{
  "schemaVersion": "artifactDefinition.v2",
  "definitionId": "CSS.artifactDefinition.v2",
  "artifactId": "CSS",
  "title": "Cloud Security Statement",
  "artifactType": "Statement",
  "format": "docx",
  "productTier": "Premium",
  "definitionRole": "contract",
  "sourceModel": {
    "body": "canonical human-readable template maintained in the Artifact Candidate page",
    "jsonDefinition": "machine-readable contract and validation model",
    "jsonExample": "curated realistic example data fixture"
  },
  "editorialStandard": {
    "purpose": "Explain cloud security controls, responsibilities, evidence and assurance boundaries.",
    "requiredEditorialElements": [
      "introduction as purpose prose",
      "scope of this document versus neighbouring records",
      "terms as a first-class group",
      "worked Arcfield example",
      "practical examples, pitfalls, evidence and external references"
    ],
    "isoAnchors": [
      {
        "label": "ISO/IEC 27001:2022 A.5.23",
        "href": "https://www.iso.org/standard/82875.html",
        "role": "Annex A control this artifact implements."
      },
      {
        "label": "ISO/IEC 27001:2022 A.5.19",
        "href": "https://www.iso.org/standard/82875.html",
        "role": "Annex A control this artifact implements."
      },
      {
        "label": "ISO/IEC 27001:2022 A.5.22",
        "href": "https://www.iso.org/standard/82875.html",
        "role": "Annex A control this artifact implements."
      },
      {
        "label": "ISO/IEC 27001:2022 A.8.9",
        "href": "https://www.iso.org/standard/82875.html",
        "role": "Annex A control this artifact implements."
      },
      {
        "label": "ISO/IEC 27001:2022 A.8.15",
        "href": "https://www.iso.org/standard/82875.html",
        "role": "Annex A control this artifact implements."
      },
      {
        "label": "ISO/IEC 27001:2022 A.8.16",
        "href": "https://www.iso.org/standard/82875.html",
        "role": "Annex A control this artifact implements."
      },
      {
        "label": "ISO/IEC 27001:2022",
        "href": "https://www.iso.org/standard/82875.html",
        "role": "Normative source this artifact implements or cites."
      }
    ],
    "bookSources": [
      {
        "series": "ISO 27001 for Software Companies",
        "volume": 4,
        "volumeTitle": "Secure Operations",
        "chapterId": "S-06-06-00",
        "chapterTitle": "Cloud Security Posture Management (CSPM)",
        "primary": true,
        "role": "Primary operating chapter for this companion artifact.",
        "href": "https://www.amazon.com/dp/9789908983462"
      },
      {
        "series": "ISO 27001 for Software Companies",
        "volume": 1,
        "volumeTitle": "Building the ISMS",
        "chapterId": "S-00-03-00",
        "chapterTitle": "Planning, Risk & Objectives (Clause 6)",
        "primary": false,
        "role": "Documented information, review and version discipline.",
        "href": "https://www.amazon.com/dp/9789908983448"
      }
    ],
    "acronyms": [
      {
        "abbr": "ISMS",
        "longForm": "Information Security Management System"
      },
      {
        "abbr": "SaaS",
        "longForm": "Software as a Service"
      },
      {
        "abbr": "CIA",
        "longForm": "Confidentiality, Integrity, and Availability"
      },
      {
        "abbr": "CI/CD",
        "longForm": "Continuous Integration / Continuous Delivery"
      },
      {
        "abbr": "ISO",
        "longForm": "International Organization for Standardization"
      },
      {
        "abbr": "CSP",
        "longForm": "Cloud Service Provider"
      },
      {
        "abbr": "CI",
        "longForm": "Continuous Integration"
      },
      {
        "abbr": "CD",
        "longForm": "Continuous Delivery"
      },
      {
        "abbr": "CS",
        "longForm": "Cybersecurity"
      },
      {
        "abbr": "CSS",
        "longForm": "Cascading Style Sheets"
      },
      {
        "abbr": "CUEC",
        "longForm": "Complementary User Entity Controls"
      },
      {
        "abbr": "EV",
        "longForm": "Extended Validation"
      },
      {
        "abbr": "JSON",
        "longForm": "JavaScript Object Notation"
      },
      {
        "abbr": "SOC",
        "longForm": "Security Operations Center"
      },
      {
        "abbr": "SoA",
        "longForm": "Statement of Applicability"
      },
      {
        "abbr": "CSPM",
        "longForm": "Cloud Security Posture Management"
      }
    ],
    "must": [
      "This file's function is: Explain cloud security controls, responsibilities, evidence and assurance boundaries. It must not be rewritten as a generic operating-rules essay.",
      "Define which cloud services and environments the statement covers.",
      "Explain provider responsibilities and Arcfield responsibilities separately.",
      "Summarize controls only where operating evidence exists.",
      "Identify supplier assurance inputs and customer responsibilities.",
      "Review customer-facing claims before external distribution.",
      "Update after architecture, supplier, control or incident changes."
    ],
    "mustNot": [
      "Do not replace this artifact's function with a shared family skeleton (operating_rules, systems_and_records)."
    ],
    "softwareCompanyAdaptations": [
      "Use Arcfield as the worked example (cover variant A).",
      "Name SaaS, cloud, CI/CD, privileged access or supplier interfaces where they affect this artifact's function."
    ],
    "exampleBody": {
      "sectionId": "statement_content",
      "workedExampleOrg": "Arcfield",
      "minBodyWords": 400,
      "requiredGroups": [
        {
          "id": "introduction",
          "heading": "What this statement is",
          "mustInclude": [
            "statement"
          ]
        },
        {
          "id": "scope",
          "heading": "Scope",
          "mustInclude": [
            "Scope"
          ]
        },
        {
          "id": "terms",
          "heading": "Terms used here",
          "mustInclude": [
            "Terms"
          ]
        },
        {
          "id": "scope_and_boundary",
          "heading": "Scope and boundary",
          "mustInclude": [
            "Scope",
            "boundary"
          ]
        },
        {
          "id": "shared_responsibility",
          "heading": "Shared responsibility",
          "mustInclude": [
            "Shared",
            "responsibility"
          ]
        },
        {
          "id": "control_summary",
          "heading": "Control summary",
          "mustInclude": [
            "Control",
            "summary"
          ]
        },
        {
          "id": "supplier_assurance",
          "heading": "Supplier assurance",
          "mustInclude": [
            "Supplier",
            "assurance"
          ]
        },
        {
          "id": "customer_facing_use",
          "heading": "Customer-facing use",
          "mustInclude": [
            "Customer-facing"
          ]
        }
      ],
      "requiredSections": [
        {
          "id": "change_log",
          "title": "Revision history",
          "role": "Versioned freeze log with how-to sentence and rows Version, Date, Change, Approved by. Last Version matches title_page.values.Version."
        },
        {
          "id": "external_references",
          "title": "References",
          "role": "ISO clauses, book chapters and companion artifacts. Not a series catalogue."
        }
      ]
    }
  },
  "sections": [
    {
      "order": 1,
      "id": "title_page",
      "title": "Title Page",
      "contentType": "metadata",
      "required": true
    },
    {
      "order": 2,
      "id": "abstract",
      "title": "Abstract",
      "contentType": "narrative",
      "required": true,
      "hint": {
        "text": "Apply Abstract with named owners, systems and exportable evidence. Do not leave this chapter as a heading plus a bare table.",
        "bookReference": "Volume 4, S-06-06-00 Cloud Security Posture Management (CS)"
      }
    },
    {
      "order": 3,
      "id": "document_control",
      "title": "Document Control",
      "contentType": "control_table",
      "required": true
    },
    {
      "order": 4,
      "id": "change_log",
      "title": "Revision history",
      "contentType": "revision_table",
      "required": true
    },
    {
      "order": 5,
      "id": "instructions",
      "title": "Instructions",
      "contentType": "ordered_list",
      "required": true,
      "hint": {
        "text": "Apply Instructions with named owners, systems and exportable evidence. Do not leave this chapter as a heading plus a bare table.",
        "bookReference": "Volume 4, S-06-06-00 Cloud Security Posture Management (CS)"
      }
    },
    {
      "order": 6,
      "id": "statement_content",
      "title": "Cloud security statement",
      "contentType": "statement_sections",
      "required": true,
      "hint": {
        "text": "Apply Cloud security statement with named owners, systems and exportable evidence. Do not leave this chapter as a heading plus a bare table.",
        "bookReference": "Volume 4, S-06-06-00 Cloud Security Posture Management (CS)"
      }
    },
    {
      "order": 9,
      "id": "evidence_and_records",
      "title": "Evidence and records",
      "contentType": "evidence_table",
      "required": true,
      "hint": {
        "text": "Apply Evidence and records with named owners, systems and exportable evidence. Do not leave this chapter as a heading plus a bare table.",
        "bookReference": "Volume 4, S-06-06-00 Cloud Security Posture Management (CS)"
      }
    },
    {
      "order": 10,
      "id": "external_references",
      "title": "References",
      "contentType": "reference_table",
      "required": true,
      "hint": {
        "text": "Apply References with named owners, systems and exportable evidence. Do not leave this chapter as a heading plus a bare table.",
        "bookReference": "Volume 4, S-06-06-00 Cloud Security Posture Management (CS)"
      }
    }
  ],
  "validationRules": [
    "JSON Example must contain definitionRef pointing to CSS.artifactDefinition.v2.",
    "Template must define cloud scope, shared responsibility, controls, supplier assurance, customer commitments and evidence expectations.",
    "Body must include practical examples, common pitfalls and evidence expectations.",
    "No legacy MD references or standalone Book reference section allowed."
  ],
  "enrichment": {
    "source": "Contract.json",
    "method": "curated-json",
    "note": "Completes Contract JSON from MD-only schema/sections, removes duplicate alias sections, and normalizes string columns into structured column objects."
  },
  "purpose": "Explain cloud security controls, responsibilities, evidence and assurance boundaries.",
  "editorialContractId": "editorial.docx.statement.v1",
  "contentContractId": "content.literary.v1",
  "relations": [
    {
      "kind": "cites",
      "artifactId": "MDR",
      "role": "evidence_register",
      "expectedType": "Register",
      "rank": 30
    },
    {
      "kind": "cites",
      "artifactId": "DR",
      "role": "evidence_register",
      "expectedType": "Register",
      "rank": 31
    },
    {
      "kind": "cites",
      "artifactId": "RRS",
      "role": "evidence_register",
      "expectedType": "Register",
      "rank": 32
    },
    {
      "kind": "cites",
      "artifactId": "AI",
      "role": "inventory",
      "expectedType": "Inventory",
      "rank": 20
    },
    {
      "kind": "cites",
      "artifactId": "SINV",
      "role": "inventory",
      "expectedType": "Inventory",
      "rank": 21
    },
    {
      "kind": "cites",
      "artifactId": "UAI",
      "role": "inventory",
      "expectedType": "Inventory",
      "rank": 22
    }
  ]
}
