{
  "schemaVersion": "artifactExample.v2",
  "artifactId": "OPC",
  "title": "Operational Planning and Control Evidence",
  "definitionRef": {
    "artifactId": "OPC",
    "definitionSchemaVersion": "artifactDefinition.v2",
    "definitionId": "OPC.artifactDefinition.v2",
    "title": "Operational Planning and Control Evidence"
  },
  "organization": "Arcfield",
  "sections": [
    {
      "id": "title_page",
      "title": "Title Page",
      "values": {
        "Register Title": "Operational Planning and Control Evidence",
        "Register ID": "OPC-REG-001",
        "Version": "1.1",
        "Status": "Approved",
        "Organization": "Arcfield",
        "Owner": "ISMS Manager",
        "Approver": "Top Management",
        "Classification": "Internal",
        "Effective Date": "2026-09-11",
        "Next Review Date": "2027-09-11"
      },
      "items": [
        "Register Title: Operational Planning and Control Evidence",
        "Register ID: OPC-REG-001",
        "Version: 1.1",
        "Status: Approved",
        "Organization: Arcfield",
        "Owner: ISMS Manager",
        "Approver: Top Management",
        "Classification: Internal",
        "Effective Date: 2026-09-11",
        "Next Review Date: 2027-09-11"
      ],
      "contentType": "metadata"
    },
    {
      "id": "abstract",
      "title": "Abstract",
      "text": "This example demonstrates Arcfield operational planning and control for recurring ISMS activities, including criteria, owners, evidence, results, deviations, follow-up actions and review decisions. Rows are the 11 September 2026 operating sample of the certified Arcfield Platform ISMS in the surveillance cycle after certificate ARC-ISMS-2025-001.",
      "contentType": "narrative"
    },
    {
      "id": "document_control",
      "title": "Document Control",
      "rows": [
        {
          "Property": "Purpose",
          "Value": "Evidence operational planning and control of ISMS activities."
        },
        {
          "Property": "Used by",
          "Value": "ISMS Manager, Control Owners, Process Owners, Internal Auditor"
        },
        {
          "Property": "Maintained by",
          "Value": "ISMS Manager"
        },
        {
          "Property": "Evidence role",
          "Value": "Clause 8.1 operation and control evidence"
        },
        {
          "Property": "ISO reference",
          "Value": "ISO/IEC 27001:2022 Clause 8.1, Clause 9.1 and Clause 10.2"
        },
        {
          "Property": "Review cadence",
          "Value": "Monthly and before management review"
        }
      ],
      "contentType": "control_table"
    },
    {
      "id": "instructions",
      "title": "Instructions",
      "items": [
        "Identify recurring or event-driven ISMS operational activities.",
        "Define the applicable criteria, frequency and accountable owner.",
        "Record evidence produced by each activity.",
        "Capture deviations, issues and follow-up actions.",
        "Link evidence references and next due dates.",
        "Review open deviations before management review.",
        "Use sheets ending in “Ex” as read-only examples. Enter live data only on the matching “Wk” (Working) sheets.",
        "Every operative list is an Excel Table with frozen headers and filters. Add new rows on the next empty worksheet row beneath the table so Excel expands it — do not leave blank rows inside the table.",
        "Where a column offers a dropdown, choose a value from the list (Status, Owner role, Priority, Severity, Likelihood, Impact, Applicability, Evidence Status, Review Result). Do not invent free-text variants.",
        "Enter dates as YYYY-MM-DD. Date columns are validated and formatted accordingly.",
        "Review the Flag columns (Overdue, Review Due, Missing Owner, Missing Evidence). They calculate automatically and highlight gaps for follow-up.",
        "Keep Cover, Legal, Book, Lists and Metadata unchanged. System sheets are protected on purpose."
      ],
      "contentType": "ordered_list"
    },
    {
      "id": "operational_control_register",
      "title": "Operational control register",
      "schemaRef": {
        "definitionId": "OPC.artifactDefinition.v2",
        "sectionId": "operational_control_register",
        "columnsRef": "sections.operational_control_register.columns"
      },
      "rows": [
        {
          "Control Activity ID": "OPC-001",
          "Operational Activity": "Monthly privileged access review",
          "Related Clause or Control": "A.8.2",
          "Planned Frequency": "Monthly",
          "Control Criteria": "All privileged accounts for critical systems are reviewed by system owners.",
          "Owner": "IT Operations Manager",
          "Evidence Produced": "Access Review Register update",
          "Last Performed Date": "2026-08-28",
          "Result": "Partially completed",
          "Deviation or Issue": "Cloud admin review pending",
          "Follow-up Action": "Complete cloud admin review and close EXR-001",
          "Next Due Date": "2026-09-05",
          "Evidence Reference": "ARR-2026-08",
          "Status": "Open follow-up",
          "Notes": "Management visibility required."
        },
        {
          "Control Activity ID": "OPC-002",
          "Operational Activity": "Supplier assurance evidence review",
          "Related Clause or Control": "A.5.19-A.5.23",
          "Planned Frequency": "Quarterly",
          "Control Criteria": "Critical suppliers have current security evidence and contractual commitments.",
          "Owner": "Supplier Manager",
          "Evidence Produced": "Supplier inventory and assessment update",
          "Last Performed Date": "2026-08-15",
          "Result": "Partially completed",
          "Deviation or Issue": "CloudHost notification addendum pending",
          "Follow-up Action": "Track addendum through LRR and EXR",
          "Next Due Date": "2026-09-10",
          "Evidence Reference": "SINV-CLOUDHOST-2026-Q3",
          "Status": "Open follow-up",
          "Notes": "Related to LRR-005."
        },
        {
          "Control Activity ID": "OPC-003",
          "Operational Activity": "Incident log review",
          "Related Clause or Control": "A.5.24-A.5.28",
          "Planned Frequency": "Weekly for open incidents",
          "Control Criteria": "Open incidents have owner, status, evidence and closure plan.",
          "Owner": "Incident Manager",
          "Evidence Produced": "Incident review decision",
          "Last Performed Date": "2026-08-29",
          "Result": "Completed",
          "Deviation or Issue": "Supplier final report pending",
          "Follow-up Action": "Follow up with Supplier Manager",
          "Next Due Date": "2026-09-06",
          "Evidence Reference": "IL-REVIEW-2026-08",
          "Status": "In progress",
          "Notes": "One supplier incident remains open."
        },
        {
          "Control Activity ID": "OPC-004",
          "Operational Activity": "Evidence pack completeness review",
          "Related Clause or Control": "Clause 7.5 and Clause 9.2",
          "Planned Frequency": "Monthly during audit preparation",
          "Control Criteria": "Evidence records have owner, status, source and review date.",
          "Owner": "Internal Auditor",
          "Evidence Produced": "Evidence Log / Audit Pack Index",
          "Last Performed Date": "2026-08-29",
          "Result": "In progress",
          "Deviation or Issue": "Two evidence records need confirmation",
          "Follow-up Action": "Confirm ELAI-004 and ELAI-006 before freeze",
          "Next Due Date": "2026-09-05",
          "Evidence Reference": "ELAI-2026-Q3",
          "Status": "In progress",
          "Notes": "ICL freeze notice sent."
        },
        {
          "Control Activity ID": "OPC-005",
          "Operational Activity": "Security awareness completion review",
          "Related Clause or Control": "Clause 7.2 and A.6.3",
          "Planned Frequency": "Monthly",
          "Control Criteria": "Training completion rate reaches target and late completion is followed up.",
          "Owner": "HR Manager",
          "Evidence Produced": "Training report and reminder log",
          "Last Performed Date": "2026-08-29",
          "Result": "Below target",
          "Deviation or Issue": "Two contractor acknowledgements pending",
          "Follow-up Action": "Send reminder and report completion in MME",
          "Next Due Date": "2026-09-03",
          "Evidence Reference": "TR-2026-Q3",
          "Status": "Open follow-up",
          "Notes": "Related to ISO-001."
        },
        {
          "Control Activity ID": "OPC-006",
          "Operational Activity": "Change impact review for ISMS changes",
          "Related Clause or Control": "Clause 6.3 and Clause 8.1",
          "Planned Frequency": "Per ISMS change",
          "Control Criteria": "ISMS changes have reason, consequences, owner, approval and effectiveness review.",
          "Owner": "ISMS Manager",
          "Evidence Produced": "ISMS Change Log entry",
          "Last Performed Date": "2026-08-29",
          "Result": "Completed",
          "Deviation or Issue": "Effectiveness reviews pending for open changes",
          "Follow-up Action": "Review in next management review",
          "Next Due Date": "2026-11-12",
          "Evidence Reference": "ISMS-CL-REVIEW-2026-Q3",
          "Status": "Active",
          "Notes": "Scope change under implementation."
        }
      ],
      "contentType": "register_table"
    },
    {
      "id": "operational_review_decision",
      "title": "Operational review decision",
      "values": {
        "Review result": "Six operational activities reviewed; four have follow-up actions and no uncontrolled deviation was accepted.",
        "Activities reviewed": 6,
        "Activities on schedule": 2,
        "Deviations open": 4,
        "Follow-up actions open": 4,
        "Reviewed by": "ISMS Manager",
        "Decision date": "2026-08-29",
        "Evidence reference": "OPC-REVIEW-2026-08"
      },
      "rows": [
        {
          "Field": "Review result",
          "Value": "Six operational activities reviewed; four have follow-up actions and no uncontrolled deviation was accepted."
        },
        {
          "Field": "Activities reviewed",
          "Value": "6"
        },
        {
          "Field": "Activities on schedule",
          "Value": "2"
        },
        {
          "Field": "Deviations open",
          "Value": "4"
        },
        {
          "Field": "Follow-up actions open",
          "Value": "4"
        },
        {
          "Field": "Reviewed by",
          "Value": "ISMS Manager"
        },
        {
          "Field": "Decision date",
          "Value": "2026-08-29"
        },
        {
          "Field": "Evidence reference",
          "Value": "OPC-REVIEW-2026-08"
        }
      ],
      "contentType": "decision_table"
    },
    {
      "id": "external_references",
      "title": "References",
      "groups": [
        {
          "text": "Cite these sources from workshops and audits. This list names ISO clauses, book chapters and companion artifacts used by this file."
        },
        {
          "rows": [
            {
              "Kind": "ISO",
              "Reference": "ISO/IEC 27001:2022 8.1",
              "How this document uses it": "Normative source this artifact implements or cites.",
              "href": "https://www.iso.org/standard/82875.html"
            },
            {
              "Kind": "Book",
              "Reference": "Building the ISMS, Planning, Risk & Objectives (Clause 6)",
              "How this document uses it": "Primary operating chapter for this companion artifact.",
              "href": "https://www.amazon.com/dp/9789908983448"
            },
            {
              "Kind": "Artifact",
              "Reference": "ELAI Evidence Log / Audit Pack Index (Implementation & Certification, Audit Process)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/s?k=ISO+27001+for+Software+Companies+Implementation+and+Certification"
            },
            {
              "Kind": "Artifact",
              "Reference": "ISO Information Security Objectives (Building the ISMS, Information Security Policies & Risk Management)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/dp/9789908983448"
            },
            {
              "Kind": "Artifact",
              "Reference": "EXR Exceptions Register (Implementation & Certification, Asset Management & Information Classification)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/s?k=ISO+27001+for+Software+Companies+Implementation+and+Certification"
            },
            {
              "Kind": "Artifact",
              "Reference": "LRR Legal, Regulatory and Contractual Requirements Register (Building the ISMS, Legal, Regulatory & Contractual Requirements)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/dp/9789908983448"
            }
          ]
        }
      ],
      "contentType": "reference_table"
    }
  ],
  "enrichment": {
    "source": "Example.json",
    "method": "curated-json",
    "note": "Completes Example JSON with renderer-native sections and generalized groups; no mdSource helper fields."
  },
  "snapshotRef": {
    "snapshotId": "arcfield.platform.surv.2026-09-11",
    "schemaVersion": "evidenceSnapshot.v1"
  },
  "scenarioRef": {
    "githubIssue": 64,
    "crId": "CR-TYPE-ARCFIELD-001",
    "family": "Register",
    "role": "Operating sample of the 11 September 2026 freeze"
  }
}
