{
  "schemaVersion": "artifactExample.v2",
  "artifactId": "CMTP",
  "title": "Competence Matrix and Training Plan",
  "definitionRef": {
    "artifactId": "CMTP",
    "definitionSchemaVersion": "artifactDefinition.v2",
    "definitionId": "CMTP.artifactDefinition.v2",
    "title": "Competence Matrix and Training Plan"
  },
  "organization": "Arcfield",
  "sections": [
    {
      "id": "title_page",
      "title": "Title Page",
      "values": {
        "Matrix Title": "Competence Matrix and Training Plan",
        "Matrix ID": "CMTP-MTX-001",
        "Version": "1.1",
        "Status": "Approved",
        "Organization": "Arcfield",
        "Owner": "HR Manager",
        "Approver": "ISMS Manager",
        "Classification": "Internal",
        "Effective Date": "2026-09-11",
        "Next Review Date": "2027-09-11"
      },
      "items": [
        "Matrix Title: Competence Matrix and Training Plan",
        "Matrix ID: CMTP-MTX-001",
        "Version: 1.1",
        "Status: Approved",
        "Organization: Arcfield",
        "Owner: HR Manager",
        "Approver: ISMS Manager",
        "Classification: Internal",
        "Effective Date: 2026-09-11",
        "Next Review Date: 2027-09-11"
      ],
      "contentType": "metadata"
    },
    {
      "id": "abstract",
      "title": "Abstract",
      "text": "This example maps Arcfield ISMS roles to required competence, current evidence, identified gaps, training actions, owners, target dates and effectiveness verification. This matrix is the mapping used by the certified Arcfield Platform ISMS in the surveillance cycle after certificate ARC-ISMS-2025-001.",
      "contentType": "narrative"
    },
    {
      "id": "document_control",
      "title": "Document Control",
      "rows": [
        {
          "Property": "Purpose",
          "Value": "Track role-based competence requirements, evidence, gaps and training actions for ISMS responsibilities."
        },
        {
          "Property": "Used by",
          "Value": "ISMS Manager, HR Manager, Managers, Internal Auditor"
        },
        {
          "Property": "Maintained by",
          "Value": "HR Manager"
        },
        {
          "Property": "Evidence role",
          "Value": "Mandatory competence planning and audit evidence"
        },
        {
          "Property": "ISO reference",
          "Value": "ISO/IEC 27001:2022 Clause 7.2 and Clause 7.3"
        },
        {
          "Property": "Review cadence",
          "Value": "Quarterly and after role, process or scope changes"
        }
      ],
      "contentType": "control_table"
    },
    {
      "id": "instructions",
      "title": "Instructions",
      "items": [
        "List ISMS roles with assigned person or group.",
        "Describe responsibilities and competence requirements.",
        "Record evidence held for competence or awareness.",
        "Identify gaps and define action owner and target date.",
        "Record effectiveness verification.",
        "Review open gaps before audit and management review.",
        "Use sheets ending in “Ex” as read-only examples. Enter live data only on the matching “Wk” (Working) sheets.",
        "Every operative list is an Excel Table with frozen headers and filters. Add new rows on the next empty worksheet row beneath the table so Excel expands it — do not leave blank rows inside the table.",
        "Where a column offers a dropdown, choose a value from the list (Status, Owner role, Priority, Severity, Likelihood, Impact, Applicability, Evidence Status, Review Result). Do not invent free-text variants.",
        "Enter dates as YYYY-MM-DD. Date columns are validated and formatted accordingly.",
        "Review the Flag columns (Overdue, Review Due, Missing Owner, Missing Evidence). They calculate automatically and highlight gaps for follow-up.",
        "Keep Cover, Legal, Book, Lists and Metadata unchanged. System sheets are protected on purpose."
      ],
      "contentType": "ordered_list"
    },
    {
      "id": "competence_matrix",
      "title": "Competence matrix",
      "schemaRef": {
        "definitionId": "CMTP.artifactDefinition.v2",
        "sectionId": "competence_matrix",
        "columnsRef": "sections.competence_matrix.columns"
      },
      "rows": [
        {
          "Role": "ISMS Manager",
          "Person or Group": "ISMS Office",
          "ISMS Responsibilities": "Maintain ISMS, coordinate evidence, prepare management review and audits.",
          "Competence Required": "ISO 27001 implementation, audit readiness and evidence management.",
          "Evidence Held": "Lead implementer certificate and management review facilitation record.",
          "Gap Identified": "No",
          "Action to Close Gap": "",
          "Action Owner": "",
          "Target Date": "",
          "Effectiveness Verification": "Internal audit preparation completed without major evidence gaps.",
          "Evidence Reference": "IAP-PLAN-2026-Q4",
          "Status": "Current",
          "Notes": "Quarterly review cadence approved."
        },
        {
          "Role": "System Owner",
          "Person or Group": "Product team leads",
          "ISMS Responsibilities": "Confirm asset criticality, access requirements and control operation evidence.",
          "Competence Required": "Asset ownership, access review and risk assessment basics.",
          "Evidence Held": "Role briefing completed for four of five system owners.",
          "Gap Identified": "Yes",
          "Action to Close Gap": "Complete privileged access review training for cloud admin owner.",
          "Action Owner": "IT Operations Manager",
          "Target Date": "2026-09-05",
          "Effectiveness Verification": "September access review checked for missing owner decisions.",
          "Evidence Reference": "ARR-2026-08",
          "Status": "Open follow-up",
          "Notes": "Linked to TR-005."
        },
        {
          "Role": "Supplier Manager",
          "Person or Group": "Supplier management team",
          "ISMS Responsibilities": "Maintain supplier inventory, due diligence evidence and contract follow-ups.",
          "Competence Required": "Supplier security review, contract security schedules and exit planning.",
          "Evidence Held": "Supplier security review workshop completed.",
          "Gap Identified": "Yes",
          "Action to Close Gap": "Complete CloudHost addendum review and update evidence pack.",
          "Action Owner": "Supplier Manager",
          "Target Date": "2026-09-10",
          "Effectiveness Verification": "CloudHost evidence pack reviewed without missing mandatory fields.",
          "Evidence Reference": "SINV-REVIEW-2026-Q3",
          "Status": "Action open",
          "Notes": "Related to LRR-005."
        },
        {
          "Role": "Incident Manager",
          "Person or Group": "Incident response team",
          "ISMS Responsibilities": "Coordinate incident response, reporting, closure and lessons learned.",
          "Competence Required": "Incident triage, escalation, evidence preservation and communication.",
          "Evidence Held": "Incident reporting briefing and tabletop scheduled.",
          "Gap Identified": "Yes",
          "Action to Close Gap": "Run supplier incident tabletop exercise.",
          "Action Owner": "Incident Manager",
          "Target Date": "2026-09-25",
          "Effectiveness Verification": "Incident report quality reviewed after tabletop.",
          "Evidence Reference": "IRRT-REVIEW-2026-08",
          "Status": "Scheduled",
          "Notes": "Supplier incident scenario planned."
        },
        {
          "Role": "HR Manager",
          "Person or Group": "HR team",
          "ISMS Responsibilities": "Maintain onboarding, training and offboarding evidence.",
          "Competence Required": "Personnel security lifecycle and competence evidence management.",
          "Evidence Held": "HR onboarding checklist and training register maintained.",
          "Gap Identified": "No",
          "Action to Close Gap": "",
          "Action Owner": "",
          "Target Date": "",
          "Effectiveness Verification": "Sample onboarding and training records reviewed.",
          "Evidence Reference": "TRC-REVIEW-2026-Q3",
          "Status": "Current",
          "Notes": "Contractor completion reminders open."
        },
        {
          "Role": "Internal Auditor",
          "Person or Group": "Internal audit function",
          "ISMS Responsibilities": "Plan audit programme, sample evidence and report findings.",
          "Competence Required": "ISO 27001 internal audit, sampling and evidence evaluation.",
          "Evidence Held": "Internal audit planning briefing completed.",
          "Gap Identified": "No",
          "Action to Close Gap": "",
          "Action Owner": "",
          "Target Date": "",
          "Effectiveness Verification": "Audit plan reviewed with evidence owners.",
          "Evidence Reference": "IAP-PLAN-2026-Q4",
          "Status": "Current",
          "Notes": "Evidence freeze planned."
        }
      ],
      "contentType": "matrix_table"
    },
    {
      "id": "competence_review_decision",
      "title": "Competence review decision",
      "values": {
        "Review result": "Six roles reviewed; three competence actions remain open with owners and target dates.",
        "Roles reviewed": 6,
        "Gaps identified": 3,
        "Actions open": 3,
        "Effectiveness checks pending": 3,
        "Reviewed by": "HR Manager",
        "Decision date": "2026-08-29",
        "Evidence reference": "CMTP-REVIEW-2026-Q3"
      },
      "rows": [
        {
          "Field": "Review result",
          "Value": "Six roles reviewed; three competence actions remain open with owners and target dates."
        },
        {
          "Field": "Roles reviewed",
          "Value": "6"
        },
        {
          "Field": "Gaps identified",
          "Value": "3"
        },
        {
          "Field": "Actions open",
          "Value": "3"
        },
        {
          "Field": "Effectiveness checks pending",
          "Value": "3"
        },
        {
          "Field": "Reviewed by",
          "Value": "HR Manager"
        },
        {
          "Field": "Decision date",
          "Value": "2026-08-29"
        },
        {
          "Field": "Evidence reference",
          "Value": "CMTP-REVIEW-2026-Q3"
        }
      ],
      "contentType": "decision_table"
    },
    {
      "id": "external_references",
      "title": "References",
      "groups": [
        {
          "text": "Cite these sources from workshops and audits. This list names ISO clauses, book chapters and companion artifacts used by this file."
        },
        {
          "rows": [
            {
              "Kind": "ISO",
              "Reference": "ISO/IEC 27001:2022 7.2",
              "How this document uses it": "Normative source this artifact implements or cites.",
              "href": "https://www.iso.org/standard/82875.html"
            },
            {
              "Kind": "Book",
              "Reference": "Implementation & Certification, Team, Roles & Responsibilities",
              "How this document uses it": "Primary operating chapter for this companion artifact.",
              "href": "https://www.amazon.com/s?k=ISO+27001+for+Software+Companies+Implementation+and+Certification"
            },
            {
              "Kind": "Artifact",
              "Reference": "ISO Information Security Objectives (Building the ISMS, Information Security Policies & Risk Management)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/dp/9789908983448"
            },
            {
              "Kind": "Artifact",
              "Reference": "IAP Internal Audit Plan (Implementation & Certification, Internal Audit & Management Review)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/s?k=ISO+27001+for+Software+Companies+Implementation+and+Certification"
            },
            {
              "Kind": "Artifact",
              "Reference": "ARR Access Rights Register (Secure Engineering, Access Control & Identity Management)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/dp/9789908983455"
            },
            {
              "Kind": "Artifact",
              "Reference": "IRRT Incident Register and Reporting Template (Secure Engineering, Incident Response & Security Monitoring)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/dp/9789908983455"
            }
          ]
        }
      ],
      "contentType": "reference_table"
    }
  ],
  "enrichment": {
    "source": "Example.json",
    "method": "curated-json",
    "note": "Completes Example JSON with renderer-native sections and generalized groups; no mdSource helper fields."
  },
  "snapshotRef": {
    "snapshotId": "arcfield.platform.surv.2026-09-11",
    "schemaVersion": "evidenceSnapshot.v1"
  },
  "scenarioRef": {
    "githubIssue": 64,
    "crId": "CR-TYPE-ARCFIELD-001",
    "family": "Matrix",
    "role": "Mapping or selection used by the certified ISMS"
  }
}
