{
  "schemaVersion": "artifactExample.v2",
  "artifactId": "MME",
  "title": "Monitoring and Measurement Evidence",
  "definitionRef": {
    "artifactId": "MME",
    "definitionSchemaVersion": "artifactDefinition.v2",
    "definitionId": "MME.artifactDefinition.v2",
    "title": "Monitoring and Measurement Evidence"
  },
  "organization": "Arcfield",
  "sections": [
    {
      "id": "title_page",
      "title": "Title Page",
      "values": {
        "Register Title": "Monitoring and Measurement Evidence",
        "Register ID": "MME-REG-001",
        "Version": "1.1",
        "Status": "Approved",
        "Organization": "Arcfield",
        "Owner": "ISMS Manager",
        "Approver": "Top Management",
        "Classification": "Internal",
        "Effective Date": "2026-09-11",
        "Next Review Date": "2027-09-11"
      },
      "items": [
        "Register Title: Monitoring and Measurement Evidence",
        "Register ID: MME-REG-001",
        "Version: 1.1",
        "Status: Approved",
        "Organization: Arcfield",
        "Owner: ISMS Manager",
        "Approver: Top Management",
        "Classification: Internal",
        "Effective Date: 2026-09-11",
        "Next Review Date: 2027-09-11"
      ],
      "contentType": "metadata"
    },
    {
      "id": "abstract",
      "title": "Abstract",
      "text": "This example tracks Arcfield ISMS monitoring and measurement evidence with metrics, targets, actual results, periods, owners, evidence sources, review frequency, status and follow-up actions. Rows are the 11 September 2026 operating sample of the certified Arcfield Platform ISMS in the surveillance cycle after certificate ARC-ISMS-2025-001.",
      "contentType": "narrative"
    },
    {
      "id": "document_control",
      "title": "Document Control",
      "rows": [
        {
          "Property": "Purpose",
          "Value": "Track ISMS monitoring and measurement evidence."
        },
        {
          "Property": "Used by",
          "Value": "ISMS Manager, Control Owners, Internal Auditor, Top Management"
        },
        {
          "Property": "Maintained by",
          "Value": "ISMS Manager"
        },
        {
          "Property": "Evidence role",
          "Value": "Clause 9.1 performance-evaluation evidence"
        },
        {
          "Property": "ISO reference",
          "Value": "ISO/IEC 27001:2022 Clause 9.1, Clause 9.3 and Clause 10.2"
        },
        {
          "Property": "Review cadence",
          "Value": "Monthly and before management review"
        }
      ],
      "contentType": "control_table"
    },
    {
      "id": "instructions",
      "title": "Instructions",
      "items": [
        "Define what is monitored or measured and why it matters.",
        "Link each metric to an objective, control, process or requirement.",
        "Record the measurement method, target and actual result.",
        "Assign an owner and review frequency.",
        "Link the evidence source and evidence reference.",
        "Open follow-up actions for weak or missing performance evidence.",
        "Use sheets ending in “Ex” as read-only examples. Enter live data only on the matching “Wk” (Working) sheets.",
        "Every operative list is an Excel Table with frozen headers and filters. Add new rows on the next empty worksheet row beneath the table so Excel expands it — do not leave blank rows inside the table.",
        "Where a column offers a dropdown, choose a value from the list (Status, Owner role, Priority, Severity, Likelihood, Impact, Applicability, Evidence Status, Review Result). Do not invent free-text variants.",
        "Enter dates as YYYY-MM-DD. Date columns are validated and formatted accordingly.",
        "Review the Flag columns (Overdue, Review Due, Missing Owner, Missing Evidence). They calculate automatically and highlight gaps for follow-up.",
        "Keep Cover, Legal, Book, Lists and Metadata unchanged. System sheets are protected on purpose."
      ],
      "contentType": "ordered_list"
    },
    {
      "id": "monitoring_measurement_register",
      "title": "Monitoring and measurement register",
      "schemaRef": {
        "definitionId": "MME.artifactDefinition.v2",
        "sectionId": "monitoring_measurement_register",
        "columnsRef": "sections.monitoring_measurement_register.columns"
      },
      "rows": [
        {
          "Metric ID": "MME-001",
          "Metric": "Security awareness completion rate",
          "Related Objective or Control": "ISO-001 / Clause 7.2",
          "Measurement Method": "Monthly training platform export",
          "Target": ">= 98% within 30 days",
          "Actual Result": "96%",
          "Period": "2026-08",
          "Owner": "HR Manager",
          "Evidence Source": "Training platform report",
          "Review Frequency": "Monthly",
          "Status": "Below target",
          "Follow-up Action": "Remind two pending contractors",
          "Evidence Reference": "TR-2026-Q3",
          "Notes": "Related to EXR-005 closure."
        },
        {
          "Metric ID": "MME-002",
          "Metric": "Privileged access review completion",
          "Related Objective or Control": "ISO-002 / A.8.2",
          "Measurement Method": "Access review register sampling",
          "Target": "100% critical systems reviewed monthly",
          "Actual Result": "4 of 5 systems reviewed",
          "Period": "2026-08",
          "Owner": "IT Operations Manager",
          "Evidence Source": "Access Review Register",
          "Review Frequency": "Monthly",
          "Status": "Below target",
          "Follow-up Action": "Complete cloud admin review",
          "Evidence Reference": "ARR-2026-08",
          "Notes": "Cloud admin exception open."
        },
        {
          "Metric ID": "MME-003",
          "Metric": "High-risk treatment overdue count",
          "Related Objective or Control": "ISO-003 / Clause 6.1",
          "Measurement Method": "Risk treatment plan review",
          "Target": "0 overdue high-risk treatments",
          "Actual Result": "1 overdue",
          "Period": "2026-08",
          "Owner": "Compliance Lead",
          "Evidence Source": "Risk Treatment Plan",
          "Review Frequency": "Bi-weekly",
          "Status": "Below target",
          "Follow-up Action": "Escalate supplier exit clause treatment",
          "Evidence Reference": "RTP-2026-Q3",
          "Notes": "Management review input required."
        },
        {
          "Metric ID": "MME-004",
          "Metric": "Incident closure within SLA",
          "Related Objective or Control": "ISO-004 / A.5.24-A.5.28",
          "Measurement Method": "Incident log trend review",
          "Target": ">= 90% medium/high incidents closed within SLA",
          "Actual Result": "83%",
          "Period": "2026-08",
          "Owner": "Incident Manager",
          "Evidence Source": "Incident Log",
          "Review Frequency": "Monthly",
          "Status": "Below target",
          "Follow-up Action": "Close supplier incident after final report",
          "Evidence Reference": "IL-REVIEW-2026-08",
          "Notes": "One supplier incident open."
        },
        {
          "Metric ID": "MME-005",
          "Metric": "Evidence pack completeness",
          "Related Objective or Control": "ISO-005 / Clause 7.5",
          "Measurement Method": "Evidence log completeness check",
          "Target": ">= 95% complete before freeze",
          "Actual Result": "91%",
          "Period": "2026-Q3",
          "Owner": "Internal Auditor",
          "Evidence Source": "Evidence Log / Audit Pack Index",
          "Review Frequency": "Monthly during audit preparation",
          "Status": "In progress",
          "Follow-up Action": "Confirm two evidence records before freeze",
          "Evidence Reference": "ELAI-2026-Q3",
          "Notes": "ICL-006 freeze notice sent."
        },
        {
          "Metric ID": "MME-006",
          "Metric": "Critical supplier assurance evidence current",
          "Related Objective or Control": "ISO-006 / A.5.19-A.5.23",
          "Measurement Method": "Supplier inventory review",
          "Target": "100% current evidence for critical suppliers",
          "Actual Result": "5 of 6 suppliers current",
          "Period": "2026-Q3",
          "Owner": "Supplier Manager",
          "Evidence Source": "Supplier Inventory",
          "Review Frequency": "Quarterly",
          "Status": "In progress",
          "Follow-up Action": "Obtain CloudHost updated assurance pack",
          "Evidence Reference": "SINV-CLOUDHOST-2026-Q3",
          "Notes": "Contract addendum pending."
        }
      ],
      "contentType": "register_table"
    },
    {
      "id": "monitoring_review_decision",
      "title": "Monitoring review decision",
      "values": {
        "Review result": "Six metrics reviewed; three below target and three in progress with assigned actions.",
        "Metrics reviewed": 6,
        "Metrics on target": 0,
        "Metrics below target": 3,
        "Actions opened": "Training reminders, cloud admin access review, supplier incident closure and supplier evidence update",
        "Reviewed by": "ISMS Manager",
        "Decision date": "2026-08-29",
        "Evidence reference": "MME-REVIEW-2026-08"
      },
      "rows": [
        {
          "Field": "Review result",
          "Value": "Six metrics reviewed; three below target and three in progress with assigned actions."
        },
        {
          "Field": "Metrics reviewed",
          "Value": "6"
        },
        {
          "Field": "Metrics on target",
          "Value": "0"
        },
        {
          "Field": "Metrics below target",
          "Value": "3"
        },
        {
          "Field": "Actions opened",
          "Value": "Training reminders, cloud admin access review, supplier incident closure and supplier evidence update"
        },
        {
          "Field": "Reviewed by",
          "Value": "ISMS Manager"
        },
        {
          "Field": "Decision date",
          "Value": "2026-08-29"
        },
        {
          "Field": "Evidence reference",
          "Value": "MME-REVIEW-2026-08"
        }
      ],
      "contentType": "decision_table"
    },
    {
      "id": "external_references",
      "title": "References",
      "groups": [
        {
          "text": "Cite these sources from workshops and audits. This list names ISO clauses, book chapters and companion artifacts used by this file."
        },
        {
          "rows": [
            {
              "Kind": "ISO",
              "Reference": "ISO/IEC 27001:2022 9.1",
              "How this document uses it": "Normative source this artifact implements or cites.",
              "href": "https://www.iso.org/standard/82875.html"
            },
            {
              "Kind": "Book",
              "Reference": "Building the ISMS, Performance, Monitoring & Audit (Clause 9)",
              "How this document uses it": "Primary operating chapter for this companion artifact.",
              "href": "https://www.amazon.com/dp/9789908983448"
            },
            {
              "Kind": "Artifact",
              "Reference": "ISO Information Security Objectives (Building the ISMS, Information Security Policies & Risk Management)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/dp/9789908983448"
            },
            {
              "Kind": "Artifact",
              "Reference": "ARR Access Rights Register (Secure Engineering, Access Control & Identity Management)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/dp/9789908983455"
            },
            {
              "Kind": "Artifact",
              "Reference": "ELAI Evidence Log / Audit Pack Index (Implementation & Certification, Audit Process)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/s?k=ISO+27001+for+Software+Companies+Implementation+and+Certification"
            },
            {
              "Kind": "Artifact",
              "Reference": "EXR Exceptions Register (Implementation & Certification, Asset Management & Information Classification)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/s?k=ISO+27001+for+Software+Companies+Implementation+and+Certification"
            }
          ]
        }
      ],
      "contentType": "reference_table"
    }
  ],
  "enrichment": {
    "source": "Example.json",
    "method": "curated-json",
    "note": "Completes Example JSON with renderer-native sections and generalized groups; no mdSource helper fields."
  },
  "snapshotRef": {
    "snapshotId": "arcfield.platform.surv.2026-09-11",
    "schemaVersion": "evidenceSnapshot.v1"
  },
  "scenarioRef": {
    "githubIssue": 64,
    "crId": "CR-TYPE-ARCFIELD-001",
    "family": "Register",
    "role": "Operating sample of the 11 September 2026 freeze"
  }
}
