{
  "schemaVersion": "artifactDefinition.v2",
  "definitionId": "IMPL-P.artifactDefinition.v2",
  "artifactId": "IMPL-P",
  "title": "Phased ISMS Implementation Plan",
  "artifactType": "Register",
  "format": "xlsx",
  "productTier": "Basic",
  "definitionRole": "contract",
  "sourceModel": {
    "body": "canonical human-readable register maintained in the Artifact Candidate page",
    "jsonDefinition": "machine-readable contract and validation model",
    "jsonExample": "curated realistic example data fixture"
  },
  "purpose": "Define the required structure for planning and tracking phased ISO 27001 ISMS implementation work, including milestones, owners, dates, exit criteria, dependencies, evidence and status.",
  "sections": [
    {
      "order": 1,
      "id": "title_page",
      "title": "Title Page",
      "contentType": "metadata",
      "required": true,
      "hint": null
    },
    {
      "order": 2,
      "id": "abstract",
      "title": "Abstract",
      "contentType": "narrative",
      "required": true,
      "hint": {
        "text": "Use IMPL-P to translate the Book 2 implementation process into visible milestones, responsibilities and exit criteria.",
        "bookReference": "Volume 2, S-09-01-00 Implementation Readiness & Planning"
      }
    },
    {
      "order": 3,
      "id": "document_control",
      "title": "Document Control",
      "contentType": "control_table",
      "required": true,
      "hint": null
    },
    {
      "order": 4,
      "id": "instructions",
      "title": "Instructions",
      "contentType": "ordered_list",
      "required": true,
      "hint": {
        "text": "Use the plan as a steering tool: each phase should have an owner, due date, evidence output and clear exit criteria.",
        "bookReference": "Volume 2, S-09-01-00 Implementation Readiness & Planning"
      },
      "intro": "Complete the Working sheets using the example tabs as a model. Follow the workbook usage rules below."
    },
    {
      "order": 5,
      "id": "implementation_plan",
      "title": "Implementation plan",
      "contentType": "register_table",
      "required": true,
      "minimumExampleRows": 8,
      "columns": [
        {
          "name": "Phase ID",
          "type": "text",
          "required": "yes",
          "description": "Unique implementation phase identifier.",
          "example": "PH-01"
        },
        {
          "name": "Milestone",
          "type": "text",
          "required": "yes",
          "description": "Implementation milestone.",
          "example": "Define ISMS scope"
        },
        {
          "name": "Indicative Timing",
          "type": "text",
          "required": "yes",
          "description": "Suggested timing.",
          "example": "Week 1"
        },
        {
          "name": "Work Performed",
          "type": "text",
          "required": "yes",
          "description": "Work performed in the phase.",
          "example": "Confirm boundaries"
        },
        {
          "name": "Exit Criteria",
          "type": "text",
          "required": "yes",
          "description": "Completion condition.",
          "example": "Scope approved"
        },
        {
          "name": "Related Artifacts",
          "type": "artifactRef",
          "required": "yes",
          "description": "Relevant companion artifacts.",
          "example": "ISS, IPR, CR",
          "artifactRef": {
            "scope": "companion",
            "value": "artifactId",
            "cardinality": "oneOrMore",
            "separator": ";",
            "description": "Cell values are companion Contract artifactId values."
          }
        },
        {
          "name": "Owner",
          "type": "select",
          "required": "yes",
          "description": "Accountable owner.",
          "example": "ISMS Manager",
          "valueSet": "domain.owner",
          "options": [
            "ISMS Manager",
            "Control Owner",
            "Risk Owner",
            "Process Owner",
            "Asset Owner",
            "IT Security",
            "HR",
            "Legal",
            "Executive Management",
            "Internal Audit"
          ],
          "validation": {
            "allowBlank": false,
            "errorTitle": "Invalid value",
            "error": "Select a value from the list."
          }
        },
        {
          "name": "Dependencies",
          "type": "text",
          "required": "no",
          "description": "Predecessors or blockers.",
          "example": "Sponsor confirmed"
        },
        {
          "name": "Planned Start",
          "type": "date",
          "required": "yes",
          "description": "Planned start date.",
          "example": "2026-09-02"
        },
        {
          "name": "Planned Finish",
          "type": "date",
          "required": "yes",
          "description": "Planned finish date.",
          "example": "2026-09-06"
        },
        {
          "name": "Actual Finish",
          "type": "date",
          "required": "no",
          "description": "Actual completion date."
        },
        {
          "name": "Evidence Reference",
          "type": "text",
          "required": "yes",
          "description": "Evidence generated by the phase.",
          "example": "ISS-2026-DRAFT"
        },
        {
          "name": "Status",
          "type": "select",
          "required": "yes",
          "description": "Planned, in progress, not started, completed or at risk.",
          "example": "In progress",
          "valueSet": "domain.status.generic",
          "options": [
            "Draft",
            "In Progress",
            "Under Review",
            "Approved",
            "Closed",
            "Deferred"
          ],
          "validation": {
            "allowBlank": false,
            "errorTitle": "Invalid value",
            "error": "Select a value from the list."
          }
        },
        {
          "name": "Notes",
          "type": "text",
          "required": "no",
          "description": "Additional context.",
          "example": "Boundary under review."
        }
      ],
      "hint": {
        "text": "Each row should connect a process milestone with the artifacts and evidence needed to prove completion.",
        "bookReference": "Volume 2, S-09-01-00 Implementation Readiness & Planning"
      }
    },
    {
      "order": 6,
      "id": "implementation_review_decision",
      "title": "Implementation review decision",
      "contentType": "decision_table",
      "required": true,
      "fields": [
        {
          "name": "Review result",
          "type": "select",
          "required": "yes",
          "valueSet": "domain.reviewResult",
          "options": [
            "Pass",
            "Pass with observations",
            "Fail",
            "Deferred"
          ],
          "validation": {
            "allowBlank": false,
            "errorTitle": "Invalid value",
            "error": "Select a value from the list."
          }
        },
        {
          "name": "Milestones reviewed",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Completed milestones",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "At-risk milestones",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Open blockers",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Reviewed by",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Decision date",
          "type": "date",
          "required": "yes"
        },
        {
          "name": "Evidence reference",
          "type": "text",
          "required": "yes"
        }
      ],
      "hint": {
        "text": "Close with a review decision so the implementation plan becomes a management and audit steering record.",
        "bookReference": "Volume 2, S-09-01-00 Implementation Readiness & Planning"
      }
    },
    {
      "order": 7,
      "id": "external_references",
      "title": "References",
      "contentType": "reference_table",
      "required": true
    }
  ],
  "validationRules": [
    "JSON Example must contain definitionRef pointing to IMPL-P.artifactDefinition.v2.",
    "JSON Example register sections must contain schemaRef pointing to the matching definition section.",
    "Implementation rows must include milestone, work performed, exit criteria, owner, dates, evidence reference and status.",
    "Body must render the contract schema and the example data.",
    "No standalone Book reference section and no generic Sample placeholders are allowed."
  ],
  "enrichment": {
    "source": "Contract.json",
    "method": "curated-json",
    "note": "Completes Contract JSON from MD-only schema/sections, removes duplicate alias sections, and normalizes string columns into structured column objects."
  },
  "editorialStandard": {
    "isoAnchors": [
      {
        "label": "ISO/IEC 27001:2022",
        "href": "https://www.iso.org/standard/82875.html",
        "role": "Normative source this artifact implements or cites."
      },
      {
        "label": "ISO/IEC 27001:2022 8.1",
        "href": "https://www.iso.org/standard/82875.html",
        "role": "Operational planning and control this register evidences."
      },
      {
        "label": "ISO/IEC 27001:2022 7.5",
        "href": "https://www.iso.org/standard/82875.html",
        "role": "Documented information: identify, review and cite this workbook by version."
      }
    ],
    "bookSources": [
      {
        "series": "ISO 27001 for Software Companies",
        "volume": 2,
        "volumeTitle": "Implementation & Certification",
        "chapterId": "S-09-01-00",
        "chapterTitle": "Implementation Readiness & Planning",
        "primary": true,
        "role": "Primary operating chapter for this companion artifact.",
        "href": "https://www.amazon.com/s?k=ISO+27001+for+Software+Companies+Implementation+and+Certification"
      },
      {
        "series": "ISO 27001 for Software Companies",
        "volume": 1,
        "volumeTitle": "Building the ISMS",
        "chapterId": "S-00-03-00",
        "chapterTitle": "Planning, Risk & Objectives (Clause 6)",
        "primary": false,
        "role": "Documented information, review and version discipline.",
        "href": "https://www.amazon.com/dp/9789908983448"
      }
    ],
    "acronyms": [
      {
        "abbr": "ISMS",
        "longForm": "Information Security Management System"
      },
      {
        "abbr": "SaaS",
        "longForm": "Software as a Service"
      },
      {
        "abbr": "CIA",
        "longForm": "Confidentiality, Integrity, and Availability"
      },
      {
        "abbr": "CI/CD",
        "longForm": "Continuous Integration / Continuous Delivery"
      },
      {
        "abbr": "CI",
        "longForm": "Continuous Integration"
      },
      {
        "abbr": "CD",
        "longForm": "Continuous Delivery"
      },
      {
        "abbr": "AI",
        "longForm": "Artificial Intelligence"
      },
      {
        "abbr": "CR",
        "longForm": "Change Request"
      },
      {
        "abbr": "JSON",
        "longForm": "JavaScript Object Notation"
      },
      {
        "abbr": "MDR",
        "longForm": "Managed Detection and Response"
      },
      {
        "abbr": "RAM",
        "longForm": "Risk Assessment Methodology"
      },
      {
        "abbr": "RR",
        "longForm": "Risk Register"
      },
      {
        "abbr": "RTP",
        "longForm": "Risk Treatment Plan"
      },
      {
        "abbr": "SoA",
        "longForm": "Statement of Applicability"
      }
    ],
    "must": [
      "Keep one live row per record on Working sheets. Do not merge several cases into one row.",
      "Example sheets must contain realistic Arcfield rows for every required sheet. Empty required cells are not an example."
    ],
    "mustNot": [
      "Do not invent live rows in the renderer. Example data lives in the Example JSON.",
      "Do not treat Ex example tabs as working sheets. Do not put live data on system sheets."
    ],
    "softwareCompanyAdaptations": [
      "Use Arcfield as the worked example (cover variant A).",
      "Name SaaS, CI/CD, privileged access or supplier interfaces in example rows where they affect this register."
    ],
    "exampleWorkbook": {
      "workedExampleOrg": "Arcfield",
      "requiredSheets": [
        "implementation_plan",
        "implementation_review_decision"
      ],
      "minExampleRows": 8,
      "coverFromExample": true
    }
  },
  "editorialContractId": "editorial.xlsx.register.v1",
  "contentContractId": "content.register.items.v1"
}
