{
  "schemaVersion": "artifactDefinition.v2",
  "definitionId": "RAM.artifactDefinition.v2",
  "artifactId": "RAM",
  "title": "Risk Assessment Methodology",
  "artifactType": "Methodology",
  "format": "docx",
  "productTier": "Basic",
  "definitionRole": "contract",
  "sourceModel": {
    "body": "canonical human-readable template maintained in the Artifact Candidate page",
    "jsonDefinition": "machine-readable contract and validation model",
    "jsonExample": "curated realistic example data fixture"
  },
  "editorialStandard": {
    "purpose": "This methodology document is the frozen rulebook for repeatable ISO/IEC 27001:2022 information-security risk assessment and treatment decisions. It must let a second assessor land in the same score band, and it must produce exportable records for scoring, treatment, residual-risk approval and evidence. It is a companion method for software companies, not a generic risk library and not a Statement of Applicability.",
    "requiredEditorialElements": [
      "introduction as purpose prose (what it is, who needs it, what it brings, how it links); not a second table of contents",
      "scope in and out as a first-class method group",
      "method terms as a first-class method group",
      "revision history with the current Document Control version",
      "scenario-based risk rule",
      "scoring calibration",
      "residual-risk approval model",
      "management escalation",
      "practical examples with a short how-to intro",
      "common pitfalls with a short how-to intro",
      "evidence expectations as interfaces to other artifacts",
      "external references (ISO catalogue hrefs, book chapter ids, companion artifacts)"
    ],
    "bookSources": [
      {
        "series": "ISO 27001 for Software Companies",
        "volume": 1,
        "volumeTitle": "Building the ISMS",
        "chapterId": "S-00-03-00",
        "chapterTitle": "Planning, Risk & Objectives (Clause 6)",
        "primary": false,
        "role": "Clause 6.1.2 method one-pager: impact and likelihood anchors, matrix thresholds, acceptance authority, comparable scores, register entry fields",
        "href": "https://www.amazon.com/dp/9789908983448"
      },
      {
        "series": "ISO 27001 for Software Companies",
        "volume": 2,
        "volumeTitle": "Implementation & Certification",
        "chapterId": "S-07-02-00",
        "chapterTitle": "Risk Assessment & Risk Treatment Process",
        "primary": true,
        "role": "Method freeze, scenario-first identification, residual acceptance with expiry and triggers, 80/20 software-company scenarios",
        "href": "https://www.amazon.com/s?k=ISO+27001+for+Software+Companies+Implementation+and+Certification"
      },
      {
        "series": "ISO 27001 for Software Companies",
        "volume": 1,
        "volumeTitle": "Building the ISMS",
        "chapterId": "S-02-01-00",
        "chapterTitle": "Information Security Policies & Risk",
        "primary": false,
        "role": "Area 2 six-step cycle (context, identify, analyse, evaluate, treat, monitor) and software-company change triggers",
        "href": "https://www.amazon.com/dp/9789908983448"
      }
    ],
    "isoAnchors": [
      {
        "label": "ISO/IEC 27001:2022 6.1.2",
        "href": "https://www.iso.org/standard/82875.html",
        "role": "define and apply a repeatable assessment method; establish criteria including acceptance criteria; identify CIA-related risks within the ISMS scope and their risk owners; analyse likelihood and impact; evaluate and prioritize against the criteria so repeated assessments stay consistent, valid and comparable"
      },
      {
        "label": "ISO/IEC 27001:2022 6.1.3",
        "href": "https://www.iso.org/standard/82875.html",
        "role": "select treatment options (modify, avoid, transfer, accept); obtain risk-owner approval of the treatment plan and of residual risk. Statement of Applicability and Annex A comparison are different artifacts, not this methodology"
      },
      {
        "label": "ISO/IEC 27005",
        "href": "https://www.iso.org/standard/80585.html",
        "role": "Background process language only. Not a second method."
      },
      {
        "label": "ISO 31000",
        "href": "https://www.iso.org/standard/65694.html",
        "role": "Background process language only. MAGERIT-style analysis belongs to RASM, not RAM"
      }
    ],
    "acronyms": [
      {
        "abbr": "BIA",
        "longForm": "Business Impact Analysis"
      },
      {
        "abbr": "CIA",
        "longForm": "Confidentiality, Integrity, and Availability"
      },
      {
        "abbr": "FAIR",
        "longForm": "Factor Analysis of Information Risk"
      },
      {
        "abbr": "ISMS",
        "longForm": "Information Security Management System"
      },
      {
        "abbr": "MAGERIT",
        "longForm": "Methodology for Information Systems Risk Analysis and Management"
      },
      {
        "abbr": "RAM",
        "longForm": "Risk Assessment Methodology"
      },
      {
        "abbr": "RAMT",
        "longForm": "Risk Acceptance Minutes"
      },
      {
        "abbr": "RASM",
        "longForm": "Risk Analysis Statement according to MAGERIT"
      },
      {
        "abbr": "RPO",
        "longForm": "Recovery Point Objective"
      },
      {
        "abbr": "RR",
        "longForm": "Risk Register"
      },
      {
        "abbr": "RTO",
        "longForm": "Recovery Time Objective"
      },
      {
        "abbr": "RTP",
        "longForm": "Risk Treatment Plan"
      },
      {
        "abbr": "SaaS",
        "longForm": "Software as a Service"
      },
      {
        "abbr": "SoA",
        "longForm": "Statement of Applicability"
      },
      {
        "abbr": "SRE",
        "longForm": "Site Reliability Engineering"
      },
      {
        "abbr": "CD",
        "longForm": "Continuous Delivery"
      },
      {
        "abbr": "CI",
        "longForm": "Continuous Integration"
      },
      {
        "abbr": "CRM",
        "longForm": "Customer Relationship Management"
      },
      {
        "abbr": "CVSS",
        "longForm": "Common Vulnerability Scoring System"
      },
      {
        "abbr": "DLP",
        "longForm": "Data Loss Prevention"
      },
      {
        "abbr": "EV",
        "longForm": "Extended Validation"
      },
      {
        "abbr": "JSON",
        "longForm": "JavaScript Object Notation"
      },
      {
        "abbr": "MFA",
        "longForm": "Multi-Factor Authentication"
      },
      {
        "abbr": "SLA",
        "longForm": "Service Level Agreement"
      },
      {
        "abbr": "SLO",
        "longForm": "Service Level Objective"
      }
    ],
    "must": [
      "Publish impact and likelihood scales with explicit anchors, a matrix with Low/Medium/High/Critical thresholds, and acceptance criteria as a separate rule: who may accept which residual level, with a review date.",
      "Identify information-security risks as a loss of confidentiality, integrity or availability of information inside the approved ISMS scope, and name a risk owner for each risk.",
      "Analyse with a short factual rationale, not a bare number. Evaluate against the published thresholds. Record inherent score and residual score separately.",
      "Define treatment options as modify, avoid, transfer or accept. Residual-risk acceptance must include risk ID, inherent and residual scores, actions taken, rationale, compensating controls, accountable owner, approval authority, expiry date and reassessment triggers.",
      "Define monitoring cadence plus event triggers: incident, architecture change, supplier change, scope change, audit finding or material risk change.",
      "Do not change scales or thresholds mid-workshop. A version bump is a Document Control change: approval plus a Revision history row in the change_log section. The last Version in that table must match title_page.values.Version.",
      "The Example JSON must carry professional-document information as fields the renderer can format: purpose, audience, scope in/out, method terms, and revision history. The renderer must not invent those fields.",
      "Every body section and methodology group that contains a table or list must open with one or two sentences that say what the reader must do with it. Do not leave a heading plus a bare table."
    ],
    "mustNot": [
      "Do not write taxonomy or generic register lines such as 'Cloud risk', 'phishing' or 'malware' without asset, event, weakness and impact.",
      "Do not present quantitative FAIR, Monte-Carlo or other false-precision models as this methodology.",
      "Do not import the MAGERIT / RASM analysis process into RAM.",
      "Do not select, include or exclude Annex A controls or produce a Statement of Applicability in this artifact.",
      "Do not accept residual risk without the defined approval authority, an expiry date and a monitoring or reassessment rule.",
      "Do not replace this artifact's function with a shared family skeleton (operating_rules, systems_and_records)."
    ],
    "softwareCompanyAdaptations": [
      "Write every risk as a scenario: because of [weakness or exposure], [threat event] could affect [asset, service or process], causing [business or security impact]. Include one weak and one good example.",
      "Calibrate before workshops: two assessors score the same scenarios; if the delta exceeds one point, clarify the anchors and bump the Document Control version after approval.",
      "Justify availability impact with BIA facts (RTO/RPO, service criticality, customer or contractual impact), not an unexplained High label.",
      "Use 80/20 software-company scenario types as calibration examples, not as a copied risk library: privileged access, cloud misconfiguration, CI/CD compromise, SaaS data leakage, critical supplier failure, availability incident.",
      "State the golden thread in the introduction: methodology → risk register → treatment decision → ticketed work → SoA mapping. This document owns only the methodology rules; it does not duplicate the SoA.",
      "Keep the method short. The register must not copy the whole method; it cites the Document Control version.",
      "Use Arcfield as the worked example organization (Premium/Basic companion identity, cover variant A)."
    ],
    "exampleBody": {
      "sectionId": "methodology_content",
      "workedExampleOrg": "Arcfield",
      "minBodyWords": 400,
      "requiredGroups": [
        {
          "id": "introduction",
          "heading": "What this method is",
          "mustInclude": [
            "what the method is (ISO 6.1.2 / 6.1.3 rulebook, not a register or SoA)",
            "who needs it, as prose not a nested heading",
            "what it brings, as prose not a nested heading",
            "how it links to RR, RTP, RAMT, BIA and SoA, as prose not a nested heading",
            "cite Document Control version, do not copy the method into the register"
          ]
        },
        {
          "id": "scope",
          "heading": "Scope",
          "mustInclude": [
            "scope in and out as a table with a how-to sentence",
            "SoA, FAIR and MAGERIT or RASM out of this method"
          ]
        },
        {
          "id": "terms",
          "heading": "Terms used here",
          "mustInclude": [
            "method terms as a table with a how-to sentence",
            "scenario, inherent score, residual score, method freeze"
          ]
        },
        {
          "id": "scenario_rule",
          "heading": "Scenario rule",
          "mustInclude": [
            "scenario sentence pattern (weakness, event, asset or service, impact)",
            "one weak example",
            "one good software-company example"
          ]
        },
        {
          "id": "criteria_and_acceptance",
          "heading": "Criteria, scales, thresholds and acceptance authority",
          "mustInclude": [
            "impact scale 1-5 with anchors and a one-sentence how-to intro",
            "likelihood scale 1-5 with anchors and a one-sentence how-to intro",
            "matrix thresholds with a one-sentence how-to intro",
            "who may accept which residual level",
            "review date on accepted residual risk"
          ]
        },
        {
          "id": "calibration",
          "heading": "Calibration",
          "mustInclude": [
            "second-assessor check",
            "one-point delta rule",
            "how-to sentence before the stop-rules list",
            "how-to sentence before the scored scenarios table",
            "at least two scored calibration scenarios"
          ]
        },
        {
          "id": "roles",
          "heading": "Roles",
          "mustInclude": [
            "method owner",
            "risk owner",
            "Top Management / acceptance authority"
          ]
        },
        {
          "id": "treatment_and_residual",
          "heading": "Treatment and residual acceptance",
          "mustInclude": [
            "modify, avoid, transfer, accept",
            "required residual-acceptance fields",
            "link to RAMT as the acceptance record, not a substitute for the rule"
          ]
        },
        {
          "id": "management_escalation",
          "heading": "Management escalation",
          "mustInclude": [
            "High and Critical visibility",
            "overdue treatment",
            "legal or customer-impacting residual risk"
          ]
        },
        {
          "id": "cadence_and_triggers",
          "heading": "Cadence and triggers",
          "mustInclude": [
            "planned review cadence",
            "incident trigger",
            "architecture trigger",
            "supplier trigger",
            "scope-change trigger"
          ]
        },
        {
          "id": "software_8020_calibration",
          "heading": "Software-company 80/20 calibration set",
          "mustInclude": [
            "privileged access",
            "cloud misconfiguration",
            "CI/CD compromise",
            "SaaS data leakage",
            "critical supplier failure",
            "availability incident"
          ]
        },
        {
          "id": "operating_evidence_sample",
          "heading": "Operating evidence sample",
          "mustInclude": [
            "retrievable workshop pack",
            "risk register export",
            "RAMT residual acceptance"
          ]
        }
      ],
      "requiredSections": [
        {
          "id": "change_log",
          "title": "Revision history",
          "role": "Versioned freeze log with how-to sentence and rows Version, Date, Change, Approved by. Last Version matches title_page.values.Version. Rendered on the Document Control page as a label, not a TOC heading and not as a body chapter."
        },
        {
          "id": "external_references",
          "title": "References",
          "role": "ISO clauses with official catalogue href, book chapter ids from bookSources, companion artifacts with the book-chapter Amazon href for that artifact. Rendered as a numbered list, not a table. Not a series catalogue."
        }
      ]
    },
    "documentQuality": {
      "register": "The Example JSON carries every publishable professional-document field. The renderer formats those fields; it must not invent purpose, scope, terms or revision history.",
      "requiredInformation": [
        {
          "id": "identity",
          "in": "title_page.values",
          "form": "Version, Owner, Approver, Effective Date, Next Review Date, Classification"
        },
        {
          "id": "purpose",
          "in": "methodology_content.introduction",
          "form": "opening paragraphs stating what the method is and is not, who uses it, what it brings and how it links; no nested headings"
        },
        {
          "id": "scope",
          "in": "methodology_content.scope",
          "form": "Heading 2 group: how-to sentence plus table with In this method / Not in this method"
        },
        {
          "id": "audience",
          "in": "methodology_content.introduction",
          "form": "named actors in the purpose prose, not a separate heading"
        },
        {
          "id": "terms",
          "in": "methodology_content.terms",
          "form": "Heading 2 group: how-to sentence plus table of method-specific terms not already covered by acronyms"
        },
        {
          "id": "change_log",
          "in": "change_log",
          "form": "how-to sentence plus table Version, Date, Change, Approved by; last Version matches title_page.values.Version"
        }
      ],
      "prose": [
        "Abstract is a cover blurb. It must not copy the first body paragraph.",
        "Instructions tell the reader how to adopt this Word file. They are imperative, one action per item, parallel grammar, and not a second copy of the method.",
        "Method rules are present tense and name the actor or the record.",
        "Body paragraphs are complete sentences, not noun-phrase fragments under a heading.",
        "Every table or list has a how-to sentence immediately before it.",
        "Lists of the same kind stay parallel (same grammatical start).",
        "Purpose, scope and terms are Heading 2 method groups. Do not nest them, and do not add a How-this-document-is-structured heading that repeats the table of contents.",
        "Scoring and risk-level cells use valueColorScales. polarity adverse is green (better) to red (worse). polarity favorable is the reverse, so High benefit is green."
      ],
      "valueColorScales": [
        {
          "id": "risk_score",
          "polarity": "adverse",
          "headers": [
            "Score"
          ],
          "levels": [
            "1",
            "2",
            "3",
            "4",
            "5"
          ]
        },
        {
          "id": "risk_level",
          "polarity": "adverse",
          "headers": [
            "Risk level",
            "Typical band"
          ],
          "levels": [
            "Low",
            "Medium",
            "High",
            "Critical"
          ]
        }
      ]
    }
  },
  "sections": [
    {
      "order": 1,
      "id": "title_page",
      "title": "Title Page",
      "contentType": "metadata",
      "required": true,
      "hint": null
    },
    {
      "order": 2,
      "id": "abstract",
      "title": "Abstract",
      "contentType": "narrative",
      "required": true,
      "hint": {
        "text": "Apply Abstract with named owners, systems and exportable evidence. Do not leave this chapter as a heading plus a bare table.",
        "bookReference": "Volume 1, S-00-03-00 Planning, Risk & Objectives (Clause 6)"
      }
    },
    {
      "order": 3,
      "id": "document_control",
      "title": "Document Control",
      "contentType": "control_table",
      "required": true
    },
    {
      "order": 4,
      "id": "change_log",
      "title": "Revision history",
      "contentType": "revision_table",
      "required": true
    },
    {
      "order": 5,
      "id": "instructions",
      "title": "Instructions",
      "contentType": "ordered_list",
      "required": true,
      "hint": {
        "text": "Adopt this file as the controlled master. These steps are not a second copy of the method.",
        "bookReference": "Volume 2, S-07-02-00 Risk Assessment & Risk Treatment Process"
      }
    },
    {
      "order": 6,
      "id": "methodology_content",
      "title": "Risk assessment method",
      "contentType": "methodology_sections",
      "required": true,
      "hint": {
        "text": "Freeze scales and acceptance authority in Document Control. Residual acceptance lives in RAMT, not in this file.",
        "bookReference": "Volume 2, S-07-02-00 Risk Assessment & Risk Treatment Process"
      }
    },
    {
      "order": 9,
      "id": "evidence_and_records",
      "title": "Evidence and records",
      "contentType": "evidence_table",
      "required": true,
      "hint": {
        "text": "This file owns the rules. Keep the named records with their owners; typical issues are what auditors look for first.",
        "bookReference": "Volume 1, S-00-03-00 Planning, Risk & Objectives (Clause 6)"
      }
    },
    {
      "order": 10,
      "id": "external_references",
      "title": "References",
      "contentType": "reference_table",
      "required": true,
      "hint": {
        "text": "Apply References with named owners, systems and exportable evidence. Do not leave this chapter as a heading plus a bare table.",
        "bookReference": "Volume 1, S-00-03-00 Planning, Risk & Objectives (Clause 6)"
      }
    }
  ],
  "validationRules": [
    "JSON Example must contain definitionRef pointing to RAM.artifactDefinition.v2.",
    "title_page.values must include Version, Owner, Approver, Effective Date and Next Review Date. The renderer fills Document Control from those values. Do not emit a second Document Control table.",
    "change_log must include a how-to sentence and rows Version, Date, Change, Approved by. The last Version must match title_page.values.Version.",
    "Introduction must state purpose, scope in/out, audience and method terms as JSON fields, not as renderer-invented copy.",
    "Risk method must open with an introduction, then scenario rule, scoring calibration, treatment rules, residual-risk approval and management escalation.",
    "Body must include practical examples, common pitfalls, evidence expectations and external references. Do not add a How-this-method-is-used chapter that repeats Instructions.",
    "Do not change scales or thresholds mid-workshop (method freeze). A version bump is a Document Control change.",
    "Each risk statement in the method examples must be a scenario (weakness, event, asset or service, impact), not a taxonomy label such as Cloud risk or phishing.",
    "Treatment rules must name modify, avoid, transfer and accept. Residual-risk acceptance must require owner, rationale, compensating controls, approval authority, expiry date and reassessment triggers.",
    "High and Critical risks, overdue treatment and residual risk above appetite must escalate to Top Management visibility.",
    "Do not include FAIR or other quantitative false-precision models, MAGERIT/RASM process steps, or Annex A / SoA control selection.",
    "Document approval is recorded in Document Control. Residual acceptance is RAMT. Do not add a Review and approval chapter or a third signature block.",
    "References cite ISO clauses with official catalogue hrefs, bookSources chapter ids and companion artifacts with the book-chapter Amazon href. No book-series catalogue or slogan block. No legacy MD references."
  ],
  "enrichment": {
    "source": "Contract.json",
    "method": "curated-json",
    "note": "Completes Contract JSON from MD-only schema/sections, removes duplicate alias sections, and normalizes string columns into structured column objects."
  },
  "editorialContractId": "editorial.docx.methodology.v1",
  "contentContractId": "content.methodology.v1",
  "relations": [
    {
      "kind": "usesTemplate",
      "artifactId": "RAMT",
      "role": "residualAcceptance",
      "expectedType": "Minutes",
      "rank": 3
    },
    {
      "kind": "cites",
      "artifactId": "RR",
      "role": "evidence_register",
      "expectedType": "Register",
      "rank": 1
    },
    {
      "kind": "cites",
      "artifactId": "RTP",
      "role": "evidence_register",
      "expectedType": "Register",
      "rank": 2
    },
    {
      "kind": "cites",
      "artifactId": "MDR",
      "role": "evidence_register",
      "expectedType": "Register",
      "rank": 4
    }
  ]
}
