{
  "schemaVersion": "artifactExample.v2",
  "artifactId": "ISS",
  "title": "ISMS Scope Statement",
  "definitionRef": {
    "artifactId": "ISS",
    "definitionSchemaVersion": "artifactDefinition.v2",
    "definitionId": "ISS.artifactDefinition.v2",
    "title": "ISMS Scope Statement"
  },
  "organization": "Arcfield",
  "sections": [
    {
      "id": "title_page",
      "title": "Title Page",
      "values": {
        "Document Title": "ISMS Scope Statement",
        "Document ID": "ISMS-SCOPE-001",
        "Version": "1.1",
        "Status": "Approved",
        "Organization": "Arcfield",
        "Owner": "ISMS Manager",
        "Approver": "Top Management",
        "Classification": "Internal",
        "Effective Date": "2026-09-11",
        "Next Review Date": "2027-09-11"
      },
      "items": [
        "Document Title: ISMS Scope Statement",
        "Document ID: ISMS-SCOPE-001",
        "Version: 1.1",
        "Status: Approved",
        "Organization: Arcfield",
        "Owner: ISMS Manager",
        "Approver: Top Management",
        "Classification: Internal",
        "Effective Date: 2026-09-11",
        "Next Review Date: 2027-09-11"
      ],
      "contentType": "metadata"
    },
    {
      "id": "abstract",
      "title": "Abstract",
      "text": "This example defines the Arcfield ISMS audit boundary, including scope decision principles, context inputs, interested parties, included boundaries, exclusions, shared responsibilities, change triggers and downstream traceability. This statement remains binding for the certified Arcfield Platform ISMS in the surveillance cycle after certificate ARC-ISMS-2025-001.",
      "contentType": "narrative"
    },
    {
      "id": "document_control",
      "title": "Document Control",
      "contentType": "control_table"
    },
    {
      "id": "change_log",
      "title": "Revision history",
      "groups": [
        {
          "text": "A published change is a new row. Do not edit an approved version in place."
        },
        {
          "rows": [
            {
              "Version": "1.0",
              "Date": "2026-08-29",
              "Change": "Initial Arcfield Platform publication.",
              "Approved by": "Top Management"
            },
            {
              "Version": "1.1",
              "Date": "2026-09-11",
              "Change": "Approved Arcfield worked example after the 11 September 2026 internal audit.",
              "Approved by": "Top Management"
            }
          ]
        }
      ],
      "contentType": "revision_table"
    },
    {
      "id": "instructions",
      "title": "Instructions",
      "groups": [
        {
          "text": "Copy this file as the controlled Word master for your ISMS. The Arcfield identity fields on the cover are the approved worked example. Complete the steps below when you adopt the file for your organization."
        },
        {
          "items": [
            "Fill the cover identity fields (Organization, Version, Classification, Owner, Approver, Effective Date and Next Review Date) when you adopt this file. The Arcfield values shown here are the approved worked example.",
            "Issue your own version and a new Revision history row. Do not edit an approved version in place.",
            "Cite this approved version from related records. Do not copy this file into those records."
          ]
        }
      ],
      "contentType": "ordered_list"
    },
    {
      "id": "scope_content",
      "title": "Scope",
      "values": {
        "Scope decision principle": "Arcfield includes services, systems, people, suppliers and evidence sources that affect confidentiality, integrity or availability of in-scope customer services.",
        "Management approval": "Top Management approves the ISMS boundary and accepts accountability for justified exclusions.",
        "Context inputs": [
          "Customer contractual requirements",
          "Regulated fintech and health customer expectations",
          "Cloud service dependencies",
          "Supplier and subprocessor responsibilities",
          "Internal support and engineering processes"
        ],
        "Interested parties": [
          "Customers",
          "Personnel and contractors",
          "Cloud and support suppliers",
          "Regulators and auditors",
          "Top Management"
        ],
        "Scope statement": "The ISMS covers Arcfield Platform, production cloud environment, supporting engineering and operations processes, selected corporate IT services, supplier management and evidence repositories used to operate and assure those services. Corporate finance systems are out of scope. In-scope data is customer PII and limited payment metadata; card data is not stored.",
        "Included boundaries": [
          "Production cloud accounts and environments",
          "Customer support and ticketing processes",
          "Identity, access and privileged administration processes",
          "Security monitoring, incident response and backup processes",
          "Critical suppliers and shared-responsibility interfaces"
        ],
        "Exclusions": [
          "Marketing website without customer data or production trust path, subject to annual verification",
          "Corporate finance systems are out of scope."
        ],
        "Interfaces and dependencies": [
          "Cloud hosting provider",
          "Identity provider",
          "Support platform",
          "Backup provider",
          "External penetration test supplier"
        ],
        "Scope change triggers": [
          "New customer-data processing",
          "New critical supplier",
          "Major architecture change",
          "New regulatory or contractual obligation",
          "Material incident or audit finding"
        ],
        "Downstream traceability": "Scope decisions feed the risk register, Statement of Applicability, asset inventory, supplier inventory, audit plan and management review."
      },
      "groups": [
        {
          "id": "introduction",
          "heading": "What this statement is",
          "level": 1,
          "text": "This document is Arcfield's ISMS Scope Statement. It freezes what is inside the Information Security Management System and which exclusions are approved. It is not the Organization Statement, not the asset inventory and not the Statement of Applicability. Risk, SoA, audit and supplier assurance all cite this Document Control version. Do not copy the boundary into those records."
        },
        {
          "id": "scope",
          "heading": "Scope",
          "level": 1,
          "text": "Use this table before you freeze a boundary or exclusion. The ISMS scope statement later in this file is the boundary itself.",
          "rows": [
            {
              "In this statement": "The ISMS boundary, justified exclusions, interfaces and change triggers.",
              "Not in this statement": "ISMS roles and deputies. Those live in the Organization Statement.",
              "Evidence reference": "ISS-SCOPE-2026-Q3",
              "Evidence status": "Complete"
            },
            {
              "In this statement": "Interfaces that can affect CIA of in-scope services, including cloud and critical suppliers.",
              "Not in this statement": "Annex A control selection. That is the SoA.",
              "Evidence reference": "ISS-SCOPE-2026-Q3",
              "Evidence status": "Complete"
            },
            {
              "In this statement": "The freeze that asset inventory, supplier inventory, RAM and the audit plan must cite.",
              "Not in this statement": "The live asset or supplier register rows.",
              "Evidence reference": "ISS-SCOPE-2026-Q3",
              "Evidence status": "Complete"
            }
          ]
        },
        {
          "id": "terms",
          "heading": "Terms used here",
          "level": 1,
          "text": "These terms are local to this file. Expand every acronym on first use in the body.",
          "rows": [
            {
              "Term": "Boundary",
              "Meaning": "The freeze of people, processes, technology, locations and suppliers inside the ISMS."
            },
            {
              "Term": "Exclusion",
              "Meaning": "Something left outside the ISMS only when it is explicit, justified, approved and reviewable."
            },
            {
              "Term": "Interface",
              "Meaning": "A shared-responsibility hand-off (cloud, identity, CI/CD, support) that can still affect in-scope CIA."
            }
          ]
        },
        {
          "id": "named_registers",
          "heading": "Systems, integrations and data",
          "level": 1,
          "text": "Related inventories live in the companion documents named below. This file cites them by their approved version. It does not copy their content.",
          "items": [
            "[Asset Inventory](AI_Asset_Inventory.xlsx) — In-scope assets with owner, classification, hosting, personal-data flag and related risk.",
            "[Supplier Inventory](SINV_Supplier_Inventory.xlsx) — Security-relevant suppliers with tier, due diligence, contract controls, subprocessors and exit planning.",
            "[Users and Access Inventory](UAI_Users_and_Access_Inventory.xlsx) — Users and accounts with access rights, privileged access, MFA status, reviews and revocations."
          ],
          "ordered": true,
          "relationView": "inventory"
        },
        {
          "heading": "Scope decision principle",
          "level": 1,
          "text": "Any person, process, system, supplier, location or data flow that can affect production security outcomes, customer-data protection, critical service continuity or ISMS evidence is in scope unless a documented, risk-assessed and approved exclusion exists."
        },
        {
          "heading": "Management approval and accountability",
          "level": 1,
          "text": "Top Management approves the ISMS scope and accepts accountability for the resulting audit boundary. The ISMS Manager maintains the statement; the Risk Manager confirms downstream risk impact; supplier owners confirm third-party dependencies."
        },
        {
          "heading": "Context inputs",
          "level": 1,
          "text": "Arcfield operates a B2B SaaS platform with cloud-first operations, remote work, enterprise customer security expectations and contractual evidence obligations. These factors bring cloud infrastructure, identity, deployment, monitoring, support, supplier and evidence systems into scope."
        },
        {
          "heading": "Interested parties",
          "level": 1,
          "text": "Enterprise customers, Top Management, personnel, suppliers, auditors and regulators influence the scope through evidence, governance, access-control, supplier-assurance and documented-information requirements."
        },
        {
          "heading": "ISMS scope statement",
          "level": 1,
          "text": "The ISMS covers the information, people, processes, technologies, suppliers and locations required to design, develop, operate, support, secure, monitor and improve the Arcfield SaaS platform and associated business operations.\n\nIncluded areas include production and non-production environments, identity and access management, repositories, CI/CD, infrastructure-as-code, monitoring, logging, backup, recovery, vulnerability management, incident management, support operations, ISMS governance, approved endpoints and critical suppliers. Corporate finance systems are out of scope. In-scope data is customer PII and limited payment metadata; card data is not stored.",
          "id": "scope_statement"
        },
        {
          "heading": "Exclusions",
          "level": 1,
          "text": "Exclusions must be explicit, justified, approved and periodically reviewed. An exclusion is invalid if it hides a system, process, person or supplier that can affect production security outcomes, customer-data protection, continuity or ISMS evidence. Corporate finance systems are out of scope.",
          "id": "exclusions"
        },
        {
          "heading": "Interfaces and dependencies",
          "level": 1,
          "text": "Cloud providers, identity providers, repositories, CI/CD, ticketing, support tooling, monitoring platforms and evidence repositories are boundary interfaces. Interfaces are not footnotes: they define where scope, risk, supplier responsibility and evidence meet.",
          "id": "interfaces"
        },
        {
          "heading": "Scope change triggers",
          "level": 1,
          "text": "Review the scope after new products, suppliers, environments, major incidents, audit findings, regulatory changes, acquisitions, outsourcing or new tooling affecting identity, support, deployment, logging or monitoring."
        },
        {
          "id": "operating_evidence_sample",
          "heading": "Operating evidence sample",
          "level": 1,
          "text": "These records can be retrieved for the 2026-08-29 Arcfield / Arcfield Platform freeze. They are the sample an auditor can re-perform. They are not a second register grid.",
          "rows": [
            {
              "Sample ID": "ISS-EV-001",
              "What was sampled": "Approved ISMS boundary freeze (This file (Document Control 1.1))",
              "Evidence reference": "ISS-SCOPE-2026-Q3"
            },
            {
              "Sample ID": "ISS-EV-002",
              "What was sampled": "Exclusion file for supplier-operated layers (SINV / SAS shared-responsibility)",
              "Evidence reference": "ISS-EXCL-SUP-2026"
            },
            {
              "Sample ID": "ISS-EV-003",
              "What was sampled": "Interface list to identity, CI/CD and backup (SAS_Systems_Architecture_Statement.docx)",
              "Evidence reference": "SAS-EV-002"
            },
            {
              "Sample ID": "ISS-EV-004",
              "What was sampled": "Asset inventory coverage of the named boundary (AI_Asset_Inventory.xlsx)",
              "Evidence reference": "AI-COMPLETE-2026-Q3"
            },
            {
              "Sample ID": "ISS-EV-005",
              "What was sampled": "Top Management approval of inclusions and exclusions (DR / Document Control)",
              "Evidence reference": "ISS-APPROVAL-2026-09-11"
            }
          ]
        }
      ],
      "contentType": "scope_sections"
    },
    {
      "id": "exclusion_approval_matrix",
      "title": "Exclusion approval matrix",
      "schemaRef": {
        "definitionId": "ISS.artifactDefinition.v2",
        "sectionId": "exclusion_approval_matrix",
        "columnsRef": "sections.exclusion_approval_matrix.columns"
      },
      "groups": [
        {
          "text": "Use this table or list as the working record. Name owners, systems and evidence so a second person can apply the same rule."
        },
        {
          "rows": [
            {
              "Exclusion type": "No customer data and no production trust path",
              "Required approval": "ISMS Manager",
              "Required evidence": "Data-flow and trust-path verification",
              "Review rule": "Annual and after architecture change",
              "Evidence reference": "ISS-SCOPE-2026-Q3",
              "Evidence status": "Complete"
            },
            {
              "Exclusion type": "Supplier-operated infrastructure layer",
              "Required approval": "Supplier Manager and Risk Manager",
              "Required evidence": "Shared-responsibility review and supplier assurance",
              "Review rule": "At supplier review cadence",
              "Evidence reference": "ISS-SCOPE-2026-Q3",
              "Evidence status": "Complete"
            },
            {
              "Exclusion type": "Physical location with no in-scope work",
              "Required approval": "ISMS Manager and Office Manager",
              "Required evidence": "Location-use confirmation",
              "Review rule": "Annual and after workforce change",
              "Evidence reference": "ISS-SCOPE-2026-Q3",
              "Evidence status": "Complete"
            },
            {
              "Exclusion type": "Potential customer or regulatory impact",
              "Required approval": "Top Management and Legal or Privacy Lead",
              "Required evidence": "Impact assessment and risk decision",
              "Review rule": "Before exclusion and after material change",
              "Evidence reference": "ISS-SCOPE-2026-Q3",
              "Evidence status": "Complete"
            }
          ]
        }
      ],
      "contentType": "approval_matrix"
    },
    {
      "id": "evidence_and_records",
      "title": "Evidence and records",
      "groups": [
        {
          "text": "Related records live in the companion documents named below. This file cites them by their approved version. It does not copy their content. The Owner named on the cover is accountable for those live records."
        },
        {
          "items": [
            "[Mandatory Documents and Records Register](MDR_Mandatory_Documents_and_Records_Register.xlsx) — The 27 mandatory ISO 27001 documents and records, with owner, required status, approval, review cadence, location and evidence readiness.",
            "[Document Register](DR_Document_Register.xlsx) — Controlled documented information: origin, owner, approver, version, review cycle, retention and location.",
            "[Records Retention Schedule](RRS_Records_Retention_Schedule_Register.xlsx) — Retention rules for ISMS, security, privacy, audit and operational records, with owner, period, disposal method and evidence."
          ],
          "ordered": true,
          "relationView": "evidence"
        }
      ],
      "contentType": "evidence_table"
    },
    {
      "id": "external_references",
      "title": "References",
      "groups": [
        {
          "id": "linked_documents",
          "heading": "Linked documents",
          "level": 1,
          "text": "These companion files sit next to this document in the unpacked package. This file cites them by their approved version. It does not copy their content.",
          "rows": [
            {
              "Kind": "Artifact",
              "Reference": "MDR Mandatory Documents and Records Register",
              "How this document uses it": "The 27 mandatory ISO 27001 documents and records, with owner, required status, approval, review cadence, location and evidence readiness.",
              "href": "MDR_Mandatory_Documents_and_Records_Register.xlsx"
            },
            {
              "Kind": "Artifact",
              "Reference": "DR Document Register",
              "How this document uses it": "Controlled documented information: origin, owner, approver, version, review cycle, retention and location.",
              "href": "DR_Document_Register.xlsx"
            },
            {
              "Kind": "Artifact",
              "Reference": "RRS Records Retention Schedule",
              "How this document uses it": "Retention rules for ISMS, security, privacy, audit and operational records, with owner, period, disposal method and evidence.",
              "href": "RRS_Records_Retention_Schedule_Register.xlsx"
            },
            {
              "Kind": "Artifact",
              "Reference": "AI Asset Inventory",
              "How this document uses it": "In-scope assets with owner, classification, hosting, personal-data flag and related risk.",
              "href": "AI_Asset_Inventory.xlsx"
            },
            {
              "Kind": "Artifact",
              "Reference": "SINV Supplier Inventory",
              "How this document uses it": "Security-relevant suppliers with tier, due diligence, contract controls, subprocessors and exit planning.",
              "href": "SINV_Supplier_Inventory.xlsx"
            },
            {
              "Kind": "Artifact",
              "Reference": "UAI Users and Access Inventory",
              "How this document uses it": "Users and accounts with access rights, privileged access, MFA status, reviews and revocations.",
              "href": "UAI_Users_and_Access_Inventory.xlsx"
            },
            {
              "Kind": "Artifact",
              "Reference": "CR Context Register (Building the ISMS, Context of the Organization (Clause 4))",
              "href": "CR_Context_Register.xlsx",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record."
            },
            {
              "Kind": "Artifact",
              "Reference": "IMPL-WB ISMS Implementation Workbook (Implementation & Certification, Implementation Readiness & Planning)",
              "href": "IMPL-WB_ISMS_Implementation_Workbook_Dashboard.xlsx",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record."
            }
          ]
        },
        {
          "id": "external_sources",
          "heading": "External references",
          "level": 1,
          "text": "Cite these ISO clauses and book chapters from workshops and audits.",
          "rows": [
            {
              "Kind": "ISO",
              "Reference": "ISO/IEC 27001:2022",
              "How this document uses it": "Normative ISMS requirements this companion artifact supports.",
              "href": "https://www.iso.org/standard/82875.html"
            },
            {
              "Kind": "Book",
              "Reference": "Building the ISMS, Context of the Organization (Clause 4)",
              "How this document uses it": "Primary operating chapter for this companion artifact.",
              "href": "https://www.amazon.com/dp/9789908983448"
            }
          ]
        }
      ],
      "contentType": "reference_table"
    }
  ],
  "enrichment": {
    "source": "Example.json",
    "method": "curated-json",
    "note": "Completes Example JSON with renderer-native sections and generalized groups; no mdSource helper fields."
  },
  "snapshotRef": {
    "snapshotId": "arcfield.platform.surv.2026-09-11",
    "schemaVersion": "evidenceSnapshot.v1"
  },
  "scenarioRef": {
    "githubIssue": 64,
    "crId": "CR-TYPE-ARCFIELD-001",
    "family": "Statement",
    "role": "Binding Arcfield Platform ISMS statement in the surveillance window"
  }
}
