{
  "schemaVersion": "artifactDefinition.v2",
  "definitionId": "OPC.artifactDefinition.v2",
  "artifactId": "OPC",
  "title": "Operational Planning and Control Evidence",
  "artifactType": "Register",
  "format": "xlsx",
  "productTier": "Premium",
  "definitionRole": "contract",
  "sourceModel": {
    "body": "canonical human-readable register maintained in the Artifact Candidate page",
    "jsonDefinition": "machine-readable contract and validation model",
    "jsonExample": "curated realistic example data fixture"
  },
  "purpose": "Define the required structure for demonstrating operational planning and control of ISMS processes, including planned activities, owners, criteria, evidence, deviations and follow-up actions.",
  "sections": [
    {
      "order": 1,
      "id": "title_page",
      "title": "Title Page",
      "contentType": "metadata",
      "required": true,
      "hint": null
    },
    {
      "order": 2,
      "id": "abstract",
      "title": "Abstract",
      "contentType": "narrative",
      "required": true,
      "hint": {
        "text": "Use OPC to prove that ISMS processes are planned, operated, monitored and adjusted in a controlled way.",
        "bookReference": "Volume 1, S-00-03-00 Planning, Risk & Objectives (Clause 6"
      }
    },
    {
      "order": 3,
      "id": "document_control",
      "title": "Document Control",
      "contentType": "control_table",
      "required": true,
      "hint": null
    },
    {
      "order": 4,
      "id": "instructions",
      "title": "Instructions",
      "contentType": "ordered_list",
      "required": true,
      "hint": {
        "text": "Record recurring ISMS operations with defined criteria, evidence expectations and escalation routes for deviations.",
        "bookReference": "Volume 1, S-00-03-00 Planning, Risk & Objectives (Clause 6"
      },
      "intro": "Complete the Working sheets using the example tabs as a model. Follow the workbook usage rules below."
    },
    {
      "order": 5,
      "id": "operational_control_register",
      "title": "Operational control register",
      "contentType": "register_table",
      "required": true,
      "minimumExampleRows": 6,
      "columns": [
        {
          "name": "Control Activity ID",
          "type": "text",
          "required": "yes",
          "description": "Unique operational activity identifier.",
          "example": "OPC-001"
        },
        {
          "name": "Operational Activity",
          "type": "text",
          "required": "yes",
          "description": "Activity being performed.",
          "example": "Access review"
        },
        {
          "name": "Related Clause or Control",
          "type": "text",
          "required": "yes",
          "description": "ISO clause or Annex A control.",
          "example": "A.8.2"
        },
        {
          "name": "Planned Frequency",
          "type": "text",
          "required": "yes",
          "description": "Planned cadence.",
          "example": "Monthly"
        },
        {
          "name": "Control Criteria",
          "type": "text",
          "required": "yes",
          "description": "Criteria used to judge completion.",
          "example": "All accounts reviewed"
        },
        {
          "name": "Owner",
          "type": "select",
          "required": "yes",
          "description": "Accountable owner.",
          "example": "IT Operations Manager",
          "valueSet": "domain.owner",
          "options": [
            "ISMS Manager",
            "Control Owner",
            "Risk Owner",
            "Process Owner",
            "Asset Owner",
            "IT Security",
            "HR",
            "Legal",
            "Executive Management",
            "Internal Audit"
          ],
          "validation": {
            "allowBlank": false,
            "errorTitle": "Invalid value",
            "error": "Select a value from the list."
          }
        },
        {
          "name": "Evidence Produced",
          "type": "text",
          "required": "yes",
          "description": "Evidence output.",
          "example": "Access review register"
        },
        {
          "name": "Last Performed Date",
          "type": "date",
          "required": "yes",
          "description": "Last performance date.",
          "example": "2026-08-28"
        },
        {
          "name": "Result",
          "type": "text",
          "required": "yes",
          "description": "Result summary.",
          "example": "Partially completed"
        },
        {
          "name": "Deviation or Issue",
          "type": "text",
          "required": "no",
          "description": "Issue or deviation.",
          "example": "Review pending"
        },
        {
          "name": "Follow-up Action",
          "type": "text",
          "required": "no",
          "description": "Required follow-up.",
          "example": "Complete review"
        },
        {
          "name": "Next Due Date",
          "type": "date",
          "required": "yes",
          "description": "Next activity or follow-up date.",
          "example": "2026-09-05"
        },
        {
          "name": "Evidence Reference",
          "type": "text",
          "required": "yes",
          "description": "Evidence record.",
          "example": "ARR-2026-08"
        },
        {
          "name": "Status",
          "type": "select",
          "required": "yes",
          "description": "Active, in progress, completed or open follow-up.",
          "example": "Open follow-up",
          "valueSet": "domain.status.generic",
          "options": [
            "Draft",
            "In Progress",
            "Under Review",
            "Approved",
            "Closed",
            "Deferred"
          ],
          "validation": {
            "allowBlank": false,
            "errorTitle": "Invalid value",
            "error": "Select a value from the list."
          }
        },
        {
          "name": "Notes",
          "type": "text",
          "required": "no",
          "description": "Additional context.",
          "example": "Management visibility required."
        }
      ],
      "hint": {
        "text": "Each row should show what operation is performed, which criteria apply, what evidence is produced and how deviations are handled.",
        "bookReference": "Volume 1, S-00-03-00 Planning, Risk & Objectives (Clause 6"
      }
    },
    {
      "order": 6,
      "id": "operational_review_decision",
      "title": "Operational review decision",
      "contentType": "decision_table",
      "required": true,
      "fields": [
        {
          "name": "Review result",
          "type": "select",
          "required": "yes",
          "valueSet": "domain.reviewResult",
          "options": [
            "Pass",
            "Pass with observations",
            "Fail",
            "Deferred"
          ],
          "validation": {
            "allowBlank": false,
            "errorTitle": "Invalid value",
            "error": "Select a value from the list."
          }
        },
        {
          "name": "Activities reviewed",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Activities on schedule",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Deviations open",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Follow-up actions open",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Reviewed by",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Decision date",
          "type": "date",
          "required": "yes"
        },
        {
          "name": "Evidence reference",
          "type": "text",
          "required": "yes"
        }
      ],
      "hint": {
        "text": "Close with a review decision so operational deviations feed corrective action and management review.",
        "bookReference": "Volume 1, S-00-03-00 Planning, Risk & Objectives (Clause 6"
      }
    },
    {
      "order": 7,
      "id": "external_references",
      "title": "References",
      "contentType": "reference_table",
      "required": true
    }
  ],
  "validationRules": [
    "JSON Example must contain definitionRef pointing to OPC.artifactDefinition.v2.",
    "JSON Example register sections must contain schemaRef pointing to the matching definition section.",
    "Rows must include operational activity, related clause or control, criteria, owner, evidence, result, next due date and status.",
    "Body must render the contract schema and the example data.",
    "No standalone Book reference section and no generic Sample placeholders are allowed."
  ],
  "enrichment": {
    "source": "Contract.json",
    "method": "curated-json",
    "note": "Completes Contract JSON from MD-only schema/sections, removes duplicate alias sections, and normalizes string columns into structured column objects."
  },
  "editorialStandard": {
    "isoAnchors": [
      {
        "label": "ISO/IEC 27001:2022 8.1",
        "href": "https://www.iso.org/standard/82875.html",
        "role": "Normative source this artifact implements or cites."
      },
      {
        "label": "ISO/IEC 27001:2022 7.5",
        "href": "https://www.iso.org/standard/82875.html",
        "role": "Documented information: identify, review and cite this workbook by version."
      }
    ],
    "bookSources": [
      {
        "series": "ISO 27001 for Software Companies",
        "volume": 1,
        "volumeTitle": "Building the ISMS",
        "chapterId": "S-00-03-00",
        "chapterTitle": "Planning, Risk & Objectives (Clause 6",
        "primary": true,
        "role": "Primary operating chapter for this companion artifact.",
        "href": "https://www.amazon.com/dp/9789908983448"
      },
      {
        "series": "ISO 27001 for Software Companies",
        "volume": 1,
        "volumeTitle": "Building the ISMS",
        "chapterId": "S-02-01-00",
        "chapterTitle": "Information Security Policies & Risk Management",
        "primary": false,
        "role": "Policy framework and risk-based operation.",
        "href": "https://www.amazon.com/dp/9789908983448"
      }
    ],
    "acronyms": [
      {
        "abbr": "ISMS",
        "longForm": "Information Security Management System"
      },
      {
        "abbr": "SaaS",
        "longForm": "Software as a Service"
      },
      {
        "abbr": "CIA",
        "longForm": "Confidentiality, Integrity, and Availability"
      },
      {
        "abbr": "CI/CD",
        "longForm": "Continuous Integration / Continuous Delivery"
      },
      {
        "abbr": "CI",
        "longForm": "Continuous Integration"
      },
      {
        "abbr": "CD",
        "longForm": "Continuous Delivery"
      },
      {
        "abbr": "CL",
        "longForm": "Control Library"
      },
      {
        "abbr": "HR",
        "longForm": "Human Resources"
      },
      {
        "abbr": "IL",
        "longForm": "Impact Level"
      },
      {
        "abbr": "JSON",
        "longForm": "JavaScript Object Notation"
      }
    ],
    "must": [
      "Keep one live row per record on Working sheets. Do not merge several cases into one row.",
      "Example sheets must contain realistic Arcfield rows for every required sheet. Empty required cells are not an example."
    ],
    "mustNot": [
      "Do not invent live rows in the renderer. Example data lives in the Example JSON.",
      "Do not treat Ex example tabs as working sheets. Do not put live data on system sheets."
    ],
    "softwareCompanyAdaptations": [
      "Use Arcfield as the worked example (cover variant A).",
      "Name SaaS, CI/CD, privileged access or supplier interfaces in example rows where they affect this register."
    ],
    "exampleWorkbook": {
      "workedExampleOrg": "Arcfield",
      "requiredSheets": [
        "operational_control_register",
        "operational_review_decision"
      ],
      "minExampleRows": 6,
      "coverFromExample": true
    }
  },
  "editorialContractId": "editorial.xlsx.register.v1",
  "contentContractId": "content.register.items.v1"
}
