{
  "schemaVersion": "artifactExample.v2",
  "artifactId": "IMPL-P",
  "title": "Phased ISMS Implementation Plan",
  "definitionRef": {
    "artifactId": "IMPL-P",
    "definitionSchemaVersion": "artifactDefinition.v2",
    "definitionId": "IMPL-P.artifactDefinition.v2",
    "title": "Phased ISMS Implementation Plan"
  },
  "organization": "Arcfield",
  "sections": [
    {
      "id": "title_page",
      "title": "Title Page",
      "values": {
        "Register Title": "Phased ISMS Implementation Plan",
        "Register ID": "IMPL-P-REG-001",
        "Version": "1.1",
        "Status": "Approved",
        "Organization": "Arcfield",
        "Owner": "ISMS Manager",
        "Approver": "Top Management",
        "Classification": "Internal",
        "Effective Date": "2026-09-11",
        "Next Review Date": "2027-09-11"
      },
      "items": [
        "Register Title: Phased ISMS Implementation Plan",
        "Register ID: IMPL-P-REG-001",
        "Version: 1.1",
        "Status: Approved",
        "Organization: Arcfield",
        "Owner: ISMS Manager",
        "Approver: Top Management",
        "Classification: Internal",
        "Effective Date: 2026-09-11",
        "Next Review Date: 2027-09-11"
      ],
      "contentType": "metadata"
    },
    {
      "id": "abstract",
      "title": "Abstract",
      "text": "This example plans Arcfield phased ISO 27001 implementation work with milestones, timing, work performed, exit criteria, related artifacts, owners, dependencies, dates, evidence and status. Rows are the 11 September 2026 operating sample of the certified Arcfield Platform ISMS in the surveillance cycle after certificate ARC-ISMS-2025-001.",
      "contentType": "narrative"
    },
    {
      "id": "document_control",
      "title": "Document Control",
      "rows": [
        {
          "Property": "Purpose",
          "Value": "Plan and track phased ISO 27001 implementation work."
        },
        {
          "Property": "Used by",
          "Value": "ISMS Manager, Project Manager, Top Management, Process Owners, Internal Auditor"
        },
        {
          "Property": "Maintained by",
          "Value": "ISMS Manager"
        },
        {
          "Property": "Evidence role",
          "Value": "Implementation steering and readiness evidence"
        },
        {
          "Property": "ISO reference",
          "Value": "ISO/IEC 27001:2022 Clauses 4.4, 6.1 and 8.1"
        },
        {
          "Property": "Review cadence",
          "Value": "Weekly during implementation and before readiness gates"
        }
      ],
      "contentType": "control_table"
    },
    {
      "id": "instructions",
      "title": "Instructions",
      "items": [
        "Break the implementation into clear phases and milestones.",
        "Assign each milestone to an accountable owner.",
        "Define exit criteria and related artifacts before work starts.",
        "Track planned dates, actual finish dates, evidence references and blockers.",
        "Review at-risk milestones weekly and escalate implementation blockers.",
        "Use the final plan as evidence for implementation control and management review.",
        "Use sheets ending in “Ex” as read-only examples. Enter live data only on the matching “Wk” (Working) sheets.",
        "Every operative list is an Excel Table with frozen headers and filters. Add new rows on the next empty worksheet row beneath the table so Excel expands it — do not leave blank rows inside the table.",
        "Where a column offers a dropdown, choose a value from the list (Status, Owner role, Priority, Severity, Likelihood, Impact, Applicability, Evidence Status, Review Result). Do not invent free-text variants.",
        "Enter dates as YYYY-MM-DD. Date columns are validated and formatted accordingly.",
        "Review the Flag columns (Overdue, Review Due, Missing Owner, Missing Evidence). They calculate automatically and highlight gaps for follow-up.",
        "Keep Cover, Legal, Book, Lists and Metadata unchanged. System sheets are protected on purpose."
      ],
      "contentType": "ordered_list"
    },
    {
      "id": "implementation_plan",
      "title": "Implementation plan",
      "schemaRef": {
        "definitionId": "IMPL-P.artifactDefinition.v2",
        "sectionId": "implementation_plan",
        "columnsRef": "sections.implementation_plan.columns"
      },
      "rows": [
        {
          "Phase ID": "PH-01",
          "Milestone": "Define ISMS scope",
          "Indicative Timing": "Week 1",
          "Work Performed": "Confirm boundaries, services, locations, interfaces and exclusions.",
          "Exit Criteria": "Scope statement approved and communicated.",
          "Related Artifacts": "ISS, IPR, CR",
          "Owner": "ISMS Manager",
          "Dependencies": "Management sponsor confirmed",
          "Planned Start": "2026-09-02",
          "Planned Finish": "2026-09-06",
          "Actual Finish": "",
          "Evidence Reference": "ISS-2026-DRAFT",
          "Status": "In progress",
          "Notes": "Cloud support service boundary under review."
        },
        {
          "Phase ID": "PH-02",
          "Milestone": "Identify interested parties and context",
          "Indicative Timing": "Week 1-2",
          "Work Performed": "Document internal and external issues, stakeholder requirements and evidence expectations.",
          "Exit Criteria": "IPR and CR reviewed by management.",
          "Related Artifacts": "IPR, CR",
          "Owner": "Compliance Lead",
          "Dependencies": "Scope draft available",
          "Planned Start": "2026-09-04",
          "Planned Finish": "2026-09-11",
          "Actual Finish": "",
          "Evidence Reference": "IPR-2026-Q3",
          "Status": "Planned",
          "Notes": "Enterprise customer obligations need legal input."
        },
        {
          "Phase ID": "PH-03",
          "Milestone": "Establish risk method",
          "Indicative Timing": "Week 2",
          "Work Performed": "Approve risk criteria, rating scales, acceptance rules and review cadence.",
          "Exit Criteria": "Risk methodology accepted by management.",
          "Related Artifacts": "RAM, RR",
          "Owner": "ISMS Manager",
          "Dependencies": "Scope and context stable",
          "Planned Start": "2026-09-09",
          "Planned Finish": "2026-09-13",
          "Actual Finish": "",
          "Evidence Reference": "RAM-APP-2026",
          "Status": "Planned",
          "Notes": "Use same scales for opportunities."
        },
        {
          "Phase ID": "PH-04",
          "Milestone": "Perform risk assessment",
          "Indicative Timing": "Week 3-4",
          "Work Performed": "Identify risks, assess likelihood and impact, assign owners and initial decisions.",
          "Exit Criteria": "Risk register reviewed and high risks prioritized.",
          "Related Artifacts": "AI, RR",
          "Owner": "Risk Owners",
          "Dependencies": "Asset inventory and risk method approved",
          "Planned Start": "2026-09-16",
          "Planned Finish": "2026-09-27",
          "Actual Finish": "",
          "Evidence Reference": "RR-2026-Q3",
          "Status": "Not started",
          "Notes": "Critical supplier risks included."
        },
        {
          "Phase ID": "PH-05",
          "Milestone": "Select controls and prepare SoA",
          "Indicative Timing": "Week 5",
          "Work Performed": "Map risks to Annex A controls, define applicability and justify exclusions.",
          "Exit Criteria": "SoA covers all Annex A controls and exclusions are justified.",
          "Related Artifacts": "SOA, ISOCTRL, RTP",
          "Owner": "ISMS Manager",
          "Dependencies": "Risk assessment ready",
          "Planned Start": "2026-09-30",
          "Planned Finish": "2026-10-04",
          "Actual Finish": "",
          "Evidence Reference": "SOA-2026-Q3",
          "Status": "Not started",
          "Notes": "Full 93-control coverage required."
        },
        {
          "Phase ID": "PH-06",
          "Milestone": "Implement treatment plan",
          "Indicative Timing": "Week 6-8",
          "Work Performed": "Assign treatment actions, deadlines, evidence owners and implementation status.",
          "Exit Criteria": "High-risk treatments have owners, due dates and evidence references.",
          "Related Artifacts": "RTP, CAR, DAL",
          "Owner": "Control Owners",
          "Dependencies": "SoA approved",
          "Planned Start": "2026-10-07",
          "Planned Finish": "2026-10-25",
          "Actual Finish": "",
          "Evidence Reference": "RTP-2026-Q4",
          "Status": "Not started",
          "Notes": "Track overdue actions weekly."
        },
        {
          "Phase ID": "PH-07",
          "Milestone": "Operate and collect evidence",
          "Indicative Timing": "Week 8-10",
          "Work Performed": "Run controls, collect records, resolve evidence gaps and prepare audit pack.",
          "Exit Criteria": "Evidence log complete for mandatory records and selected controls.",
          "Related Artifacts": "ELAI, MDR, ISOCTRL",
          "Owner": "Evidence Owners",
          "Dependencies": "Control operation started",
          "Planned Start": "2026-10-21",
          "Planned Finish": "2026-11-08",
          "Actual Finish": "",
          "Evidence Reference": "ELAI-2026-Q4",
          "Status": "Not started",
          "Notes": "Evidence freeze before internal audit."
        },
        {
          "Phase ID": "PH-08",
          "Milestone": "Review readiness",
          "Indicative Timing": "Week 11-12",
          "Work Performed": "Perform internal readiness review, resolve blockers and prepare management review input.",
          "Exit Criteria": "Open blockers tracked and management review decision recorded.",
          "Related Artifacts": "IAP, MRART, CAR",
          "Owner": "Internal Auditor",
          "Dependencies": "Evidence pack complete",
          "Planned Start": "2026-11-11",
          "Planned Finish": "2026-11-22",
          "Actual Finish": "",
          "Evidence Reference": "IAP-2026-Q4",
          "Status": "Not started",
          "Notes": "Pre-certification readiness gate."
        }
      ],
      "contentType": "register_table"
    },
    {
      "id": "implementation_review_decision",
      "title": "Implementation review decision",
      "values": {
        "Review result": "Implementation plan started; scope phase in progress and downstream phases scheduled",
        "Milestones reviewed": 8,
        "Completed milestones": 0,
        "At-risk milestones": 1,
        "Open blockers": "Confirm cloud support scope boundary",
        "Reviewed by": "ISMS Manager",
        "Decision date": "2026-08-29",
        "Evidence reference": "IMPL-P-REVIEW-2026-W35"
      },
      "rows": [
        {
          "Field": "Review result",
          "Value": "Implementation plan started; scope phase in progress and downstream phases scheduled"
        },
        {
          "Field": "Milestones reviewed",
          "Value": "8"
        },
        {
          "Field": "Completed milestones",
          "Value": "0"
        },
        {
          "Field": "At-risk milestones",
          "Value": "1"
        },
        {
          "Field": "Open blockers",
          "Value": "Confirm cloud support scope boundary"
        },
        {
          "Field": "Reviewed by",
          "Value": "ISMS Manager"
        },
        {
          "Field": "Decision date",
          "Value": "2026-08-29"
        },
        {
          "Field": "Evidence reference",
          "Value": "IMPL-P-REVIEW-2026-W35"
        }
      ],
      "contentType": "decision_table"
    },
    {
      "id": "external_references",
      "title": "References",
      "groups": [
        {
          "text": "Cite these sources from workshops and audits. This list names ISO clauses, book chapters and companion artifacts used by this file."
        },
        {
          "rows": [
            {
              "Kind": "ISO",
              "Reference": "ISO/IEC 27001:2022",
              "How this document uses it": "Normative source this artifact implements or cites.",
              "href": "https://www.iso.org/standard/82875.html"
            },
            {
              "Kind": "Book",
              "Reference": "Implementation & Certification, Implementation Readiness & Planning",
              "How this document uses it": "Primary operating chapter for this companion artifact.",
              "href": "https://www.amazon.com/s?k=ISO+27001+for+Software+Companies+Implementation+and+Certification"
            },
            {
              "Kind": "Artifact",
              "Reference": "IPR Interested Parties Register (Building the ISMS, Context of the Organization (Clause 4))",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/dp/9789908983448"
            },
            {
              "Kind": "Artifact",
              "Reference": "ISO Information Security Objectives (Building the ISMS, Information Security Policies & Risk Management)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/dp/9789908983448"
            },
            {
              "Kind": "Artifact",
              "Reference": "CR Context Register (Building the ISMS, Context of the Organization (Clause 4))",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/dp/9789908983448"
            },
            {
              "Kind": "Artifact",
              "Reference": "RR Risk Register (Building the ISMS, Planning, Risk & Objectives (Clause 6))",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/dp/9789908983448"
            }
          ]
        }
      ],
      "contentType": "reference_table"
    }
  ],
  "enrichment": {
    "source": "Example.json",
    "method": "curated-json",
    "note": "Completes Example JSON with renderer-native sections and generalized groups; no mdSource helper fields."
  },
  "snapshotRef": {
    "snapshotId": "arcfield.platform.surv.2026-09-11",
    "schemaVersion": "evidenceSnapshot.v1"
  },
  "scenarioRef": {
    "githubIssue": 64,
    "crId": "CR-TYPE-ARCFIELD-001",
    "family": "Register",
    "role": "Operating sample of the 11 September 2026 freeze"
  }
}
