and accounts with access rights, privileged access, MFA status, reviews and revocations Another book's pack, not this Office pack.",
              "href": "UAI_Users_and_Access_Inventory.xlsx",
              "availability": "other_volume"
            },
            {
              "Kind": "Artifact",
              "Reference": "TRC Training Records (Building the ISMS, Security Awareness & Training Programs)",
              "href": "TRC_Training_Records_Register.xlsx",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record In this book's pack when present.",
              "availability": "in-pack"
            },
            {
              "Kind": "Artifact",
              "Reference": "DCP Document Control Procedure (Secure Engineering, Access Control & Identity Management)",
              "href": "DCP_Document_Control_Procedure.docx",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record Another book's pack, not this Office pack.",
              "availability": "other_volume"
            },
            {
              "Kind": "Artifact",
              "Reference": "EXR Exceptions Register (Implementation & Certification, Asset Management & Information Classification)",
              "href": "EXR_Exceptions_Register.xlsx",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record Another book's pack, not this Office pack.",
              "availability": "other_volume"
            },
            {
              "Kind": "Record",
              "Reference": "CA-ARCFIELD-EN-2025-04-10 certification-audit-report-2025.md",
              "How this document uses it": "Status of the Arcfield Platform ISMS at the 2025 Stage 2 / certificate issue. Cite it; do not copy it into this policy."
            },
            {
              "Kind": "Record",
              "Reference": "CA-ARCFIELD-EN-2025-04-10-DET certification-audit-report-2025-detailed.md",
              "How this document uses it": "BBB GmbH Stage 1 and Stage 2 findings at certificate issue. Cite it; do not copy findings into this policy."
            }
          ]
        },
        {
          "id": "linked_templates",
          "heading": "Linked templates",
          "level": 1,
          "text": "Recurring records use these companion templates. Do not keep a second schema in this file.",
          "rows": [
            {
              "Kind": "Artifact",
              "Reference": "MRMT Management Review Minutes Template",
              "How this document uses it": "Recurring minutes this file requires. Record them with this companion template; do not keep a second minutes schema here In this book's pack when present.",
              "href": "MRMT_Management_Review_Minutes_Template.docx",
              "availability": "in-pack"
            }
          ]
        },
        {
          "id": "external_sources",
          "heading": "External references",
          "level": 1,
          "text": "Cite these ISO clauses and book chapters from workshops and audits.",
          "rows": [
            {
              "Kind": "ISO",
              "Reference": "ISO/IEC 27001:2022",
              "How this document uses it": "Normative ISMS requirements this companion artifact supports.",
              "href": "https://www.iso.org/standard/82875.html"
            },
            {
              "Kind": "Book",
              "Reference": "Building the ISMS, Information Security Policies & Risk Management",
              "How this document uses it": "Primary operating chapter for this companion artifact.",
              "href": "https://www.amazon.com/dp/9789908983448"
            },
            {
              "Kind": "Book",
              "Reference": "Building the ISMS, Leadership & Management (Clause 5)",
              "How this document uses it": "Management commitment and policy approval.",
              "href": "https://www.amazon.com/dp/9789908983448"
            }
          ]
        }
      ],
      "contentType": "reference_table"
    }
  ],
  "enrichment": {
    "source": "Example.json",
    "method": "curated-json",
    "note": "Completes Example JSON with renderer-native sections and generalized groups; no mdSource helper fields."
  },
  "snapshotRef": {
    "snapshotId": "arcfield.platform.surv.2026-09-11",
    "schemaVersion": "evidenceSnapshot.v1"
  },
  "scenarioRef": {
    "crId": "CR-POL-EN-002",
    "dependsOn": [
      106,
      107
    ],
    "family": "Policy",
    "role": "Fictional Arcfield worked example. Not a real management-team approval and not a certification statement.",
    "reviewState": "pending",
    "provenance": "EXAMPLE_DECISION"
  }
}
