{
  "schemaVersion": "artifactExample.v2",
  "artifactId": "CSS",
  "title": "Cloud Security Statement",
  "definitionRef": {
    "artifactId": "CSS",
    "definitionSchemaVersion": "artifactDefinition.v2",
    "definitionId": "CSS.artifactDefinition.v2",
    "title": "Cloud Security Statement"
  },
  "organization": "Arcfield",
  "sections": [
    {
      "id": "title_page",
      "title": "Title Page",
      "values": {
        "Document Title": "Cloud Security Statement",
        "Document ID": "CLOUD-SEC-STATEMENT-001",
        "Version": "1.1",
        "Status": "Approved",
        "Organization": "Arcfield",
        "Owner": "Cloud Service Owner",
        "Approver": "Security Lead",
        "Classification": "Internal",
        "Effective Date": "2026-09-11",
        "Next Review Date": "2027-09-11"
      },
      "items": [
        "Document Title: Cloud Security Statement",
        "Document ID: CLOUD-SEC-STATEMENT-001",
        "Version: 1.1",
        "Status: Approved",
        "Organization: Arcfield",
        "Owner: Cloud Service Owner",
        "Approver: Security Lead",
        "Classification: Internal",
        "Effective Date: 2026-09-11",
        "Next Review Date: 2027-09-11"
      ],
      "contentType": "metadata"
    },
    {
      "id": "abstract",
      "title": "Abstract",
      "text": "This example provides a customer-facing cloud security statement for Arcfield services. It explains cloud scope, shared responsibility, key security controls, supplier assurance, customer commitments and evidence expectations without overstating guarantees. This statement remains binding for the certified Arcfield Platform ISMS in the surveillance cycle after certificate ARC-ISMS-2025-001.",
      "contentType": "narrative"
    },
    {
      "id": "document_control",
      "title": "Document Control",
      "contentType": "control_table"
    },
    {
      "id": "change_log",
      "title": "Revision history",
      "groups": [
        {
          "text": "A published change is a new row. Do not edit an approved version in place."
        },
        {
          "rows": [
            {
              "Version": "1.0",
              "Date": "2026-08-29",
              "Change": "Initial Arcfield Platform publication.",
              "Approved by": "Security Lead"
            },
            {
              "Version": "1.1",
              "Date": "2026-09-11",
              "Change": "Approved Arcfield worked example after the 11 September 2026 internal audit.",
              "Approved by": "Security Lead"
            }
          ]
        }
      ],
      "contentType": "revision_table"
    },
    {
      "id": "instructions",
      "title": "Instructions",
      "groups": [
        {
          "text": "Copy this file as the controlled Word master for your ISMS. The Arcfield identity fields on the cover are the approved worked example. Complete the steps below when you adopt the file for your organization."
        },
        {
          "items": [
            "Fill the cover identity fields (Organization, Version, Classification, Owner, Approver, Effective Date and Next Review Date) when you adopt this file. The Arcfield values shown here are the approved worked example.",
            "Issue your own version and a new Revision history row. Do not edit an approved version in place.",
            "Cite this approved version from related records. Do not copy this file into those records."
          ]
        }
      ],
      "contentType": "ordered_list"
    },
    {
      "id": "statement_content",
      "title": "Cloud security statement",
      "groups": [
        {
          "id": "introduction",
          "heading": "What this statement is",
          "level": 1,
          "text": "This document is Arcfield's Cloud Security Statement. Explain cloud security controls, responsibilities, evidence and assurance boundaries. It is not the Information Security Policy, the SoA or a live register. This statement applies to the Arcfield Platform (B2B SaaS for regulated fintech and health customers): production, customer data, CI/CD, privileged access and critical suppliers. Neighbouring records (ISO, SRP, CSP) cite this Document Control version. Do not copy these paragraphs into them."
        },
        {
          "id": "scope",
          "heading": "Scope",
          "level": 1,
          "text": "Use this table before you copy a rule into another record or exclude a duty from this file.",
          "rows": [
            {
              "In this statement": "The rules, roles, worked Arcfield example and the records this file owns.",
              "Not in this statement": "The ISMS boundary (ISS), Annex A selection (SoA) or live rows in ISO, SRP, CSP."
            },
            {
              "In this statement": "Interfaces that must cite this Document Control version, including CI/CD, identity and suppliers where they affect CIA.",
              "Not in this statement": "Live ISS scope rows, SoA applicability decisions, or neighbouring live registers. Those files keep their own approved versions; this file does not duplicate them."
            }
          ]
        },
        {
          "id": "terms",
          "heading": "Terms used here",
          "level": 1,
          "text": "These terms are local to this file. Expand every acronym on first use in the body.",
          "rows": [
            {
              "Term": "Owner",
              "Meaning": "The named role that can be called in an audit for an outcome. A team name is not an owner."
            },
            {
              "Term": "Exception",
              "Meaning": "A time-bound, approved departure with expiry and a compensating control."
            },
            {
              "Term": "CIA",
              "Meaning": "Confidentiality, Integrity and Availability of in-scope information and services."
            },
            {
              "Term": "Document Control version",
              "Meaning": "The approved version cited from neighbouring records. Do not copy this body into those records."
            }
          ]
        },
        {
          "id": "named_registers",
          "heading": "Systems, integrations and data",
          "level": 1,
          "text": "Related inventories live in the companion documents named below. This file cites them by their approved version. It does not copy their content.",
          "items": [
            "[Asset Inventory](AI_Asset_Inventory.xlsx) — In-scope assets with owner, classification, hosting, personal-data flag and related risk.",
            "[Supplier Inventory](SINV_Supplier_Inventory.xlsx) — Security-relevant suppliers with tier, due diligence, contract controls, subprocessors and exit planning.",
            "[Users and Access Inventory](UAI_Users_and_Access_Inventory.xlsx) — Users and accounts with access rights, privileged access, MFA status, reviews and revocations."
          ],
          "ordered": true,
          "relationView": "inventory"
        },
        {
          "id": "scope_and_boundary",
          "heading": "Scope and boundary",
          "level": 1,
          "text": "Scope and boundary is a Arcfield Platform operating rule for Arcfield, not a restatement of this file's purpose. Scope and boundary states the Arcfield rule, the Arcfield Platform system it binds and the evidence a second person can retrieve. Explain cloud security controls, responsibilities, evidence and assurance boundaries. Apply it to Arcfield Platform production, customer data, CI/CD, privileged access and critical suppliers. Name the owner, the live record and the review date. Cite this approved version from neighbouring records; do not copy this chapter into them.",
          "rows": [
            {
              "Arcfield case": "Arcfield Platform production — scope and boundary",
              "Rule applied": "Scope and boundary binds the named production system and a named owner. Explain cloud security controls, responsibilities, evidence and assurance boundaries.",
              "Evidence": "CSS-scope_and_boundary-PROD"
            },
            {
              "Arcfield case": "Customer data / support — scope and boundary",
              "Rule applied": "Support attachments and tenant configuration inherit this scope and boundary rule; they are not out of scope because they are temporary.",
              "Evidence": "CSS-scope_and_boundary-CUST"
            },
            {
              "Arcfield case": "Supplier or CI/CD — scope and boundary",
              "Rule applied": "Name the shared-responsibility split for scope and boundary on hosting, identity and deploy paths. An unnamed interface is an unnamed audit boundary.",
              "Evidence": "CSS-scope_and_boundary-SUP"
            }
          ]
        },
        {
          "id": "shared_responsibility",
          "heading": "Shared responsibility",
          "level": 1,
          "text": "Shared responsibility is a Arcfield Platform operating rule for Arcfield, not a restatement of this file's purpose. Shared responsibility states the Arcfield rule, the Arcfield Platform system it binds and the evidence a second person can retrieve. Explain cloud security controls, responsibilities, evidence and assurance boundaries. Apply it to Arcfield Platform production, customer data, CI/CD, privileged access and critical suppliers. Name the owner, the live record and the review date. Cite this approved version from neighbouring records; do not copy this chapter into them.",
          "rows": [
            {
              "Arcfield case": "Arcfield Platform production — shared responsibility",
              "Rule applied": "Shared responsibility binds the named production system and a named owner. Explain cloud security controls, responsibilities, evidence and assurance boundaries.",
              "Evidence": "CSS-shared_responsibility-PROD"
            },
            {
              "Arcfield case": "Customer data / support — shared responsibility",
              "Rule applied": "Support attachments and tenant configuration inherit this shared responsibility rule; they are not out of scope because they are temporary.",
              "Evidence": "CSS-shared_responsibility-CUST"
            },
            {
              "Arcfield case": "Supplier or CI/CD — shared responsibility",
              "Rule applied": "Name the shared-responsibility split for shared responsibility on hosting, identity and deploy paths. An unnamed interface is an unnamed audit boundary.",
              "Evidence": "CSS-shared_responsibility-SUP"
            }
          ]
        },
        {
          "id": "control_summary",
          "heading": "Control summary",
          "level": 1,
          "text": "Control summary is a Arcfield Platform operating rule for Arcfield, not a restatement of this file's purpose. Control summary states the Arcfield rule, the Arcfield Platform system it binds and the evidence a second person can retrieve. Explain cloud security controls, responsibilities, evidence and assurance boundaries. Apply it to Arcfield Platform production, customer data, CI/CD, privileged access and critical suppliers. Name the owner, the live record and the review date. Cite this approved version from neighbouring records; do not copy this chapter into them.",
          "rows": [
            {
              "Arcfield case": "Arcfield Platform production — control summary",
              "Rule applied": "Control summary binds the named production system and a named owner. Explain cloud security controls, responsibilities, evidence and assurance boundaries.",
              "Evidence": "CSS-control_summary-PROD"
            },
            {
              "Arcfield case": "Customer data / support — control summary",
              "Rule applied": "Support attachments and tenant configuration inherit this control summary rule; they are not out of scope because they are temporary.",
              "Evidence": "CSS-control_summary-CUST"
            },
            {
              "Arcfield case": "Supplier or CI/CD — control summary",
              "Rule applied": "Name the shared-responsibility split for control summary on hosting, identity and deploy paths. An unnamed interface is an unnamed audit boundary.",
              "Evidence": "CSS-control_summary-SUP"
            }
          ]
        },
        {
          "id": "supplier_assurance",
          "heading": "Supplier assurance",
          "level": 1,
          "text": "Supplier assurance is a Arcfield Platform operating rule for Arcfield, not a restatement of this file's purpose. Supplier assurance states the Arcfield rule, the Arcfield Platform system it binds and the evidence a second person can retrieve. Explain cloud security controls, responsibilities, evidence and assurance boundaries. Apply it to hosting, payments, health-integration and support suppliers for Arcfield Platform. Name the owner, the live record and the review date. Cite this approved version from neighbouring records; do not copy this chapter into them.",
          "rows": [
            {
              "Arcfield case": "Arcfield Platform production — supplier assurance",
              "Rule applied": "Supplier assurance binds the named production system and a named owner. Explain cloud security controls, responsibilities, evidence and assurance boundaries.",
              "Evidence": "CSS-supplier_assurance-PROD"
            },
            {
              "Arcfield case": "Customer data / support — supplier assurance",
              "Rule applied": "Support attachments and tenant configuration inherit this supplier assurance rule; they are not out of scope because they are temporary.",
              "Evidence": "CSS-supplier_assurance-CUST"
            },
            {
              "Arcfield case": "Supplier or CI/CD — supplier assurance",
              "Rule applied": "Name the shared-responsibility split for supplier assurance on hosting, identity and deploy paths. An unnamed interface is an unnamed audit boundary.",
              "Evidence": "CSS-supplier_assurance-SUP"
            }
          ]
        },
        {
          "id": "customer_facing_use",
          "heading": "Customer-facing use",
          "level": 1,
          "text": "Customer-facing use is a Arcfield Platform operating rule for Arcfield, not a restatement of this file's purpose. Customer-facing use states the Arcfield rule, the Arcfield Platform system it binds and the evidence a second person can retrieve. Explain cloud security controls, responsibilities, evidence and assurance boundaries. Apply it to Arcfield Platform production, customer data, CI/CD, privileged access and critical suppliers. Name the owner, the live record and the review date. Cite this approved version from neighbouring records; do not copy this chapter into them.",
          "rows": [
            {
              "Arcfield case": "Arcfield Platform production — customer-facing use",
              "Rule applied": "Customer-facing use binds the named production system and a named owner. Explain cloud security controls, responsibilities, evidence and assurance boundaries.",
              "Evidence": "CSS-customer_facing_use-PROD"
            },
            {
              "Arcfield case": "Customer data / support — customer-facing use",
              "Rule applied": "Support attachments and tenant configuration inherit this customer-facing use rule; they are not out of scope because they are temporary.",
              "Evidence": "CSS-customer_facing_use-CUST"
            },
            {
              "Arcfield case": "Supplier or CI/CD — customer-facing use",
              "Rule applied": "Name the shared-responsibility split for customer-facing use on hosting, identity and deploy paths. An unnamed interface is an unnamed audit boundary.",
              "Evidence": "CSS-customer_facing_use-SUP"
            }
          ]
        }
      ],
      "contentType": "statement_sections"
    },
    {
      "id": "evidence_and_records",
      "title": "Evidence and records",
      "groups": [
        {
          "text": "Related records live in the companion documents named below. This file cites them by their approved version. It does not copy their content. The Owner named on the cover is accountable for those live records."
        },
        {
          "items": [
            "[Mandatory Documents and Records Register](MDR_Mandatory_Documents_and_Records_Register.xlsx) — The 27 mandatory ISO 27001 documents and records, with owner, required status, approval, review cadence, location and evidence readiness.",
            "[Document Register](DR_Document_Register.xlsx) — Controlled documented information: origin, owner, approver, version, review cycle, retention and location.",
            "[Records Retention Schedule](RRS_Records_Retention_Schedule_Register.xlsx) — Retention rules for ISMS, security, privacy, audit and operational records, with owner, period, disposal method and evidence."
          ],
          "ordered": true,
          "relationView": "evidence"
        }
      ],
      "contentType": "evidence_table"
    },
    {
      "id": "external_references",
      "title": "References",
      "groups": [
        {
          "id": "linked_documents",
          "heading": "Linked documents",
          "level": 1,
          "text": "These companion files sit next to this document in the unpacked package. This file cites them by their approved version. It does not copy their content.",
          "rows": [
            {
              "Kind": "Artifact",
              "Reference": "AI Asset Inventory",
              "How this document uses it": "In-scope assets with owner, classification, hosting, personal-data flag and related risk.",
              "href": "AI_Asset_Inventory.xlsx"
            },
            {
              "Kind": "Artifact",
              "Reference": "SINV Supplier Inventory",
              "How this document uses it": "Security-relevant suppliers with tier, due diligence, contract controls, subprocessors and exit planning.",
              "href": "SINV_Supplier_Inventory.xlsx"
            },
            {
              "Kind": "Artifact",
              "Reference": "UAI Users and Access Inventory",
              "How this document uses it": "Users and accounts with access rights, privileged access, MFA status, reviews and revocations.",
              "href": "UAI_Users_and_Access_Inventory.xlsx"
            },
            {
              "Kind": "Artifact",
              "Reference": "MDR Mandatory Documents and Records Register",
              "How this document uses it": "The 27 mandatory ISO 27001 documents and records, with owner, required status, approval, review cadence, location and evidence readiness.",
              "href": "MDR_Mandatory_Documents_and_Records_Register.xlsx"
            },
            {
              "Kind": "Artifact",
              "Reference": "DR Document Register",
              "How this document uses it": "Controlled documented information: origin, owner, approver, version, review cycle, retention and location.",
              "href": "DR_Document_Register.xlsx"
            },
            {
              "Kind": "Artifact",
              "Reference": "RRS Records Retention Schedule",
              "How this document uses it": "Retention rules for ISMS, security, privacy, audit and operational records, with owner, period, disposal method and evidence.",
              "href": "RRS_Records_Retention_Schedule_Register.xlsx"
            },
            {
              "Kind": "Artifact",
              "Reference": "SRP Supplier Relationships Policy (Building the ISMS, Supplier Security & Third-party Risk Management)",
              "href": "SRP_Supplier_Relationships_Policy.docx",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record."
            },
            {
              "Kind": "Artifact",
              "Reference": "CSP Cloud Security Policy (Secure Operations, Cloud Security Posture Management (CSPM))",
              "href": "CSP_Cloud_Security_Policy.docx",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record."
            },
            {
              "Kind": "Artifact",
              "Reference": "CSRM Cloud Shared Responsibility Matrix (Secure Operations, Cloud Security Posture Management (CSPM))",
              "href": "CSRM_Cloud_Shared_Responsibility_Matrix.xlsx",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record."
            },
            {
              "Kind": "Artifact",
              "Reference": "LMP Logging and Monitoring Policy (Implementation & Certification, Monitoring, Measurement & Performance Metrics)",
              "href": "LMP_Logging_and_Monitoring_Policy.docx",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record."
            }
          ]
        },
        {
          "id": "external_sources",
          "heading": "External references",
          "level": 1,
          "text": "Cite these ISO clauses and book chapters from workshops and audits.",
          "rows": [
            {
              "Kind": "ISO",
              "Reference": "ISO/IEC 27001:2022",
              "How this document uses it": "Normative ISMS requirements this companion artifact supports.",
              "href": "https://www.iso.org/standard/82875.html"
            },
            {
              "Kind": "Book",
              "Reference": "Secure Operations, Cloud Security Posture Management (CSPM)",
              "How this document uses it": "Primary operating chapter for this companion artifact.",
              "href": "https://www.amazon.com/dp/9789908983462"
            }
          ]
        }
      ],
      "contentType": "reference_table"
    }
  ],
  "enrichment": {
    "source": "Example.json",
    "method": "curated-json",
    "note": "Completes Example JSON with renderer-native sections and generalized groups; no mdSource helper fields."
  },
  "snapshotRef": {
    "snapshotId": "arcfield.platform.surv.2026-09-11",
    "schemaVersion": "evidenceSnapshot.v1"
  },
  "scenarioRef": {
    "githubIssue": 64,
    "crId": "CR-TYPE-ARCFIELD-001",
    "family": "Statement",
    "role": "Binding Arcfield Platform ISMS statement in the surveillance window"
  }
}
