{
  "schemaVersion": "artifactExample.v2",
  "artifactId": "ISMS-CL",
  "title": "ISMS Change Log",
  "definitionRef": {
    "artifactId": "ISMS-CL",
    "definitionSchemaVersion": "artifactDefinition.v2",
    "definitionId": "ISMS-CL.artifactDefinition.v2",
    "title": "ISMS Change Log"
  },
  "organization": "Arcfield",
  "sections": [
    {
      "id": "title_page",
      "title": "Title Page",
      "values": {
        "Register Title": "ISMS Change Log",
        "Register ID": "ISMS-CL-REG-001",
        "Version": "1.1",
        "Status": "Approved",
        "Organization": "Arcfield",
        "Owner": "ISMS Manager",
        "Approver": "Top Management",
        "Classification": "Internal",
        "Effective Date": "2026-09-11",
        "Next Review Date": "2027-09-11"
      },
      "items": [
        "Register Title: ISMS Change Log",
        "Register ID: ISMS-CL-REG-001",
        "Version: 1.1",
        "Status: Approved",
        "Organization: Arcfield",
        "Owner: ISMS Manager",
        "Approver: Top Management",
        "Classification: Internal",
        "Effective Date: 2026-09-11",
        "Next Review Date: 2027-09-11"
      ],
      "contentType": "metadata"
    },
    {
      "id": "abstract",
      "title": "Abstract",
      "text": "This example records Arcfield ISMS management-system changes with rationale, affected element, consequences, resources, owner, approval, implementation dates, effectiveness review and evidence. Entries are the dated Arcfield Platform operating log sampled on the 11 September 2026 freeze in the surveillance cycle after certificate ARC-ISMS-2025-001.",
      "contentType": "narrative"
    },
    {
      "id": "document_control",
      "title": "Document Control",
      "rows": [
        {
          "Property": "Purpose",
          "Value": "Track planned ISMS changes with consequences, resources, approval and effectiveness review."
        },
        {
          "Property": "Used by",
          "Value": "ISMS Manager, Top Management, Process Owners, Internal Auditor"
        },
        {
          "Property": "Maintained by",
          "Value": "ISMS Manager"
        },
        {
          "Property": "Evidence role",
          "Value": "Clause 6.3 planning-of-changes evidence"
        },
        {
          "Property": "ISO reference",
          "Value": "ISO/IEC 27001:2022 Clause 6.3, Clause 8.1 and Clause 10.2"
        },
        {
          "Property": "Review cadence",
          "Value": "Monthly and before management review"
        }
      ],
      "contentType": "control_table"
    },
    {
      "id": "instructions",
      "title": "Instructions",
      "items": [
        "Record management-system changes before implementation.",
        "Describe why the change is needed and which ISMS element is affected.",
        "Assess potential consequences, required resources and approval needs.",
        "Track planned and actual implementation dates.",
        "Record effectiveness review status after implementation.",
        "Link evidence for approval, implementation and review.",
        "Use sheets ending in “Ex” as read-only examples. Enter live data only on the matching “Wk” (Working) sheets.",
        "Every operative list is an Excel Table with frozen headers and filters. Add new rows on the next empty worksheet row beneath the table so Excel expands it — do not leave blank rows inside the table.",
        "Where a column offers a dropdown, choose a value from the list (Status, Owner role, Priority, Severity, Likelihood, Impact, Applicability, Evidence Status, Review Result). Do not invent free-text variants.",
        "Enter dates as YYYY-MM-DD. Date columns are validated and formatted accordingly.",
        "Review the Flag columns (Overdue, Review Due, Missing Owner, Missing Evidence). They calculate automatically and highlight gaps for follow-up.",
        "Keep Cover, Legal, Book, Lists and Metadata unchanged. System sheets are protected on purpose."
      ],
      "contentType": "ordered_list"
    },
    {
      "id": "isms_change_log",
      "title": "ISMS change log",
      "schemaRef": {
        "definitionId": "ISMS-CL.artifactDefinition.v2",
        "sectionId": "isms_change_log",
        "columnsRef": "sections.isms_change_log.columns"
      },
      "rows": [
        {
          "Change ID": "ISMS-CHG-001",
          "Change Description": "Extend ISMS scope to include customer support operations.",
          "Reason for Change": "Support team now handles confidential customer data.",
          "Affected ISMS Element": "Scope statement, asset inventory, access reviews and training scope",
          "Potential Consequences": "Additional evidence owners, access reviews and policy acknowledgement required.",
          "Resources Required": "ISMS Manager, Support Manager and IT Operations",
          "Owner": "ISMS Manager",
          "Approval Role": "Top Management",
          "Approval Date": "2026-08-12",
          "Planned Implementation Date": "2026-09-15",
          "Actual Implementation Date": "",
          "Status": "In progress",
          "Effectiveness Review": "Review in next management review after first access-review cycle.",
          "Evidence Reference": "ISS-SCOPE-2026-Q3",
          "Notes": "Related to IPR-001 customer evidence expectation."
        },
        {
          "Change ID": "ISMS-CHG-002",
          "Change Description": "Introduce automated evidence collection for access reviews.",
          "Reason for Change": "Reduce manual audit preparation effort and missed evidence records.",
          "Affected ISMS Element": "Evidence log, access review process and audit pack index",
          "Potential Consequences": "Integration failures may create incomplete evidence if monitoring is weak.",
          "Resources Required": "Security Engineer and ISMS Manager",
          "Owner": "Security Lead",
          "Approval Role": "ISMS Manager",
          "Approval Date": "2026-08-18",
          "Planned Implementation Date": "2026-10-01",
          "Actual Implementation Date": "",
          "Status": "Planned",
          "Effectiveness Review": "Pilot effectiveness check after first monthly access review.",
          "Evidence Reference": "ELAI-AUTO-2026-PILOT",
          "Notes": "Track integration exception if delayed."
        },
        {
          "Change ID": "ISMS-CHG-003",
          "Change Description": "Update risk methodology to include supplier concentration scoring.",
          "Reason for Change": "Critical cloud dependencies require clearer treatment prioritization.",
          "Affected ISMS Element": "Risk assessment method and supplier risk workflow",
          "Potential Consequences": "Existing supplier risks need reassessment and management review update.",
          "Resources Required": "Compliance Lead and Supplier Manager",
          "Owner": "Compliance Lead",
          "Approval Role": "Risk Committee",
          "Approval Date": "2026-08-20",
          "Planned Implementation Date": "2026-09-20",
          "Actual Implementation Date": "",
          "Status": "In progress",
          "Effectiveness Review": "Confirm revised scoring was applied to critical suppliers.",
          "Evidence Reference": "RAM-SUP-2026-Q3",
          "Notes": "Related to SINV and CSR."
        },
        {
          "Change ID": "ISMS-CHG-004",
          "Change Description": "Move management review cadence from semi-annual to quarterly.",
          "Reason for Change": "Certification preparation requires more frequent review of blockers.",
          "Affected ISMS Element": "Management review procedure and review calendar",
          "Potential Consequences": "Additional leadership time and updated evidence calendar required.",
          "Resources Required": "ISMS Manager and Top Management",
          "Owner": "ISMS Manager",
          "Approval Role": "Top Management",
          "Approval Date": "2026-07-28",
          "Planned Implementation Date": "2026-08-15",
          "Actual Implementation Date": "2026-08-15",
          "Status": "Implemented",
          "Effectiveness Review": "First quarterly review completed with three decisions logged.",
          "Evidence Reference": "MR-2026-Q3",
          "Notes": "Decision linked to DAL-REVIEW-2026-Q3."
        },
        {
          "Change ID": "ISMS-CHG-005",
          "Change Description": "Add privacy review checkpoint to secure development workflow.",
          "Reason for Change": "Production-like test data exception identified during data masking review.",
          "Affected ISMS Element": "Secure development, privacy review and change validation",
          "Potential Consequences": "Engineering workflow adds one review step before production-like data is used.",
          "Resources Required": "Engineering Lead and Privacy Lead",
          "Owner": "Engineering Lead",
          "Approval Role": "Privacy Lead",
          "Approval Date": "2026-08-23",
          "Planned Implementation Date": "2026-09-10",
          "Actual Implementation Date": "",
          "Status": "Open",
          "Effectiveness Review": "Review after two release cycles.",
          "Evidence Reference": "EXR-004",
          "Notes": "Linked to data masking exception."
        },
        {
          "Change ID": "ISMS-CHG-006",
          "Change Description": "Retire high-risk AI recruiting pilot from ISMS scope.",
          "Reason for Change": "AI governance review determined the pilot is not aligned with current risk appetite.",
          "Affected ISMS Element": "AI system inventory, risk register and evidence retention",
          "Potential Consequences": "Pilot evidence retained; future AI use requires governance approval.",
          "Resources Required": "AI Governance Owner and HR Manager",
          "Owner": "AI Governance Owner",
          "Approval Role": "Top Management",
          "Approval Date": "2026-08-25",
          "Planned Implementation Date": "2026-08-30",
          "Actual Implementation Date": "",
          "Status": "Planned",
          "Effectiveness Review": "Confirm decommissioning and evidence retention in next AI governance review.",
          "Evidence Reference": "AISGF-REVIEW-2026-Q3",
          "Notes": "No production processing performed."
        }
      ],
      "contentType": "register_table"
    },
    {
      "id": "change_review_decision",
      "title": "Change review decision",
      "values": {
        "Review result": "Six ISMS changes reviewed; one implemented and five tracked with owners and evidence references.",
        "Changes reviewed": 6,
        "Implemented changes": 1,
        "Open changes": 5,
        "Effectiveness reviews pending": 5,
        "Reviewed by": "ISMS Manager",
        "Decision date": "2026-08-29",
        "Evidence reference": "ISMS-CL-REVIEW-2026-Q3"
      },
      "rows": [
        {
          "Field": "Review result",
          "Value": "Six ISMS changes reviewed; one implemented and five tracked with owners and evidence references."
        },
        {
          "Field": "Changes reviewed",
          "Value": "6"
        },
        {
          "Field": "Implemented changes",
          "Value": "1"
        },
        {
          "Field": "Open changes",
          "Value": "5"
        },
        {
          "Field": "Effectiveness reviews pending",
          "Value": "5"
        },
        {
          "Field": "Reviewed by",
          "Value": "ISMS Manager"
        },
        {
          "Field": "Decision date",
          "Value": "2026-08-29"
        },
        {
          "Field": "Evidence reference",
          "Value": "ISMS-CL-REVIEW-2026-Q3"
        }
      ],
      "contentType": "decision_table"
    },
    {
      "id": "external_references",
      "title": "References",
      "groups": [
        {
          "text": "Cite these sources from workshops and audits. This list names ISO clauses, book chapters and companion artifacts used by this file."
        },
        {
          "rows": [
            {
              "Kind": "ISO",
              "Reference": "ISO/IEC 27001:2022 6.3",
              "How this document uses it": "Normative source this artifact implements or cites.",
              "href": "https://www.iso.org/standard/82875.html"
            },
            {
              "Kind": "Book",
              "Reference": "Implementation & Certification, Implementation Readiness & Planning",
              "How this document uses it": "Primary operating chapter for this companion artifact.",
              "href": "https://www.amazon.com/s?k=ISO+27001+for+Software+Companies+Implementation+and+Certification"
            },
            {
              "Kind": "Artifact",
              "Reference": "AI Asset Inventory (Implementation & Certification, Asset Management & Information Classification)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/s?k=ISO+27001+for+Software+Companies+Implementation+and+Certification"
            },
            {
              "Kind": "Artifact",
              "Reference": "ISO Information Security Objectives (Building the ISMS, Information Security Policies & Risk Management)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/dp/9789908983448"
            },
            {
              "Kind": "Artifact",
              "Reference": "AISGF AI System Governance File (Dual Compliance, Multi-framework Operating Model)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/dp/9789908983479"
            },
            {
              "Kind": "Artifact",
              "Reference": "CSR Critical Services Register (Dual Compliance, Multi-framework Operating Model)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/dp/9789908983479"
            }
          ]
        }
      ],
      "contentType": "reference_table"
    }
  ],
  "enrichment": {
    "source": "Example.json",
    "method": "curated-json",
    "note": "Completes Example JSON with renderer-native sections and generalized groups; no mdSource helper fields."
  },
  "snapshotRef": {
    "snapshotId": "arcfield.platform.surv.2026-09-11",
    "schemaVersion": "evidenceSnapshot.v1"
  },
  "scenarioRef": {
    "githubIssue": 64,
    "crId": "CR-TYPE-ARCFIELD-001",
    "family": "Log",
    "role": "Dated operating log sampled on the freeze"
  }
}
