{
  "schemaVersion": "artifactExample.v2",
  "artifactId": "ELAI",
  "title": "Evidence Log / Audit Pack Index",
  "definitionRef": {
    "artifactId": "ELAI",
    "definitionSchemaVersion": "artifactDefinition.v2",
    "definitionId": "ELAI.artifactDefinition.v2",
    "title": "Evidence Log / Audit Pack Index"
  },
  "organization": "Arcfield",
  "sections": [
    {
      "id": "title_page",
      "title": "Title Page",
      "values": {
        "Register Title": "Evidence Log / Audit Pack Index",
        "Register ID": "ELAI-REG-001",
        "Version": "1.1",
        "Status": "Approved",
        "Organization": "Arcfield",
        "Owner": "ISMS Manager",
        "Approver": "Internal Auditor",
        "Classification": "Internal",
        "Effective Date": "2026-09-11",
        "Next Review Date": "2027-09-11"
      },
      "items": [
        "Register Title: Evidence Log / Audit Pack Index",
        "Register ID: ELAI-REG-001",
        "Version: 1.1",
        "Status: Approved",
        "Organization: Arcfield",
        "Owner: ISMS Manager",
        "Approver: Internal Auditor",
        "Classification: Internal",
        "Effective Date: 2026-09-11",
        "Next Review Date: 2027-09-11"
      ],
      "contentType": "metadata"
    },
    {
      "id": "abstract",
      "title": "Abstract",
      "text": "This example indexes Arcfield audit evidence by clause or control, owner, location, production date, coverage period, collection status, independent review and audit-pack readiness. This index navigates the certified Arcfield Platform companion set in the surveillance cycle after certificate ARC-ISMS-2025-001. It is not itself the evidence freeze.",
      "contentType": "narrative"
    },
    {
      "id": "document_control",
      "title": "Document Control",
      "rows": [
        {
          "Property": "Purpose",
          "Value": "Maintain the central index of audit evidence across clauses, controls, owners and evidence locations."
        },
        {
          "Property": "Used by",
          "Value": "ISMS Manager, Internal Auditor, Control Owners, External Auditor"
        },
        {
          "Property": "Maintained by",
          "Value": "ISMS Manager"
        },
        {
          "Property": "Evidence role",
          "Value": "Audit-pack and certification-readiness evidence"
        },
        {
          "Property": "ISO reference",
          "Value": "ISO/IEC 27001:2022 Clauses 7.5, 9.2, 9.3, 10.2 and relevant Annex A controls"
        },
        {
          "Property": "Review cadence",
          "Value": "Weekly during audit preparation and before audit pack release"
        }
      ],
      "contentType": "control_table"
    },
    {
      "id": "instructions",
      "title": "Instructions",
      "items": [
        "Record every evidence item included in the audit pack.",
        "Map each item to an ISO clause, Annex A control or internal requirement.",
        "Record owner, location, coverage period and confidentiality.",
        "Mark whether evidence has been collected and independently reviewed.",
        "Keep items with pending review out of the final external audit pack until approved.",
        "Use sheets ending in “Ex” as read-only examples. Enter live data only on the matching “Wk” (Working) sheets.",
        "Every operative list is an Excel Table with frozen headers and filters. Add new rows on the next empty worksheet row beneath the table so Excel expands it — do not leave blank rows inside the table.",
        "Where a column offers a dropdown, choose a value from the list (Status, Owner role, Priority, Severity, Likelihood, Impact, Applicability, Evidence Status, Review Result). Do not invent free-text variants.",
        "Enter dates as YYYY-MM-DD. Date columns are validated and formatted accordingly.",
        "Review the Flag columns (Overdue, Review Due, Missing Owner, Missing Evidence). They calculate automatically and highlight gaps for follow-up.",
        "Keep Cover, Legal, Book, Lists and Metadata unchanged. System sheets are protected on purpose.",
        "Keep Evidence IDs unique and link them from registers and actions so Traceability and Flag checks stay meaningful."
      ],
      "contentType": "ordered_list"
    },
    {
      "id": "evidence_log",
      "title": "Evidence log",
      "schemaRef": {
        "definitionId": "ELAI.artifactDefinition.v2",
        "sectionId": "evidence_log",
        "columnsRef": "sections.evidence_log.columns"
      },
      "rows": [
        {
          "Evidence ID": "ELAI-001",
          "Evidence / artifact": "Approved ISMS Scope Statement",
          "Evidence type": "Document",
          "Clause or control": "Clause 4.3",
          "Where it lives": "ISMS controlled documents / context",
          "Owner": "ISMS Manager",
          "Date produced": "2026-07-25",
          "Covers period": "Current scope",
          "Collected": "Yes",
          "Independently reviewed": "Yes",
          "Review result": "Accepted",
          "Confidentiality": "Internal",
          "Audit pack status": "Ready",
          "Notes": "Matches certification scope."
        },
        {
          "Evidence ID": "ELAI-002",
          "Evidence / artifact": "Risk Register Q3",
          "Evidence type": "Register",
          "Clause or control": "Clause 6.1; Clause 8.2",
          "Where it lives": "ISMS registers / risk",
          "Owner": "Risk Manager",
          "Date produced": "2026-08-29",
          "Covers period": "2026 Q3",
          "Collected": "Yes",
          "Independently reviewed": "Yes",
          "Review result": "Accepted with comments",
          "Confidentiality": "Internal",
          "Audit pack status": "Ready",
          "Notes": "Treatment links checked."
        },
        {
          "Evidence ID": "ELAI-003",
          "Evidence / artifact": "Statement of Applicability",
          "Evidence type": "Register",
          "Clause or control": "Clause 6.1; Annex A",
          "Where it lives": "ISMS registers / SoA",
          "Owner": "ISMS Manager",
          "Date produced": "2026-08-29",
          "Covers period": "2026 Q3",
          "Collected": "Yes",
          "Independently reviewed": "Yes",
          "Review result": "Accepted",
          "Confidentiality": "Internal",
          "Audit pack status": "Ready",
          "Notes": "All 93 Annex A controls present."
        },
        {
          "Evidence ID": "ELAI-004",
          "Evidence / artifact": "Access Review Record Q3",
          "Evidence type": "Record",
          "Clause or control": "A.5.18; A.8.2",
          "Where it lives": "Access review folder",
          "Owner": "IT Operations Manager",
          "Date produced": "2026-08-29",
          "Covers period": "2026 Q3",
          "Collected": "Yes",
          "Independently reviewed": "No",
          "Review result": "Pending",
          "Confidentiality": "Restricted",
          "Audit pack status": "Needs review",
          "Notes": "Privileged exception still open."
        },
        {
          "Evidence ID": "ELAI-005",
          "Evidence / artifact": "Management Review Minutes",
          "Evidence type": "Minutes",
          "Clause or control": "Clause 9.3",
          "Where it lives": "Management review folder",
          "Owner": "Top Management",
          "Date produced": "2026-08-12",
          "Covers period": "2026 Q3",
          "Collected": "Yes",
          "Independently reviewed": "Yes",
          "Review result": "Accepted",
          "Confidentiality": "Internal",
          "Audit pack status": "Ready",
          "Notes": "Includes decisions and actions."
        },
        {
          "Evidence ID": "ELAI-006",
          "Evidence / artifact": "Corrective Actions Register",
          "Evidence type": "Register",
          "Clause or control": "Clause 10.2",
          "Where it lives": "ISMS registers / improvement",
          "Owner": "ISMS Manager",
          "Date produced": "2026-08-29",
          "Covers period": "2026 Q3",
          "Collected": "Yes",
          "Independently reviewed": "No",
          "Review result": "Pending",
          "Confidentiality": "Internal",
          "Audit pack status": "Needs review",
          "Notes": "Two open actions remain."
        }
      ],
      "contentType": "register_table"
    },
    {
      "id": "audit_pack_decision",
      "title": "Audit pack decision",
      "values": {
        "Review result": "Audit pack mostly ready with two items needing independent review",
        "Evidence items": 6,
        "Collected items": 6,
        "Independently reviewed items": 4,
        "Items not ready": 2,
        "Reviewed by": "Internal Auditor",
        "Decision date": "2026-08-29",
        "Evidence reference": "ELAI-REVIEW-2026-Q3"
      },
      "rows": [
        {
          "Field": "Review result",
          "Value": "Audit pack mostly ready with two items needing independent review"
        },
        {
          "Field": "Evidence items",
          "Value": "6"
        },
        {
          "Field": "Collected items",
          "Value": "6"
        },
        {
          "Field": "Independently reviewed items",
          "Value": "4"
        },
        {
          "Field": "Items not ready",
          "Value": "2"
        },
        {
          "Field": "Reviewed by",
          "Value": "Internal Auditor"
        },
        {
          "Field": "Decision date",
          "Value": "2026-08-29"
        },
        {
          "Field": "Evidence reference",
          "Value": "ELAI-REVIEW-2026-Q3"
        }
      ],
      "contentType": "decision_table"
    },
    {
      "id": "external_references",
      "title": "References",
      "groups": [
        {
          "text": "Cite these sources from workshops and audits. This list names ISO clauses, book chapters and companion artifacts used by this file."
        },
        {
          "rows": [
            {
              "Kind": "ISO",
              "Reference": "ISO/IEC 27001:2022",
              "How this document uses it": "Normative source this artifact implements or cites.",
              "href": "https://www.iso.org/standard/82875.html"
            },
            {
              "Kind": "Book",
              "Reference": "Implementation & Certification, Internal Audit & Management Review",
              "How this document uses it": "Primary operating chapter for this companion artifact.",
              "href": "https://www.amazon.com/s?k=ISO+27001+for+Software+Companies+Implementation+and+Certification"
            },
            {
              "Kind": "Artifact",
              "Reference": "ISO Information Security Objectives (Building the ISMS, Information Security Policies & Risk Management)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/dp/9789908983448"
            }
          ]
        }
      ],
      "contentType": "reference_table"
    }
  ],
  "enrichment": {
    "source": "Example.json",
    "method": "curated-json",
    "note": "Completes Example JSON with renderer-native sections and generalized groups; no mdSource helper fields."
  },
  "snapshotRef": {
    "snapshotId": "arcfield.platform.surv.2026-09-11",
    "schemaVersion": "evidenceSnapshot.v1"
  },
  "scenarioRef": {
    "githubIssue": 64,
    "crId": "CR-TYPE-ARCFIELD-001",
    "family": "Index",
    "role": "Navigation across companions; not the evidence freeze"
  }
}
