{
  "schemaVersion": "artifactExample.v2",
  "artifactId": "COMM-P",
  "title": "ISMS Communication Plan",
  "definitionRef": {
    "artifactId": "COMM-P",
    "definitionSchemaVersion": "artifactDefinition.v2",
    "definitionId": "COMM-P.artifactDefinition.v2",
    "title": "ISMS Communication Plan"
  },
  "organization": "Arcfield",
  "sections": [
    {
      "id": "title_page",
      "title": "Title Page",
      "values": {
        "Register Title": "ISMS Communication Plan",
        "Register ID": "COMM-REG-001",
        "Version": "1.1",
        "Status": "Approved",
        "Organization": "Arcfield",
        "Owner": "ISMS Manager",
        "Approver": "Top Management",
        "Classification": "Internal",
        "Effective Date": "2026-09-11",
        "Next Review Date": "2027-09-11"
      },
      "items": [
        "Register Title: ISMS Communication Plan",
        "Register ID: COMM-REG-001",
        "Version: 1.1",
        "Status: Approved",
        "Organization: Arcfield",
        "Owner: ISMS Manager",
        "Approver: Top Management",
        "Classification: Internal",
        "Effective Date: 2026-09-11",
        "Next Review Date: 2027-09-11"
      ]
    },
    {
      "id": "abstract",
      "title": "Abstract",
      "text": "This example plans Arcfield ISMS communications by audience, message, trigger, frequency, channel, owner, approval, evidence and effectiveness review. Rows are the 11 September 2026 operating sample of the certified Arcfield Platform ISMS in the surveillance cycle after certificate ARC-ISMS-2025-001."
    },
    {
      "id": "document_control",
      "title": "Document Control",
      "rows": [
        {
          "Property": "Purpose",
          "Value": "Plan and evidence recurring and event-driven ISMS communications."
        },
        {
          "Property": "Used by",
          "Value": "ISMS Manager, Top Management, Control Owners, Internal Auditor"
        },
        {
          "Property": "Maintained by",
          "Value": "ISMS Manager"
        },
        {
          "Property": "Evidence role",
          "Value": "Clause 7.4 communication evidence"
        },
        {
          "Property": "ISO reference",
          "Value": "ISO/IEC 27001:2022 Clause 7.4"
        },
        {
          "Property": "Review cadence",
          "Value": "Quarterly and before management review"
        }
      ]
    },
    {
      "id": "instructions",
      "title": "Instructions",
      "items": [
        "Maintain one row for every recurring or event-driven ISMS communication.",
        "Define audience, message, purpose, trigger or frequency, owner and channel.",
        "Record required evidence and concrete evidence references.",
        "Track planned, completed and overdue communications.",
        "Review the plan before internal audit and management review.",
        "Use sheets ending in “Ex” as read-only examples. Enter live data only on the matching “Wk” (Working) sheets.",
        "Every operative list is an Excel Table with frozen headers and filters. Add new rows on the next empty worksheet row beneath the table so Excel expands it — do not leave blank rows inside the table.",
        "Where a column offers a dropdown, choose a value from the list (Status, Owner role, Priority, Severity, Likelihood, Impact, Applicability, Evidence Status, Review Result). Do not invent free-text variants.",
        "Enter dates as YYYY-MM-DD. Date columns are validated and formatted accordingly.",
        "Review the Flag columns (Overdue, Review Due, Missing Owner, Missing Evidence). They calculate automatically and highlight gaps for follow-up.",
        "Keep Cover, Legal, Book, Lists and Metadata unchanged. System sheets are protected on purpose."
      ]
    },
    {
      "id": "communication_plan",
      "title": "Communication plan",
      "schemaRef": {
        "definitionId": "COMM-P.artifactDefinition.v2",
        "sectionId": "communication_plan",
        "columnsRef": "sections.communication_plan.columns"
      },
      "rows": [
        {
          "Communication ID": "COMM-001",
          "Audience": "All employees",
          "Message / Topic": "Information security policy and acceptable use reminder",
          "Purpose": "Maintain awareness of core ISMS obligations.",
          "Trigger or Frequency": "Quarterly",
          "Channel": "All-hands email and intranet post",
          "Owner": "ISMS Manager",
          "Approver": "Top Management",
          "Evidence Required": "Sent email and intranet publication record",
          "Evidence Reference": "COMM-001-2026-Q3",
          "Status": "Completed",
          "Next Communication Date": "2026-11-15",
          "Notes": "Includes link to policy acknowledgement."
        },
        {
          "Communication ID": "COMM-002",
          "Audience": "Control owners",
          "Message / Topic": "Q3 evidence collection deadline",
          "Purpose": "Ensure evidence pack completeness before internal audit.",
          "Trigger or Frequency": "Monthly during audit preparation",
          "Channel": "Teams channel and task tracker",
          "Owner": "ISMS Manager",
          "Approver": "Internal Auditor",
          "Evidence Required": "Task tracker export",
          "Evidence Reference": "ELAI-2026-Q3",
          "Status": "Completed",
          "Next Communication Date": "2026-09-15",
          "Notes": "Linked to evidence log."
        },
        {
          "Communication ID": "COMM-003",
          "Audience": "Top Management",
          "Message / Topic": "Management review agenda and input pack",
          "Purpose": "Prepare decisions on risks, resources, objectives and improvements.",
          "Trigger or Frequency": "Before management review",
          "Channel": "Calendar invite and review pack",
          "Owner": "ISMS Manager",
          "Approver": "CEO",
          "Evidence Required": "Agenda and meeting minutes",
          "Evidence Reference": "MR-2026-Q3",
          "Status": "Planned",
          "Next Communication Date": "2026-09-20",
          "Notes": "Include open CAR and risk treatment summary."
        },
        {
          "Communication ID": "COMM-004",
          "Audience": "Critical suppliers",
          "Message / Topic": "Annual supplier security evidence request",
          "Purpose": "Collect assurance for critical outsourced services.",
          "Trigger or Frequency": "Annual and before supplier review",
          "Channel": "Supplier portal / email",
          "Owner": "Supplier Manager",
          "Approver": "Compliance Manager",
          "Evidence Required": "Supplier questionnaire and assurance documents",
          "Evidence Reference": "SINV-CLOUDHOST-2026-Q3",
          "Status": "In progress",
          "Next Communication Date": "2026-09-10",
          "Notes": "Cloud hosting supplier prioritized."
        },
        {
          "Communication ID": "COMM-005",
          "Audience": "Engineering team",
          "Message / Topic": "Secure development and vulnerability SLA reminder",
          "Purpose": "Reinforce SSDLC and vulnerability-response expectations.",
          "Trigger or Frequency": "After vulnerability trend review",
          "Channel": "Engineering meeting",
          "Owner": "Security Lead",
          "Approver": "Engineering Lead",
          "Evidence Required": "Meeting note and updated backlog items",
          "Evidence Reference": "VULN-2026-Q3",
          "Status": "Completed",
          "Next Communication Date": "2026-10-01",
          "Notes": "Linked to A.8.8 improvement."
        },
        {
          "Communication ID": "COMM-006",
          "Audience": "Incident response team",
          "Message / Topic": "Incident simulation schedule and roles",
          "Purpose": "Prepare team for tabletop exercise.",
          "Trigger or Frequency": "Before exercise",
          "Channel": "Calendar invite and runbook notice",
          "Owner": "Incident Manager",
          "Approver": "ISMS Manager",
          "Evidence Required": "Invite, attendance and exercise record",
          "Evidence Reference": "IRRT-2026-Q3",
          "Status": "Planned",
          "Next Communication Date": "2026-09-25",
          "Notes": "Uses current incident runbook."
        }
      ],
      "contentType": "register_table"
    },
    {
      "id": "communication_review_decision",
      "title": "Communication review decision",
      "values": {
        "Review result": "Controlled with one supplier communication in progress",
        "Planned communications": 6,
        "Completed communications": 3,
        "Overdue communications": 0,
        "Reviewed by": "ISMS Manager",
        "Decision date": "2026-08-29",
        "Evidence reference": "COMM-REVIEW-2026-Q3"
      },
      "rows": [
        {
          "Field": "Review result",
          "Value": "Controlled with one supplier communication in progress"
        },
        {
          "Field": "Planned communications",
          "Value": "6"
        },
        {
          "Field": "Completed communications",
          "Value": "3"
        },
        {
          "Field": "Overdue communications",
          "Value": "0"
        },
        {
          "Field": "Reviewed by",
          "Value": "ISMS Manager"
        },
        {
          "Field": "Decision date",
          "Value": "2026-08-29"
        },
        {
          "Field": "Evidence reference",
          "Value": "COMM-REVIEW-2026-Q3"
        }
      ],
      "contentType": "decision_table"
    },
    {
      "id": "external_references",
      "title": "References",
      "groups": [
        {
          "text": "Cite these sources from workshops and audits. This list names ISO clauses, book chapters and companion artifacts used by this file."
        },
        {
          "rows": [
            {
              "Kind": "ISO",
              "Reference": "ISO/IEC 27001:2022 7.4",
              "How this document uses it": "Normative source this artifact implements or cites.",
              "href": "https://www.iso.org/standard/82875.html"
            },
            {
              "Kind": "Book",
              "Reference": "Implementation & Certification, Implementation Readiness & Planning",
              "How this document uses it": "Primary operating chapter for this companion artifact.",
              "href": "https://www.amazon.com/s?k=ISO+27001+for+Software+Companies+Implementation+and+Certification"
            },
            {
              "Kind": "Artifact",
              "Reference": "ISO Information Security Objectives (Building the ISMS, Information Security Policies & Risk Management)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/dp/9789908983448"
            },
            {
              "Kind": "Artifact",
              "Reference": "CAR Corrective Actions Register (Building the ISMS, Context of the Organization (Clause 4))",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/dp/9789908983448"
            },
            {
              "Kind": "Artifact",
              "Reference": "ELAI Evidence Log / Audit Pack Index (Implementation & Certification, Audit Process)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/s?k=ISO+27001+for+Software+Companies+Implementation+and+Certification"
            },
            {
              "Kind": "Artifact",
              "Reference": "IRRT Incident Register and Reporting Template (Secure Engineering, Incident Response & Security Monitoring)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/dp/9789908983455"
            }
          ]
        }
      ],
      "contentType": "reference_table"
    }
  ],
  "enrichment": {
    "source": "Example.json",
    "method": "curated-json",
    "note": "Completes Example JSON with renderer-native sections and generalized groups; no mdSource helper fields."
  },
  "snapshotRef": {
    "snapshotId": "arcfield.platform.surv.2026-09-11",
    "schemaVersion": "evidenceSnapshot.v1"
  },
  "scenarioRef": {
    "githubIssue": 64,
    "crId": "CR-TYPE-ARCFIELD-001",
    "family": "Register",
    "role": "Operating sample of the 11 September 2026 freeze"
  }
}
