{
  "schemaVersion": "artifactExample.v2",
  "artifactId": "OS",
  "title": "Organization Statement",
  "definitionRef": {
    "artifactId": "OS",
    "definitionSchemaVersion": "artifactDefinition.v2",
    "definitionId": "OS.artifactDefinition.v2",
    "title": "Organization Statement"
  },
  "organization": "Arcfield",
  "sections": [
    {
      "id": "title_page",
      "title": "Title Page",
      "values": {
        "Document Title": "Organization Statement",
        "Document ID": "ORG-STATEMENT-001",
        "Version": "1.1",
        "Status": "Approved",
        "Organization": "Arcfield",
        "Owner": "ISMS Manager",
        "Approver": "Top Management",
        "Classification": "Internal",
        "Effective Date": "2026-09-11",
        "Next Review Date": "2027-09-11"
      },
      "items": [
        "Document Title: Organization Statement",
        "Document ID: ORG-STATEMENT-001",
        "Version: 1.1",
        "Status: Approved",
        "Organization: Arcfield",
        "Owner: ISMS Manager",
        "Approver: Top Management",
        "Classification: Internal",
        "Effective Date: 2026-09-11",
        "Next Review Date: 2027-09-11"
      ],
      "contentType": "metadata"
    },
    {
      "id": "abstract",
      "title": "Abstract",
      "text": "This example describes Arcfield organizational context, ISMS roles, decision authorities, deputies, governance interfaces, gaps and evidence expectations for ISO 27001 accountability. This statement remains binding for the certified Arcfield Platform ISMS in the surveillance cycle after certificate ARC-ISMS-2025-001.",
      "contentType": "narrative"
    },
    {
      "id": "document_control",
      "title": "Document Control",
      "contentType": "control_table"
    },
    {
      "id": "change_log",
      "title": "Revision history",
      "groups": [
        {
          "text": "A published change is a new row. Do not edit an approved version in place."
        },
        {
          "rows": [
            {
              "Version": "1.0",
              "Date": "2026-08-29",
              "Change": "Initial Arcfield Platform publication.",
              "Approved by": "Top Management"
            },
            {
              "Version": "1.1",
              "Date": "2026-09-11",
              "Change": "Approved Arcfield worked example after the 11 September 2026 internal audit.",
              "Approved by": "Top Management"
            }
          ]
        }
      ],
      "contentType": "revision_table"
    },
    {
      "id": "instructions",
      "title": "Instructions",
      "groups": [
        {
          "text": "Copy this file as the controlled Word master for your ISMS. The Arcfield identity fields on the cover are the approved worked example. Complete the steps below when you adopt the file for your organization."
        },
        {
          "items": [
            "Fill the cover identity fields (Organization, Version, Classification, Owner, Approver, Effective Date and Next Review Date) when you adopt this file. The Arcfield values shown here are the approved worked example.",
            "Issue your own version and a new Revision history row. Do not edit an approved version in place.",
            "Cite this approved version from related records. Do not copy this file into those records."
          ]
        }
      ],
      "contentType": "ordered_list"
    },
    {
      "id": "statement_content",
      "title": "Organization statement",
      "groups": [
        {
          "id": "introduction",
          "heading": "What this statement is",
          "level": 1,
          "text": "This document is Arcfield's organization statement for the Information Security Management System (ISMS). It is the freeze of who is accountable for information security inside the approved ISMS scope: roles, decision rights, deputies, interfaces and the gaps that still need owners. It is not an organization chart, not a RACI matrix and not the ISMS Scope Statement. Top Management, the ISMS Manager, HR and audit use it to show that clause 5.3 assignments are named, accepted and current. The ISMS Role Appointment Record (IRAR) holds one row per key role. The RACI matrix splits tasks. The Scope Statement (ISS) sets the boundary. This file owns only the accountability model. Cite this Document Control version from those records. Do not copy these paragraphs into them."
        },
        {
          "id": "scope",
          "heading": "Scope",
          "level": 1,
          "text": "Use this table before you assign a role or exclude a function. If a decision can delay a security, privacy, customer or audit outcome, it belongs in this statement.",
          "rows": [
            {
              "In this statement": "ISMS roles, authorities, deputies, escalation paths and governance interfaces inside the approved ISMS scope.",
              "Not in this statement": "The ISMS boundary itself. That is ISS.",
              "Evidence reference": "OS-EV-2026-Q3",
              "Evidence status": "Complete"
            },
            {
              "In this statement": "Named accountability for information-security decisions, including when a role is vacant.",
              "Not in this statement": "HR job descriptions, employment contracts or salary bands. Those stay in HR records.",
              "Evidence reference": "OS-EV-2026-Q3",
              "Evidence status": "Complete"
            },
            {
              "In this statement": "Interfaces to engineering, support, suppliers and customers that affect CIA of in-scope services.",
              "Not in this statement": "The live appointment register. Individual signed appointments live in IRAR.",
              "Evidence reference": "OS-EV-2026-Q3",
              "Evidence status": "Complete"
            },
            {
              "In this statement": "Governance gaps that still lack an owner, due date or record.",
              "Not in this statement": "Corrective-action tracking. Open actions belong in the corrective-action register, citing this version.",
              "Evidence reference": "OS-EV-2026-Q3",
              "Evidence status": "Complete"
            }
          ]
        },
        {
          "id": "terms",
          "heading": "Terms used here",
          "level": 1,
          "text": "These terms are local to this statement. Expand every acronym on first use in the body.",
          "rows": [
            {
              "Term": "Accountable owner",
              "Meaning": "The named role that can be called in an audit for an outcome. A team name is not an owner."
            },
            {
              "Term": "Deputy",
              "Meaning": "A named person or role that can take the decision if the owner is unavailable, with a defined limit and record."
            },
            {
              "Term": "Authority",
              "Meaning": "What the role may approve, freeze, escalate or refuse without waiting for another signature."
            },
            {
              "Term": "Interface",
              "Meaning": "A hand-off where two roles share a system or supplier and must record who decides."
            }
          ]
        },
        {
          "id": "named_registers",
          "heading": "Systems, integrations and data",
          "level": 1,
          "text": "Related inventories live in the companion documents named below. This file cites them by their approved version. It does not copy their content.",
          "items": [
            "[Asset Inventory](AI_Asset_Inventory.xlsx) — In-scope assets with owner, classification, hosting, personal-data flag and related risk.",
            "[Supplier Inventory](SINV_Supplier_Inventory.xlsx) — Security-relevant suppliers with tier, due diligence, contract controls, subprocessors and exit planning."
          ],
          "ordered": true,
          "relationView": "inventory"
        },
        {
          "id": "context",
          "heading": "Organizational context",
          "level": 1,
          "text": "Arcfield is a B2B SaaS company of about 180 people, including about 35 engineers and a 6-person SRE/IT/Cloud function. It operates Arcfield Platform — one main multi-tenant product plus four supporting services — for regulated fintech and health customers in the EU and UK. Production is cloud-native (Kubernetes) with managed databases and managed identity. Data in scope is customer PII and limited payment metadata; card data is not stored. Engineering, support, security, compliance and supplier-management functions all touch production systems, customer data, CI/CD, monitoring and evidence stores. Remote work and cloud operations mean accountability cannot wait for a site manager. Top Management therefore assigns ISMS responsibilities by role, not by office location, and funds the competence and records those roles need. This statement is reviewed when the approved ISMS scope changes, when a key person joins, moves or leaves, and at least annually. The cyber insurer (Northbridge Cyber (worked example)) is an interested party for residual-risk transfer; CYB-CLM-2026-001 was denied and does not reduce Arcfield accountability."
        },
        {
          "id": "role_model",
          "heading": "ISMS role model",
          "level": 1,
          "text": "Keep one accountable owner per row. If two people share a system, record the interface rather than listing a team as owner. Appointments themselves are IRAR rows that cite this Document Control version.",
          "rows": [
            {
              "Role": "Top Management",
              "Accountability": "Approve this statement, the Information Security Policy and significant residual risk; provide resources; review ISMS performance.",
              "Authority": "Approve or refuse ISMS resource and residual-risk decisions that exceed the ISMS Manager's mandate.",
              "Appointment record": "IRAR",
              "Evidence reference": "IRAR"
            },
            {
              "Role": "ISMS Manager",
              "Accountability": "Coordinate the ISMS, keep this statement current, and report evidence readiness.",
              "Authority": "Freeze documented information versions; escalate overdue treatments and vacant critical roles.",
              "Appointment record": "IRAR",
              "Evidence reference": "IRAR"
            },
            {
              "Role": "Risk Manager",
              "Accountability": "Keep risk criteria, the risk register and treatment tracking comparable.",
              "Authority": "Require a RAMT for residual acceptance in the published bands.",
              "Appointment record": "IRAR",
              "Evidence reference": "IRAR"
            },
            {
              "Role": "Control Owner / Asset Owner / Process Owner",
              "Accountability": "Operate assigned controls or assets and produce exportable evidence.",
              "Authority": "Raise exceptions with expiry; cannot accept residual risk beyond the published band.",
              "Appointment record": "IRAR",
              "Evidence reference": "IRAR"
            },
            {
              "Role": "HR Manager",
              "Accountability": "Joiner, mover and leaver evidence that matches these role assignments.",
              "Authority": "Block access provisioning when an appointment or competence record is missing.",
              "Appointment record": "IRAR",
              "Evidence reference": "IRAR"
            }
          ]
        },
        {
          "id": "decision_authority",
          "heading": "Decision authority",
          "level": 1,
          "text": "The ISMS Manager coordinates. Control and risk owners remain accountable for assigned outcomes. Top Management does not delegate the approval of this statement, of the Information Security Policy, or of residual risk above the published acceptance band. Engineering may own CI/CD change, and Security may own monitoring rules; the interface and the decision split must be written here and reflected in RACI. If a decision can affect confidentiality, integrity or availability of in-scope customer services and no owner is named, the ISMS Manager escalates it to Top Management rather than leaving it as a team habit."
        },
        {
          "id": "deputies_and_escalation",
          "heading": "Deputies and escalation",
          "level": 1,
          "text": "Critical ISMS roles need a deputy or an escalation path before absence can delay a security, audit or customer-evidence decision. The deputy may take the same decision the owner could take, within a documented limit, and must record the substitution. If the ISMS Manager is unavailable during audit preparation, the named deputy decides on evidence release and the ISMS Manager is informed on return. Vacancy of Top Management's ISMS mandate escalates to the remaining Top Management members; it does not fall silently to engineering.",
          "rows": [
            {
              "If this is true": "Owner unavailable for more than two working days during an audit, incident or change freeze.",
              "Then": "Deputy acts and records the substitution in IRAR or the incident record.",
              "Escalate to": "ISMS Manager, then Top Management if the deputy limit is exceeded.",
              "Evidence reference": "OS-EV-2026-Q3",
              "Evidence status": "Complete"
            },
            {
              "If this is true": "A critical role has no deputy.",
              "Then": "Treat it as a governance gap with owner and due date.",
              "Escalate to": "Top Management if the gap remains at the next management review.",
              "Evidence reference": "OS-EV-2026-Q3",
              "Evidence status": "Complete"
            }
          ]
        },
        {
          "id": "governance_interfaces",
          "heading": "Governance interfaces",
          "level": 1,
          "text": "Supplier managers handle vendors; service owners accept operational risk for the service the supplier supports. Product engineering may own a pipeline while Security owns detection rules. Those splits are in scope for this statement. Customer and regulator interfaces belong here when they create evidence or decision duties. Do not assume an organization chart covers them. If an interface can change residual risk, name both sides and the record they share."
        },
        {
          "id": "gaps_and_improvement",
          "heading": "Governance gaps",
          "level": 1,
          "text": "A gap that is only described is not managed. Each gap needs an owner, a due date and a record in risk, corrective action or management review. Typical gaps are missing deputies, unclear CI/CD decision rights, and supplier interfaces with no service owner. The ISMS Manager reports open gaps at management review. Closing a gap does not edit this statement in place: publish a new Document Control version if the role model itself changes."
        },
        {
          "id": "cadence_and_triggers",
          "heading": "Cadence and triggers",
          "level": 1,
          "text": "Review this statement at least annually and whenever the ISMS scope, a key role-holder, a critical supplier or a major product line changes. Joiner, mover and leaver events that affect ISMS roles must update IRAR the same day and this statement at the next freeze if the role model changed. Do not wait for the annual cycle after an incident that revealed an unnamed decision right."
        },
        {
          "id": "operating_evidence_sample",
          "heading": "Operating evidence sample",
          "level": 1,
          "text": "These records can be retrieved for the 2026-08-29 Arcfield / Arcfield Platform freeze. They are the sample an auditor can re-perform. They are not a second register grid.",
          "rows": [
            {
              "Sample ID": "OS-EV-001",
              "What was sampled": "Signed ISMS Manager appointment (IRAR)",
              "Evidence reference": "IRAR-ISMS-MGR-2026"
            },
            {
              "Sample ID": "OS-EV-002",
              "What was sampled": "Signed Risk Manager appointment (IRAR)",
              "Evidence reference": "IRAR-RISK-MGR-2026"
            },
            {
              "Sample ID": "OS-EV-003",
              "What was sampled": "Top Management approval of this statement (DR / Document Control)",
              "Evidence reference": "OS-APPROVAL-2026-09-11"
            },
            {
              "Sample ID": "OS-EV-004",
              "What was sampled": "Deputy matrix for critical ISMS roles (IRAR)",
              "Evidence reference": "IRAR-DEPUTY-2026-Q3"
            },
            {
              "Sample ID": "OS-EV-005",
              "What was sampled": "Escalation used in Q3 management review (MRMT_Management_Review_Minutes.docx)",
              "Evidence reference": "MRMT-2026-Q3"
            }
          ]
        }
      ],
      "contentType": "statement_sections"
    },
    {
      "id": "evidence_and_records",
      "title": "Evidence and records",
      "groups": [
        {
          "text": "Related records live in the companion documents named below. This file cites them by their approved version. It does not copy their content. The Owner named on the cover is accountable for those live records."
        },
        {
          "items": [
            "[Mandatory Documents and Records Register](MDR_Mandatory_Documents_and_Records_Register.xlsx) — The 27 mandatory ISO 27001 documents and records, with owner, required status, approval, review cadence, location and evidence readiness.",
            "[Document Register](DR_Document_Register.xlsx) — Controlled documented information: origin, owner, approver, version, review cycle, retention and location.",
            "[Users and Access Inventory](UAI_Users_and_Access_Inventory.xlsx) — Users and accounts with access rights, privileged access, MFA status, reviews and revocations."
          ],
          "ordered": true,
          "relationView": "evidence"
        }
      ],
      "contentType": "evidence_table"
    },
    {
      "id": "external_references",
      "title": "References",
      "groups": [
        {
          "id": "linked_documents",
          "heading": "Linked documents",
          "level": 1,
          "text": "These companion files sit next to this document in the unpacked package. This file cites them by their approved version. It does not copy their content.",
          "rows": [
            {
              "Kind": "Artifact",
              "Reference": "MDR Mandatory Documents and Records Register",
              "How this document uses it": "The 27 mandatory ISO 27001 documents and records, with owner, required status, approval, review cadence, location and evidence readiness.",
              "href": "MDR_Mandatory_Documents_and_Records_Register.xlsx"
            },
            {
              "Kind": "Artifact",
              "Reference": "DR Document Register",
              "How this document uses it": "Controlled documented information: origin, owner, approver, version, review cycle, retention and location.",
              "href": "DR_Document_Register.xlsx"
            },
            {
              "Kind": "Artifact",
              "Reference": "UAI Users and Access Inventory",
              "How this document uses it": "Users and accounts with access rights, privileged access, MFA status, reviews and revocations.",
              "href": "UAI_Users_and_Access_Inventory.xlsx"
            },
            {
              "Kind": "Artifact",
              "Reference": "AI Asset Inventory",
              "How this document uses it": "In-scope assets with owner, classification, hosting, personal-data flag and related risk.",
              "href": "AI_Asset_Inventory.xlsx"
            },
            {
              "Kind": "Artifact",
              "Reference": "SINV Supplier Inventory",
              "How this document uses it": "Security-relevant suppliers with tier, due diligence, contract controls, subprocessors and exit planning.",
              "href": "SINV_Supplier_Inventory.xlsx"
            },
            {
              "Kind": "Artifact",
              "Reference": "IRAR ISMS Role Appointment Record (Building the ISMS, Leadership & Management (Clause 5))",
              "href": "IRAR_ISMS_Role_Appointment_Record_Register.xlsx",
              "How this document uses it": "One signed appointment per key role. Cite this Document Control version; do not copy the role model into IRAR."
            },
            {
              "Kind": "Artifact",
              "Reference": "ISS ISMS Scope Statement (Building the ISMS, Context of the Organization (Clause 4))",
              "href": "ISS_ISMS_Scope_Statement.docx",
              "How this document uses it": "Boundary of the ISMS. This statement does not set the scope."
            },
            {
              "Kind": "Artifact",
              "Reference": "RACI ISMS RACI Matrix (Building the ISMS, Leadership & Management (Clause 5))",
              "href": "RACI_ISMS_RACI_Matrix.xlsx",
              "How this document uses it": "Task split. This statement names accountable owners, not every RACI cell."
            }
          ]
        },
        {
          "id": "external_sources",
          "heading": "External references",
          "level": 1,
          "text": "Cite these ISO clauses and book chapters from workshops and audits.",
          "rows": [
            {
              "Kind": "ISO",
              "Reference": "ISO/IEC 27001:2022 5.3",
              "How this document uses it": "Named roles, responsibilities and authorities; Top Management ensures they are assigned and communicated.",
              "href": "https://www.iso.org/standard/82875.html"
            },
            {
              "Kind": "ISO",
              "Reference": "ISO/IEC 27001:2022 5.1",
              "How this document uses it": "Leadership commitment and support for persons who contribute to the ISMS.",
              "href": "https://www.iso.org/standard/82875.html"
            },
            {
              "Kind": "Book",
              "Reference": "Building the ISMS, Leadership & Management (Clause 5)",
              "How this document uses it": "Primary operating chapter for ISMS roles and authorities.",
              "href": "https://www.amazon.com/dp/9789908983448"
            },
            {
              "Kind": "Book",
              "Reference": "Building the ISMS, Context of the Organization (Clause 4)",
              "How this document uses it": "Context the role model must not hide.",
              "href": "https://www.amazon.com/dp/9789908983448"
            },
            {
              "Kind": "Book",
              "Reference": "Implementation & Certification, Team, Roles & Responsibilities",
              "How this document uses it": "Implementation role model for software-company teams.",
              "href": "https://www.amazon.com/s?k=ISO+27001+for+Software+Companies+Implementation+and+Certification"
            }
          ]
        }
      ],
      "contentType": "reference_table"
    }
  ],
  "enrichment": {
    "source": "Example.json",
    "method": "curated-json",
    "note": "Completes Example JSON with renderer-native sections and generalized groups; no mdSource helper fields."
  },
  "snapshotRef": {
    "snapshotId": "arcfield.platform.surv.2026-09-11",
    "schemaVersion": "evidenceSnapshot.v1"
  },
  "scenarioRef": {
    "githubIssue": 64,
    "crId": "CR-TYPE-ARCFIELD-001",
    "family": "Statement",
    "role": "Binding Arcfield Platform ISMS statement in the surveillance window"
  }
}
