{
  "schemaVersion": "artifactDefinition.v2",
  "definitionId": "OS.artifactDefinition.v2",
  "artifactId": "OS",
  "title": "Organization Statement",
  "artifactType": "Statement",
  "format": "docx",
  "productTier": "Basic",
  "definitionRole": "contract",
  "sourceModel": {
    "body": "canonical human-readable template maintained in the Artifact Candidate page",
    "jsonDefinition": "machine-readable contract and validation model",
    "jsonExample": "curated realistic example data fixture"
  },
  "editorialStandard": {
    "purpose": "This statement is the freeze of ISMS accountability for a software company: named roles, decision rights, deputies, interfaces and gaps. It must let an auditor see who can be called for an outcome, and it must not duplicate IRAR, RACI or ISS.",
    "requiredEditorialElements": [
      "introduction as purpose prose (what it is, who needs it, how it links to IRAR, RACI, ISS); not a second table of contents",
      "scope in and out as a first-class group",
      "terms as a first-class group",
      "organizational context for a SaaS / cloud software company",
      "ISMS role model as a table with a how-to sentence",
      "decision authority",
      "deputies and escalation with a trigger table",
      "governance interfaces",
      "governance gaps with owner and due date",
      "cadence and triggers",
      "practical examples with a short how-to intro",
      "common pitfalls with a short how-to intro",
      "evidence expectations as interfaces to other artifacts",
      "external references (ISO catalogue hrefs, book chapter ids, companion artifacts)"
    ],
    "isoAnchors": [
      {
        "label": "ISO/IEC 27001:2022 5.3",
        "href": "https://www.iso.org/standard/82875.html",
        "role": "Assign and communicate information-security roles, responsibilities and authorities; Top Management must ensure they are assigned and communicated."
      },
      {
        "label": "ISO/IEC 27001:2022 5.1",
        "href": "https://www.iso.org/standard/82875.html",
        "role": "Leadership and commitment, including directing and supporting persons who contribute to ISMS effectiveness."
      },
      {
        "label": "ISO/IEC 27001:2022 4.1",
        "href": "https://www.iso.org/standard/82875.html",
        "role": "Organizational context that this statement makes operational for ISMS roles. Scope boundaries remain ISS."
      }
    ],
    "bookSources": [
      {
        "series": "ISO 27001 for Software Companies",
        "volume": 1,
        "volumeTitle": "Building the ISMS",
        "chapterId": "S-00-02-00",
        "chapterTitle": "Leadership & Management (Clause 5)",
        "primary": true,
        "role": "Roles, authorities and management commitment.",
        "href": "https://www.amazon.com/dp/9789908983448"
      },
      {
        "series": "ISO 27001 for Software Companies",
        "volume": 1,
        "volumeTitle": "Building the ISMS",
        "chapterId": "S-00-01-00",
        "chapterTitle": "Context of the Organization (Clause 4)",
        "primary": false,
        "role": "Context inputs that this statement must not hide.",
        "href": "https://www.amazon.com/dp/9789908983448"
      },
      {
        "series": "ISO 27001 for Software Companies",
        "volume": 2,
        "volumeTitle": "Implementation & Certification",
        "chapterId": "S-09-02-00",
        "chapterTitle": "Team, Roles & Responsibilities",
        "primary": false,
        "role": "Implementation role model for software-company teams.",
        "href": "https://www.amazon.com/s?k=ISO+27001+for+Software+Companies+Implementation+and+Certification"
      }
    ],
    "acronyms": [
      {
        "abbr": "CIA",
        "longForm": "Confidentiality, Integrity, and Availability"
      },
      {
        "abbr": "CI/CD",
        "longForm": "Continuous Integration / Continuous Delivery"
      },
      {
        "abbr": "HR",
        "longForm": "Human Resources"
      },
      {
        "abbr": "IRAR",
        "longForm": "ISMS Role Appointment Record"
      },
      {
        "abbr": "ISMS",
        "longForm": "Information Security Management System"
      },
      {
        "abbr": "ISS",
        "longForm": "ISMS Scope Statement"
      },
      {
        "abbr": "RACI",
        "longForm": "Responsible, Accountable, Consulted, Informed"
      },
      {
        "abbr": "RAMT",
        "longForm": "Risk Acceptance Minutes"
      },
      {
        "abbr": "SaaS",
        "longForm": "Software as a Service"
      },
      {
        "abbr": "CD",
        "longForm": "Continuous Delivery"
      },
      {
        "abbr": "CI",
        "longForm": "Continuous Integration"
      },
      {
        "abbr": "CICD",
        "longForm": "Continuous Integration / Continuous Delivery"
      },
      {
        "abbr": "EV",
        "longForm": "Extended Validation"
      },
      {
        "abbr": "GS",
        "longForm": "General Support"
      },
      {
        "abbr": "JSON",
        "longForm": "JavaScript Object Notation"
      },
      {
        "abbr": "OS",
        "longForm": "Operating System"
      }
    ],
    "must": [
      "Name ISMS roles as accountable owners, not team names.",
      "Require a deputy or escalation path for critical roles before absence can delay a security or audit decision.",
      "State the golden thread: this statement → IRAR appointments → RACI task split → ISS boundary. This file does not replace those records."
    ],
    "mustNot": [
      "Do not treat an organization chart as a substitute for ISMS role assignment.",
      "Do not copy IRAR rows or ISS exclusions into this statement.",
      "Do not replace this artifact's function with a shared family skeleton (operating_rules, systems_and_records)."
    ],
    "softwareCompanyAdaptations": [
      "Write interfaces for CI/CD, monitoring, customer support and critical SaaS suppliers, not only office functions.",
      "Use Arcfield as the worked example (cover variant A).",
      "Keep the statement short. IRAR cites this Document Control version; it does not copy the role model."
    ],
    "exampleBody": {
      "sectionId": "statement_content",
      "workedExampleOrg": "Arcfield",
      "minBodyWords": 400,
      "requiredGroups": [
        {
          "id": "introduction",
          "heading": "What this statement is",
          "mustInclude": [
            "not an organization chart, RACI or ISS",
            "who uses it",
            "golden thread to IRAR, RACI, ISS",
            "cite Document Control version"
          ]
        },
        {
          "id": "scope",
          "heading": "Scope",
          "mustInclude": [
            "scope in and out as a table with a how-to sentence"
          ]
        },
        {
          "id": "terms",
          "heading": "Terms used here",
          "mustInclude": [
            "accountable owner",
            "deputy",
            "authority",
            "interface"
          ]
        },
        {
          "id": "context",
          "heading": "Organizational context",
          "mustInclude": [
            "SaaS",
            "cloud",
            "remote work"
          ]
        },
        {
          "id": "role_model",
          "heading": "ISMS role model",
          "mustInclude": [
            "Top Management",
            "ISMS Manager",
            "how-to sentence before the table"
          ]
        },
        {
          "id": "decision_authority",
          "heading": "Decision authority",
          "mustInclude": [
            "ISMS Manager coordinates",
            "owners remain accountable"
          ]
        },
        {
          "id": "deputies_and_escalation",
          "heading": "Deputies and escalation",
          "mustInclude": [
            "deputy or escalation before absence delays a decision"
          ]
        },
        {
          "id": "governance_interfaces",
          "heading": "Governance interfaces",
          "mustInclude": [
            "supplier",
            "engineering or CI/CD"
          ]
        },
        {
          "id": "gaps_and_improvement",
          "heading": "Governance gaps",
          "mustInclude": [
            "owner and due date"
          ]
        },
        {
          "id": "cadence_and_triggers",
          "heading": "Cadence and triggers",
          "mustInclude": [
            "annual review",
            "joiner/mover/leaver",
            "scope change"
          ]
        }
      ],
      "requiredSections": [
        {
          "id": "change_log",
          "title": "Revision history",
          "role": "Versioned freeze log with how-to sentence and rows Version, Date, Change, Approved by. Last Version matches title_page.values.Version."
        },
        {
          "id": "external_references",
          "title": "References",
          "role": "ISO clauses, book chapters and companion artifacts. Not a series catalogue."
        }
      ]
    }
  },
  "sections": [
    {
      "order": 1,
      "id": "title_page",
      "title": "Title Page",
      "contentType": "metadata",
      "required": true
    },
    {
      "order": 2,
      "id": "abstract",
      "title": "Abstract",
      "contentType": "narrative",
      "required": true,
      "hint": {
        "text": "Apply Abstract with named owners, systems and exportable evidence. Do not leave this chapter as a heading plus a bare table.",
        "bookReference": "Volume 1, S-00-02-00 Leadership & Management (Clause 5)"
      }
    },
    {
      "order": 3,
      "id": "document_control",
      "title": "Document Control",
      "contentType": "control_table",
      "required": true
    },
    {
      "order": 4,
      "id": "change_log",
      "title": "Revision history",
      "contentType": "revision_table",
      "required": true
    },
    {
      "order": 5,
      "id": "instructions",
      "title": "Instructions",
      "contentType": "ordered_list",
      "required": true,
      "hint": {
        "text": "Apply Instructions with named owners, systems and exportable evidence. Do not leave this chapter as a heading plus a bare table.",
        "bookReference": "Volume 1, S-00-02-00 Leadership & Management (Clause 5)"
      }
    },
    {
      "order": 6,
      "id": "statement_content",
      "title": "Organization statement",
      "contentType": "statement_sections",
      "required": true,
      "hint": {
        "text": "Apply Organization statement with named owners, systems and exportable evidence. Do not leave this chapter as a heading plus a bare table.",
        "bookReference": "Volume 1, S-00-02-00 Leadership & Management (Clause 5)"
      }
    },
    {
      "order": 9,
      "id": "evidence_and_records",
      "title": "Evidence and records",
      "contentType": "evidence_table",
      "required": true,
      "hint": {
        "text": "Apply Evidence and records with named owners, systems and exportable evidence. Do not leave this chapter as a heading plus a bare table.",
        "bookReference": "Volume 1, S-00-02-00 Leadership & Management (Clause 5)"
      }
    },
    {
      "order": 10,
      "id": "external_references",
      "title": "References",
      "contentType": "reference_table",
      "required": true,
      "hint": {
        "text": "Apply References with named owners, systems and exportable evidence. Do not leave this chapter as a heading plus a bare table.",
        "bookReference": "Volume 1, S-00-02-00 Leadership & Management (Clause 5)"
      }
    }
  ],
  "validationRules": [
    "JSON Example must contain definitionRef pointing to OS.artifactDefinition.v2.",
    "Body must define organization context, ISMS roles, authorities, deputies, governance interfaces, gaps and evidence.",
    "No legacy MD references or standalone Book reference section allowed."
  ],
  "enrichment": {
    "source": "Contract.json",
    "method": "curated-json",
    "note": "Completes Contract JSON from MD-only schema/sections, removes duplicate alias sections, and normalizes string columns into structured column objects."
  },
  "editorialContractId": "editorial.docx.statement.v1",
  "contentContractId": "content.literary.v1",
  "relations": [
    {
      "kind": "cites",
      "artifactId": "MDR",
      "role": "evidence_register",
      "expectedType": "Register",
      "rank": 1
    },
    {
      "kind": "cites",
      "artifactId": "DR",
      "role": "evidence_register",
      "expectedType": "Register",
      "rank": 2
    },
    {
      "kind": "cites",
      "artifactId": "UAI",
      "role": "evidence_register",
      "expectedType": "Inventory",
      "rank": 3
    },
    {
      "kind": "cites",
      "artifactId": "AI",
      "role": "inventory",
      "expectedType": "Inventory",
      "rank": 20
    },
    {
      "kind": "cites",
      "artifactId": "SINV",
      "role": "inventory",
      "expectedType": "Inventory",
      "rank": 21
    }
  ]
}
