{
  "schemaVersion": "artifactDefinition.v2",
  "definitionId": "RAE.artifactDefinition.v2",
  "artifactId": "RAE",
  "title": "Resource Allocation Evidence",
  "artifactType": "Register",
  "format": "xlsx",
  "productTier": "Premium",
  "definitionRole": "contract",
  "sourceModel": {
    "body": "canonical human-readable register maintained in the Artifact Candidate page",
    "jsonDefinition": "machine-readable contract and validation model",
    "jsonExample": "curated realistic example data fixture"
  },
  "purpose": "Define the required structure for evidencing that resources needed for ISMS establishment, operation, monitoring and improvement are identified, approved, assigned and reviewed.",
  "sections": [
    {
      "order": 1,
      "id": "title_page",
      "title": "Title Page",
      "contentType": "metadata",
      "required": true,
      "hint": null
    },
    {
      "order": 2,
      "id": "abstract",
      "title": "Abstract",
      "contentType": "narrative",
      "required": true,
      "hint": {
        "text": "Use RAE to prove that ISMS resource needs are visible, approved and tracked.",
        "bookReference": "Volume 1, S-00-04-00 Support & Resources (Clause 7)"
      }
    },
    {
      "order": 3,
      "id": "document_control",
      "title": "Document Control",
      "contentType": "control_table",
      "required": true,
      "hint": null
    },
    {
      "order": 4,
      "id": "instructions",
      "title": "Instructions",
      "contentType": "ordered_list",
      "required": true,
      "hint": {
        "text": "Record resource decisions with enough evidence to show that implementation constraints were managed.",
        "bookReference": "Volume 1, S-00-04-00 Support & Resources (Clause 7)"
      },
      "intro": "Complete the Working sheets using the example tabs as a model. Follow the workbook usage rules below."
    },
    {
      "order": 5,
      "id": "resource_allocation_register",
      "title": "Resource allocation register",
      "contentType": "register_table",
      "required": true,
      "minimumExampleRows": 6,
      "columns": [
        {
          "name": "Resource ID",
          "type": "text",
          "required": "yes",
          "description": "Unique resource record.",
          "example": "RAE-001"
        },
        {
          "name": "Resource Need",
          "type": "text",
          "required": "yes",
          "description": "Needed resource.",
          "example": "ISMS coordination capacity"
        },
        {
          "name": "Related ISMS Activity",
          "type": "text",
          "required": "yes",
          "description": "Linked activity.",
          "example": "Implementation plan"
        },
        {
          "name": "Resource Type",
          "type": "select",
          "required": "yes",
          "description": "People, tooling, budget, time or engineering capacity.",
          "example": "People"
        },
        {
          "name": "Owner",
          "type": "select",
          "required": "yes",
          "description": "Accountable owner.",
          "example": "ISMS Manager",
          "valueSet": "domain.owner",
          "options": [
            "ISMS Manager",
            "Control Owner",
            "Risk Owner",
            "Process Owner",
            "Asset Owner",
            "IT Security",
            "HR",
            "Legal",
            "Executive Management",
            "Internal Audit"
          ],
          "validation": {
            "allowBlank": false,
            "errorTitle": "Invalid value",
            "error": "Select a value from the list."
          }
        },
        {
          "name": "Requested By",
          "type": "text",
          "required": "yes",
          "description": "Requesting role.",
          "example": "Compliance Lead"
        },
        {
          "name": "Approval Role",
          "type": "text",
          "required": "yes",
          "description": "Approval authority.",
          "example": "Top Management"
        },
        {
          "name": "Decision",
          "type": "text",
          "required": "yes",
          "description": "Approval decision.",
          "example": "Approved"
        },
        {
          "name": "Allocated Resource",
          "type": "text",
          "required": "yes",
          "description": "Allocated resource.",
          "example": "0.5 FTE"
        },
        {
          "name": "Planned Date",
          "type": "date",
          "required": "yes",
          "description": "Planned allocation date.",
          "example": "2026-09-02"
        },
        {
          "name": "Actual Date",
          "type": "date",
          "required": "no",
          "description": "Actual allocation date.",
          "example": "2026-09-02"
        },
        {
          "name": "Evidence Reference",
          "type": "text",
          "required": "yes",
          "description": "Evidence record.",
          "example": "RAE-REVIEW-2026-Q3"
        },
        {
          "name": "Status",
          "type": "select",
          "required": "yes",
          "description": "Allocated, planned, scheduled, in progress or open.",
          "example": "Allocated",
          "valueSet": "domain.status.generic",
          "options": [
            "Draft",
            "In Progress",
            "Under Review",
            "Approved",
            "Closed",
            "Deferred"
          ],
          "validation": {
            "allowBlank": false,
            "errorTitle": "Invalid value",
            "error": "Select a value from the list."
          }
        },
        {
          "name": "Notes",
          "type": "text",
          "required": "no",
          "description": "Additional context.",
          "example": "Supports scope phase."
        }
      ],
      "hint": {
        "text": "Each row should show the ISMS need, decision, owner, allocated resource, timing and evidence.",
        "bookReference": "Volume 1, S-00-04-00 Support & Resources (Clause 7)"
      }
    },
    {
      "order": 6,
      "id": "resource_review_decision",
      "title": "Resource review decision",
      "contentType": "decision_table",
      "required": true,
      "fields": [
        {
          "name": "Review result",
          "type": "select",
          "required": "yes",
          "valueSet": "domain.reviewResult",
          "options": [
            "Pass",
            "Pass with observations",
            "Fail",
            "Deferred"
          ],
          "validation": {
            "allowBlank": false,
            "errorTitle": "Invalid value",
            "error": "Select a value from the list."
          }
        },
        {
          "name": "Resource items reviewed",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Approved items",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Open items",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Blocked items",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Reviewed by",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Decision date",
          "type": "date",
          "required": "yes"
        },
        {
          "name": "Evidence reference",
          "type": "text",
          "required": "yes"
        }
      ],
      "hint": {
        "text": "Close with a review decision so resource gaps are visible before they affect certification readiness.",
        "bookReference": "Volume 1, S-00-04-00 Support & Resources (Clause 7)"
      }
    },
    {
      "order": 7,
      "id": "external_references",
      "title": "References",
      "contentType": "reference_table",
      "required": true
    }
  ],
  "validationRules": [
    "JSON Example must contain definitionRef pointing to RAE.artifactDefinition.v2.",
    "JSON Example register sections must contain schemaRef pointing to the matching definition section.",
    "Rows must include resource need, related ISMS activity, owner, decision, allocated resource, dates, status and evidence reference.",
    "Body must render the contract schema and the example data.",
    "No standalone Book reference section and no generic Sample placeholders are allowed."
  ],
  "enrichment": {
    "source": "Contract.json",
    "method": "curated-json",
    "note": "Completes Contract JSON from MD-only schema/sections, removes duplicate alias sections, and normalizes string columns into structured column objects."
  },
  "editorialStandard": {
    "isoAnchors": [
      {
        "label": "ISO/IEC 27001:2022 7.1",
        "href": "https://www.iso.org/standard/82875.html",
        "role": "Normative source this artifact implements or cites."
      },
      {
        "label": "ISO/IEC 27001:2022 7.5",
        "href": "https://www.iso.org/standard/82875.html",
        "role": "Documented information: identify, review and cite this workbook by version."
      }
    ],
    "bookSources": [
      {
        "series": "ISO 27001 for Software Companies",
        "volume": 1,
        "volumeTitle": "Building the ISMS",
        "chapterId": "S-00-04-00",
        "chapterTitle": "Support & Resources (Clause 7)",
        "primary": true,
        "role": "Primary operating chapter for this companion artifact.",
        "href": "https://www.amazon.com/dp/9789908983448"
      },
      {
        "series": "ISO 27001 for Software Companies",
        "volume": 1,
        "volumeTitle": "Building the ISMS",
        "chapterId": "S-00-03-00",
        "chapterTitle": "Planning, Risk & Objectives (Clause 6)",
        "primary": false,
        "role": "Documented information, review and version discipline.",
        "href": "https://www.amazon.com/dp/9789908983448"
      }
    ],
    "acronyms": [
      {
        "abbr": "ISMS",
        "longForm": "Information Security Management System"
      },
      {
        "abbr": "SaaS",
        "longForm": "Software as a Service"
      },
      {
        "abbr": "CIA",
        "longForm": "Confidentiality, Integrity, and Availability"
      },
      {
        "abbr": "CI/CD",
        "longForm": "Continuous Integration / Continuous Delivery"
      },
      {
        "abbr": "CI",
        "longForm": "Continuous Integration"
      },
      {
        "abbr": "CD",
        "longForm": "Continuous Delivery"
      },
      {
        "abbr": "CHG",
        "longForm": "Change"
      },
      {
        "abbr": "COO",
        "longForm": "Chief Operating Officer"
      },
      {
        "abbr": "CTO",
        "longForm": "Chief Technology Officer"
      },
      {
        "abbr": "FTE",
        "longForm": "Full-Time Equivalent"
      },
      {
        "abbr": "JSON",
        "longForm": "JavaScript Object Notation"
      }
    ],
    "must": [
      "Keep one live row per record on Working sheets. Do not merge several cases into one row.",
      "Example sheets must contain realistic Arcfield rows for every required sheet. Empty required cells are not an example."
    ],
    "mustNot": [
      "Do not invent live rows in the renderer. Example data lives in the Example JSON.",
      "Do not treat Ex example tabs as working sheets. Do not put live data on system sheets."
    ],
    "softwareCompanyAdaptations": [
      "Use Arcfield as the worked example (cover variant A).",
      "Name SaaS, CI/CD, privileged access or supplier interfaces in example rows where they affect this register."
    ],
    "exampleWorkbook": {
      "workedExampleOrg": "Arcfield",
      "requiredSheets": [
        "resource_allocation_register",
        "resource_review_decision"
      ],
      "minExampleRows": 6,
      "coverFromExample": true
    }
  },
  "editorialContractId": "editorial.xlsx.register.v1",
  "contentContractId": "content.register.items.v1"
}
