{
  "schemaVersion": "artifactExample.v2",
  "artifactId": "RAM",
  "title": "Risk Assessment Methodology",
  "definitionRef": {
    "artifactId": "RAM",
    "definitionSchemaVersion": "artifactDefinition.v2",
    "definitionId": "RAM.artifactDefinition.v2",
    "title": "Risk Assessment Methodology"
  },
  "organization": "Arcfield",
  "sections": [
    {
      "id": "title_page",
      "title": "Title Page",
      "values": {
        "Document Title": "Risk Assessment Methodology",
        "Document ID": "RISK-METH-001",
        "Version": "1.1",
        "Status": "Approved",
        "Organization": "Arcfield",
        "Owner": "Risk Manager",
        "Approver": "Top Management",
        "Classification": "Internal",
        "Effective Date": "2026-09-11",
        "Next Review Date": "2027-09-11"
      },
      "items": [
        "Document Title: Risk Assessment Methodology",
        "Document ID: RISK-METH-001",
        "Version: 1.1",
        "Status: Approved",
        "Organization: Arcfield",
        "Owner: Risk Manager",
        "Approver: Top Management",
        "Classification: Internal",
        "Effective Date: 2026-09-11",
        "Next Review Date: 2027-09-11"
      ],
      "contentType": "metadata"
    },
    {
      "id": "abstract",
      "title": "Abstract",
      "text": "Arcfield uses this file as the frozen scoring and residual-acceptance rulebook. Workshops cite the Document Control version. This is not a risk register, not a Statement of Applicability, and not a MAGERIT analysis. This methodology remains the approved Arcfield Platform risk method in the surveillance cycle after certificate ARC-ISMS-2025-001.",
      "contentType": "narrative"
    },
    {
      "id": "document_control",
      "title": "Document Control",
      "contentType": "control_table"
    },
    {
      "id": "change_log",
      "title": "Revision history",
      "groups": [
        {
          "text": "A published change is a new row. Do not edit an approved version in place."
        },
        {
          "rows": [
            {
              "Version": "1.0",
              "Date": "2026-08-29",
              "Change": "Initial Arcfield Platform publication.",
              "Approved by": "Top Management"
            },
            {
              "Version": "1.1",
              "Date": "2026-09-11",
              "Change": "First freeze of the approved Arcfield Platform method. A scale or threshold change is a new row, not a workshop edit.",
              "Approved by": "Top Management"
            }
          ]
        }
      ],
      "contentType": "revision_table"
    },
    {
      "id": "instructions",
      "title": "Instructions",
      "groups": [
        {
          "text": "Copy this file as the controlled Word master for your ISMS. The Arcfield identity fields on the cover are the approved worked example. Complete the steps below when you adopt the file for your organization; the method rules start in the next chapter."
        },
        {
          "items": [
            "Fill the cover identity fields (Organization, Version, Classification, Owner, Approver, Effective Date and Next Review Date) when you adopt this file. The Arcfield values shown here are the approved worked example.",
            "Issue your own version and a new Revision history row. Do not edit an approved version in place.",
            "Freeze this file before workshops. A scale or threshold change is a new version and a Revision history row, not a workshop edit.",
            "Cite this approved version in the risk register (RR), the treatment plan (RTP) and RAMT (Risk Acceptance Minutes). Do not copy these rules into those records.",
            "Record residual-risk acceptance in RAMT. This file does not accept residual risk."
          ]
        }
      ],
      "contentType": "ordered_list"
    },
    {
      "id": "methodology_content",
      "title": "Risk assessment method",
      "groups": [
        {
          "id": "introduction",
          "heading": "What this method is",
          "level": 1,
          "groups": [
            {
              "text": "This document is Arcfield's information-security risk assessment method. It is the rulebook for writing, scoring, treating and accepting risks to confidentiality, integrity and availability inside the approved ISMS scope. It follows ISO/IEC 27001:2022 clauses 6.1.2 and 6.1.3. It is not a risk register, not a Statement of Applicability, and not a MAGERIT analysis."
            },
            {
              "text": "Top Management, the ISMS Manager, the Risk Manager and risk owners use it to make repeatable decisions. Auditors sample whether a second assessor lands in the same score band. Engineering, SRE, legal and supplier managers provide facts; they do not change the scales."
            },
            {
              "text": "The method produces comparable scores, names who may accept residual risk, and leaves exportable records. Workshops, the risk register, the treatment plan and RAMT cite this file's Document Control version. They must not copy these rules."
            },
            {
              "text": "This file owns the rules. The risk register (RR) stores scored scenarios. The treatment plan (RTP) and tickets store work. RAMT stores residual acceptance. BIA supplies availability facts (RTO/RPO, criticality, customer or contractual impact). The Statement of Applicability selects Annex A controls in a different artifact. Approve this file in Document Control. Accept residual risk in RAMT."
            }
          ]
        },
        {
          "id": "scope",
          "heading": "Scope",
          "level": 1,
          "groups": [
            {
              "text": "Use this table to decide whether a workshop item belongs in this method."
            },
            {
              "rows": [
                {
                  "In this method": "CIA risks to in-scope information, services and suppliers.",
                  "Not in this method": "Annex A control selection (SoA)."
                },
                {
                  "In this method": "Frozen scales, thresholds and residual-acceptance rules.",
                  "Not in this method": "FAIR, Monte-Carlo or other quantitative models."
                },
                {
                  "In this method": "Calibration scenarios as workshop prompts.",
                  "Not in this method": "MAGERIT or RASM analysis."
                }
              ]
            }
          ]
        },
        {
          "id": "terms",
          "heading": "Terms used here",
          "level": 1,
          "groups": [
            {
              "text": "Read these terms the same way in every workshop. Acronyms expand on first use; this table is only the method vocabulary."
            },
            {
              "rows": [
                {
                  "Term": "Scenario",
                  "Meaning": "A risk statement with weakness, event, asset or service, and CIA or business impact."
                },
                {
                  "Term": "Inherent score",
                  "Meaning": "Likelihood × impact before treatment in this cycle."
                },
                {
                  "Term": "Residual score",
                  "Meaning": "Likelihood × impact after the chosen treatment."
                },
                {
                  "Term": "Method freeze",
                  "Meaning": "Do not change scales or thresholds while scoring. A change is a Document Control version bump plus a Revision history row."
                }
              ]
            }
          ]
        },
        {
          "id": "scenario_rule",
          "heading": "Scenario rule",
          "level": 1,
          "groups": [
            {
              "text": "Every information-security risk is a loss of confidentiality, integrity or availability of information inside the approved ISMS scope, with a named risk owner. Sentence pattern: Because of [weakness or exposure], [threat event] could affect [asset, service or process], causing [business or security impact]."
            },
            {
              "rows": [
                {
                  "Kind": "Weak",
                  "Statement": "Cloud risk.",
                  "Why": "No weakness, event, asset or impact. Cannot be scored, treated or sampled."
                },
                {
                  "Kind": "Good",
                  "Statement": "Because privileged cloud roles for Arcfield Platform production are reviewed only quarterly, an excessive admin role could remain active and allow unauthorized production changes, exposing customer health data.",
                  "Why": "Weakness, event, in-scope service and CIA impact are explicit."
                }
              ]
            }
          ],
          "text": ""
        },
        {
          "id": "criteria_and_acceptance",
          "heading": "Criteria, scales, thresholds and acceptance authority",
          "level": 1,
          "groups": [
            {
              "text": "Likelihood and impact are scored from 1 to 5 with the anchors below. The risk level is likelihood × impact. Availability impact must cite BIA facts (RTO/RPO, service criticality, customer or contractual impact), not an unexplained High label. Acceptance criteria are a separate rule from the matrix: they say who may accept which residual level and when that acceptance is reviewed."
            },
            {
              "heading": "Impact scale",
              "groups": [
                {
                  "text": "Score the worst credible CIA or business effect on the in-scope service. Availability at 4 or 5 must cite RTO/RPO, criticality or customer impact."
                },
                {
                  "rows": [
                    {
                      "Score": "1",
                      "Anchor": "Negligible operational noise; no customer, legal or CIA material effect."
                    },
                    {
                      "Score": "2",
                      "Anchor": "Limited internal disruption; recoverable without customer notification."
                    },
                    {
                      "Score": "3",
                      "Anchor": "Material service, data or contractual effect; contained but visible to customers or auditors."
                    },
                    {
                      "Score": "4",
                      "Anchor": "Serious CIA, customer-trust or legal effect on an in-scope service (for availability: RTO/RPO missed)."
                    },
                    {
                      "Score": "5",
                      "Anchor": "Severe or prolonged loss of an in-scope service, regulated data or certification standing."
                    }
                  ]
                }
              ]
            },
            {
              "heading": "Likelihood scale",
              "groups": [
                {
                  "text": "Score how plausible the scenario is in the planning horizon given current controls, exposure and history, not how dramatic the asset feels."
                },
                {
                  "rows": [
                    {
                      "Score": "1",
                      "Anchor": "Implausible given current controls, exposure and history."
                    },
                    {
                      "Score": "2",
                      "Anchor": "Possible but unlikely; strong controls and limited exposure."
                    },
                    {
                      "Score": "3",
                      "Anchor": "Credible in the planning horizon; controls exist but are incomplete or untested."
                    },
                    {
                      "Score": "4",
                      "Anchor": "Expected without treatment; exposure is open or a similar event has occurred."
                    },
                    {
                      "Score": "5",
                      "Anchor": "Almost certain or already occurring."
                    }
                  ]
                }
              ]
            },
            {
              "heading": "Matrix",
              "groups": [
                {
                  "text": "The level is likelihood × impact. The band decides the required action; it does not by itself accept residual risk."
                },
                {
                  "rows": [
                    {
                      "Score range": "1-4",
                      "Risk level": "Low",
                      "Required action": "Monitor."
                    },
                    {
                      "Score range": "5-9",
                      "Risk level": "Medium",
                      "Required action": "Treat or accept."
                    },
                    {
                      "Score range": "10-15",
                      "Risk level": "High",
                      "Required action": "Treatment plan with owner, due date and evidence."
                    },
                    {
                      "Score range": "16-25",
                      "Risk level": "Critical",
                      "Required action": "Immediate management attention; modify, avoid or transfer."
                    }
                  ]
                }
              ]
            },
            {
              "heading": "Acceptance authority",
              "groups": [
                {
                  "text": "This table is residual-risk authority after treatment, not approval of this methodology file."
                },
                {
                  "rows": [
                    {
                      "Risk level": "Low",
                      "Who may accept residual": "Risk owner, with a review date."
                    },
                    {
                      "Risk level": "Medium",
                      "Who may accept residual": "ISMS Manager, expiry ≤ 12 months."
                    },
                    {
                      "Risk level": "High",
                      "Who may accept residual": "Top Management via RAMT only."
                    },
                    {
                      "Risk level": "Critical",
                      "Who may accept residual": "Not accepted."
                    }
                  ]
                }
              ]
            }
          ],
          "text": ""
        },
        {
          "id": "calibration",
          "heading": "Calibration",
          "level": 1,
          "groups": [
            {
              "text": "Before a scoring workshop, two assessors independently score the same scenarios. The goal is comparable management decisions, not false mathematical precision. FAIR, Monte-Carlo or other quantitative models are out of scope for this method."
            },
            {
              "text": "Stop and fix the method when:"
            },
            {
              "items": [
                "If the delta on likelihood or impact exceeds one point, stop and clarify the anchor.",
                "If an anchor's wording changes, bump the methodology version after approval."
              ]
            },
            {
              "text": "Score these two scenarios independently, then compare. They exist to keep Impact 5 and High residual from drifting."
            },
            {
              "rows": [
                {
                  "ID": "A",
                  "Scenario": "Internal wiki with no customer data left world-readable for one hour.",
                  "Typical band": "Impact 2 × Likelihood 2 = 4 Low"
                },
                {
                  "ID": "B",
                  "Scenario": "Arcfield Platform production database internet-exposed because a security group drifted.",
                  "Typical band": "Impact 5 × Likelihood 3 = 15 High"
                }
              ]
            },
            {
              "text": "A second assessor who scores Calibration B as Impact 3 without BIA or customer facts has left the method; re-anchor before continuing."
            }
          ],
          "text": ""
        },
        {
          "id": "roles",
          "heading": "Roles",
          "level": 1,
          "groups": [
            {
              "text": "Separate who owns the method, who owns each risk, and who may accept residual exposure. Document approval of this file stays in Document Control."
            },
            {
              "rows": [
                {
                  "Role": "Method owner",
                  "Who": "Risk Manager (ISMS Manager supports traceability)",
                  "Does": "Maintains this Document Control version, calibration notes and the change log."
                },
                {
                  "Role": "Risk owner",
                  "Who": "Accountable owner of the in-scope asset, service or process in the scenario",
                  "Does": "Owns scoring rationale, treatment work and residual status."
                },
                {
                  "Role": "Acceptance — Low",
                  "Who": "Risk owner",
                  "Does": "May accept residual Low with a review date."
                },
                {
                  "Role": "Acceptance — Medium",
                  "Who": "ISMS Manager",
                  "Does": "May accept residual Medium under the matrix, expiry ≤ 12 months."
                },
                {
                  "Role": "Acceptance — High",
                  "Who": "Top Management via RAMT",
                  "Does": "Accepts residual High via RAMT. Residual Critical is not accepted. This is not a second approval of the method."
                },
                {
                  "Role": "Contributors",
                  "Who": "Engineering, SRE, legal, supplier managers",
                  "Does": "Provide facts. They do not silently change scales."
                }
              ]
            }
          ],
          "text": ""
        },
        {
          "id": "treatment_and_residual",
          "heading": "Treatment and residual acceptance",
          "level": 1,
          "groups": [
            {
              "text": "After evaluation against the thresholds, choose one option. Modify is the default for High and the only path for Critical. This document does not select Annex A controls or produce a Statement of Applicability. Residual-risk acceptance is recorded in RAMT, not as a comment in the register."
            },
            {
              "rows": [
                {
                  "Option": "Modify",
                  "Meaning": "Reduce likelihood or impact through controls and tickets."
                },
                {
                  "Option": "Avoid",
                  "Meaning": "Do not run the activity."
                },
                {
                  "Option": "Transfer",
                  "Meaning": "Contract, insurance or supplier obligation. Arcfield remains accountable."
                },
                {
                  "Option": "Accept",
                  "Meaning": "Live with residual exposure under the authority matrix."
                }
              ]
            },
            {
              "text": "RAMT is the residual-acceptance record. The list below is the minimum field set. A register comment is not acceptance."
            },
            {
              "groups": [
                {
                  "text": "Copy these fields into RAMT. A register comment is not acceptance."
                },
                {
                  "items": [
                    "Risk ID",
                    "Inherent score",
                    "Residual score",
                    "Treatment actions taken",
                    "Rationale",
                    "Compensating controls",
                    "Accountable owner",
                    "Approval authority",
                    "Expiry date",
                    "Reassessment triggers"
                  ]
                }
              ]
            },
            {
              "text": "Acceptance without authority, expiry or monitoring is invalid."
            }
          ],
          "text": ""
        },
        {
          "id": "management_escalation",
          "heading": "Management escalation",
          "level": 1,
          "groups": [
            {
              "text": "Top Management must see the following at least in management review. Escalation evidence is the management-review pack or the RAMT record, not a chat message. Product teams may propose accepting Medium risk to hit a launch date; they may not hide High risk from the review."
            },
            {
              "items": [
                "Every High and Critical risk",
                "Every overdue treatment action",
                "Every residual risk above appetite",
                "Every legal, customer-contract or certification-impacting residual risk"
              ]
            }
          ],
          "text": ""
        },
        {
          "id": "cadence_and_triggers",
          "heading": "Cadence and triggers",
          "level": 1,
          "groups": [
            {
              "text": "Planned reviews keep High and Critical items visible. Event triggers reopen scoring without waiting for the annual cycle. Annual re-approval of this method is Document Control, not a signature on the last page."
            },
            {
              "rows": [
                {
                  "Kind": "Planned",
                  "When": "Quarterly",
                  "What": "Review High and Critical items."
                },
                {
                  "Kind": "Planned",
                  "When": "Annually",
                  "What": "Re-approve this method."
                }
              ]
            },
            {
              "groups": [
                {
                  "text": "Do not wait for the quarterly cycle. Open a new scoring pass when one of these events occurs."
                },
                {
                  "items": [
                    "Security incident",
                    "Architecture or identity-provider change",
                    "Onboarding or material change of a Tier-1 supplier",
                    "ISMS scope change",
                    "Audit finding",
                    "Missed RTO/RPO or a new regulated customer commitment"
                  ]
                }
              ]
            },
            {
              "text": "Record the trigger in the risk register and in the ISMS change log."
            }
          ],
          "text": ""
        },
        {
          "id": "software_8020_calibration",
          "heading": "Software-company 80/20 calibration set",
          "level": 1,
          "groups": [
            {
              "text": "Use these types to start a Arcfield workshop. They are calibration prompts, not a copied risk library. Rewrite each in Arcfield Platform language or document why the type does not apply."
            },
            {
              "rows": [
                {
                  "Type": "Privileged access",
                  "Prompt": "Excessive cloud or production admin role remains after a role change.",
                  "Typical treatment": "Modify: access review, MFA, time-bound roles."
                },
                {
                  "Type": "Cloud misconfiguration",
                  "Prompt": "Security-group or storage drift exposes an in-scope service.",
                  "Typical treatment": "Modify: baseline, drift detection, restore evidence."
                },
                {
                  "Type": "CI/CD compromise",
                  "Prompt": "Pipeline credentials or unsigned artifacts can change production.",
                  "Typical treatment": "Modify: secret hygiene, signed builds, protected branches."
                },
                {
                  "Type": "SaaS data leakage",
                  "Prompt": "Support or CRM export contains customer configuration or health data.",
                  "Typical treatment": "Modify: DLP path, classification, access limit; accept only via RAMT."
                },
                {
                  "Type": "Critical supplier failure",
                  "Prompt": "A Tier-1 platform outage or breach hits Arcfield Platform availability or confidentiality.",
                  "Typical treatment": "Modify and/or transfer: SLA, fallback test, shared-responsibility record."
                },
                {
                  "Type": "Availability incident",
                  "Prompt": "Core outage exceeds BIA RTO/RPO and customer or contractual impact.",
                  "Typical treatment": "Modify: SLO, backup restore test, incident evidence; residual via RAMT if needed."
                }
              ]
            }
          ],
          "text": ""
        },
        {
          "id": "operating_evidence_sample",
          "heading": "Operating evidence sample",
          "level": 1,
          "text": "These records can be retrieved for the 2026-08-29 Arcfield / Arcfield Platform freeze. They are the sample an auditor can re-perform. They are not a second register grid.",
          "rows": [
            {
              "Sample ID": "RAM-EV-001",
              "What was sampled": "Q3 residual-risk workshop pack and attendance (RAMT_Risk_Acceptance_Minutes.docx)",
              "Evidence reference": "RAMT-2026-Q3"
            },
            {
              "Sample ID": "RAM-EV-002",
              "What was sampled": "Live risk register export (12 CIA scenarios) (RR_Risk_Register.xlsx)",
              "Evidence reference": "RR-EXPORT-2026-08-29"
            },
            {
              "Sample ID": "RAM-EV-003",
              "What was sampled": "Treatment plan export for the same Risk IDs (RTP_Risk_Treatment_Plan.xlsx)",
              "Evidence reference": "RTP-EXPORT-2026-08-29"
            },
            {
              "Sample ID": "RAM-EV-004",
              "What was sampled": "BIA RTO/RPO freeze cited by availability scenarios (BIA_Business_Impact_Analysis_BIA.docx)",
              "Evidence reference": "BIA-WORKSHOP-2026-Q3"
            },
            {
              "Sample ID": "RAM-EV-005",
              "What was sampled": "Calibration set used in the Q3 workshop (This file (Document Control 1.1))",
              "Evidence reference": "RAM-CAL-2026-Q3"
            },
            {
              "Sample ID": "RAM-EV-006",
              "What was sampled": "Frozen scales, thresholds and acceptance authority (This file (Document Control 1.1))",
              "Evidence reference": "RAM-SCALES-2026-09-11"
            },
            {
              "Sample ID": "RAM-EV-007",
              "What was sampled": "Risk owner and deputy appointments (IRAR appointment records)",
              "Evidence reference": "IRAR-2026-Q3"
            },
            {
              "Sample ID": "RAM-EV-008",
              "What was sampled": "SoA linkage sample for treated risks (SOA_Statement_of_Applicability_SoA.xlsx)",
              "Evidence reference": "SOA-FULL-93-2026"
            },
            {
              "Sample ID": "RAM-EV-009",
              "What was sampled": "Next review of this method on the ISMS calendar (GC calendar export)",
              "Evidence reference": "GC-RAM-2026-Q4"
            },
            {
              "Sample ID": "RAM-EV-010",
              "What was sampled": "Evidence log index for the Q3 risk cycle (EVID_Evidence_Log.xlsx)",
              "Evidence reference": "EVID-RAM-2026-Q3"
            }
          ]
        }
      ],
      "contentType": "methodology_sections"
    },
    {
      "id": "evidence_and_records",
      "title": "Evidence and records",
      "groups": [
        {
          "text": "Related records live in the companion documents named below. This file cites them by their approved version. It does not copy their content. The Owner named on the cover is accountable for those live records."
        },
        {
          "items": [
            "[Risk Register](RR_Risk_Register.xlsx) — Live risks with assessment, treatment linkage, residual-risk decision, SoA linkage, evidence and review dates.",
            "[Risk Treatment Plan](RTP_Risk_Treatment_Plan_Register.xlsx) — Treatment actions linked to those risks, with control implementation, evidence, residual-risk approval and effectiveness checks.",
            "[Risk Acceptance Minutes Template](RAMT_Risk_Acceptance_Minutes_Template.docx) — Residual-risk acceptance decisions, with conditions and review dates.",
            "[Mandatory Documents and Records Register](MDR_Mandatory_Documents_and_Records_Register.xlsx) — The 27 mandatory ISO 27001 documents and records, with owner, required status, approval, review cadence, location and evidence readiness."
          ],
          "ordered": true,
          "relationView": "evidence"
        }
      ],
      "contentType": "evidence_table"
    },
    {
      "id": "external_references",
      "title": "References",
      "groups": [
        {
          "id": "linked_documents",
          "heading": "Linked documents",
          "level": 1,
          "text": "These companion files sit next to this document in the unpacked package. This file cites them by their approved version. It does not copy their content.",
          "rows": [
            {
              "Kind": "Artifact",
              "Reference": "RR Risk Register",
              "How this method uses it": "Stores scored scenarios that cite this frozen version.",
              "href": "RR_Risk_Register.xlsx"
            },
            {
              "Kind": "Artifact",
              "Reference": "RTP Risk Treatment Plan",
              "How this method uses it": "Turns modify, avoid or transfer into owned work.",
              "href": "RTP_Risk_Treatment_Plan_Register.xlsx"
            },
            {
              "Kind": "Artifact",
              "Reference": "MDR Mandatory Documents and Records Register",
              "How this method uses it": "The 27 mandatory ISO 27001 documents and records, with owner, required status, approval, review cadence, location and evidence readiness.",
              "href": "MDR_Mandatory_Documents_and_Records_Register.xlsx"
            },
            {
              "Kind": "Artifact",
              "Reference": "SoA Statement of Applicability (Implementation & Certification)",
              "href": "SOA_Statement_of_Applicability_SoA_Coverage.xlsx",
              "How this method uses it": "Out of scope. Do not map Annex A here."
            },
            {
              "Kind": "Artifact",
              "Reference": "BIA Business Impact Analysis (Implementation & Certification, Business Impact Analysis & Business Continuity Planning)",
              "href": "BIA_Business_Impact_Analysis_BIA_Statement_Plan.docx",
              "How this method uses it": "Facts for availability impact (RTO/RPO, criticality)."
            }
          ]
        },
        {
          "id": "linked_templates",
          "heading": "Linked templates",
          "level": 1,
          "text": "Recurring records use these companion templates. Do not keep a second schema in this file.",
          "rows": [
            {
              "Kind": "Artifact",
              "Reference": "RAMT Risk Acceptance Minutes Template",
              "How this method uses it": "Residual-acceptance record with authority, expiry and triggers.",
              "href": "RAMT_Risk_Acceptance_Minutes_Template.docx"
            }
          ]
        },
        {
          "id": "external_sources",
          "heading": "External references",
          "level": 1,
          "text": "Cite these ISO clauses and book chapters from workshops and audits. MAGERIT/RASM and FAIR stay in their own artifacts.",
          "rows": [
            {
              "Kind": "ISO",
              "Reference": "ISO/IEC 27001:2022 6.1.2",
              "How this method uses it": "Repeatable method, criteria, CIA risks, owners, comparable scores.",
              "href": "https://www.iso.org/standard/82875.html"
            },
            {
              "Kind": "ISO",
              "Reference": "ISO/IEC 27001:2022 6.1.3",
              "How this method uses it": "Treatment options and residual approval. SoA is a different artifact.",
              "href": "https://www.iso.org/standard/82875.html"
            },
            {
              "Kind": "Book",
              "Reference": "Implementation & Certification, Risk Assessment & Risk Treatment Process",
              "How this method uses it": "Primary operating model: freeze, scenario-first identification, residual with expiry.",
              "href": "https://www.amazon.com/s?k=ISO+27001+for+Software+Companies+Implementation+and+Certification"
            },
            {
              "Kind": "Book",
              "Reference": "Building the ISMS, Planning, Risk & Objectives (Clause 6)",
              "How this method uses it": "Anchors, matrix thresholds and named acceptance authority.",
              "href": "https://www.amazon.com/dp/9789908983448"
            },
            {
              "Kind": "Book",
              "Reference": "Building the ISMS, Information Security Policies & Risk Management",
              "How this method uses it": "Six-step cycle and software-company change triggers.",
              "href": "https://www.amazon.com/dp/9789908983448"
            },
            {
              "Kind": "Background",
              "Reference": "ISO 31000",
              "href": "https://www.iso.org/standard/65694.html",
              "How this method uses it": "Context only. Not a second method."
            },
            {
              "Kind": "Background",
              "Reference": "ISO/IEC 27005",
              "How this method uses it": "Context only. Not a second method.",
              "href": "https://www.iso.org/standard/80585.html"
            }
          ]
        }
      ],
      "contentType": "reference_table"
    }
  ],
  "enrichment": {
    "source": "Example.json",
    "method": "curated-json",
    "note": "Completes Example JSON with renderer-native sections and generalized groups; no mdSource helper fields."
  },
  "snapshotRef": {
    "snapshotId": "arcfield.platform.surv.2026-09-11",
    "schemaVersion": "evidenceSnapshot.v1"
  },
  "scenarioRef": {
    "githubIssue": 64,
    "crId": "CR-TYPE-ARCFIELD-001",
    "family": "Methodology",
    "role": "Approved risk method still in force"
  }
}
