{
  "schemaVersion": "artifactDefinition.v2",
  "definitionId": "LRR.artifactDefinition.v2",
  "artifactId": "LRR",
  "title": "Legal, Regulatory and Contractual Requirements Register",
  "artifactType": "Register",
  "format": "xlsx",
  "productTier": "Premium",
  "definitionRole": "contract",
  "sourceModel": {
    "body": "canonical human-readable register maintained in the Artifact Candidate page",
    "jsonDefinition": "machine-readable contract and validation model",
    "jsonExample": "curated realistic example data fixture"
  },
  "purpose": "Define the required structure for documenting legal, regulatory, contractual, privacy and intellectual-property requirements relevant to the ISMS, including applicability, ownership, evidence and review cadence.",
  "sections": [
    {
      "order": 1,
      "id": "title_page",
      "title": "Title Page",
      "contentType": "metadata",
      "required": true,
      "hint": null
    },
    {
      "order": 2,
      "id": "abstract",
      "title": "Abstract",
      "contentType": "narrative",
      "required": true,
      "hint": {
        "text": "Use LRR to turn external obligations into clear ISMS requirements, owners and evidence expectations.",
        "bookReference": "Volume 1, S-02-04-00 Legal, Regulatory & Contractual Requi"
      }
    },
    {
      "order": 3,
      "id": "document_control",
      "title": "Document Control",
      "contentType": "control_table",
      "required": true,
      "hint": null
    },
    {
      "order": 4,
      "id": "instructions",
      "title": "Instructions",
      "contentType": "ordered_list",
      "required": true,
      "hint": {
        "text": "Capture only obligations relevant to the ISMS and link each obligation to evidence or a planned action.",
        "bookReference": "Volume 1, S-02-04-00 Legal, Regulatory & Contractual Requi"
      },
      "intro": "Complete the Working sheets using the example tabs as a model. Follow the workbook usage rules below."
    },
    {
      "order": 5,
      "id": "requirements_register",
      "title": "Requirements register",
      "contentType": "register_table",
      "required": true,
      "minimumExampleRows": 6,
      "columns": [
        {
          "name": "Requirement ID",
          "type": "text",
          "required": "yes",
          "description": "Unique requirement reference.",
          "example": "LRR-001"
        },
        {
          "name": "Requirement Type",
          "type": "select",
          "required": "yes",
          "description": "Legal, regulatory, contractual, privacy, IP or ISO.",
          "example": "Privacy"
        },
        {
          "name": "Requirement Source",
          "type": "text",
          "required": "yes",
          "description": "Law, regulation, contract, standard or policy.",
          "example": "GDPR"
        },
        {
          "name": "Requirement Summary",
          "type": "text",
          "required": "yes",
          "description": "Plain-language obligation.",
          "example": "Processing must be lawful"
        },
        {
          "name": "Applicability",
          "type": "select",
          "required": "yes",
          "description": "Applicable, not applicable or to assess.",
          "example": "Applicable",
          "valueSet": "domain.applicability",
          "options": [
            "Applicable",
            "Not Applicable",
            "Partially Applicable"
          ],
          "validation": {
            "allowBlank": false,
            "errorTitle": "Invalid value",
            "error": "Select a value from the list."
          }
        },
        {
          "name": "ISMS Relevance",
          "type": "text",
          "required": "yes",
          "description": "Why the obligation matters to the ISMS.",
          "example": "Customer data in scope"
        },
        {
          "name": "How We Satisfy It",
          "type": "text",
          "required": "yes",
          "description": "Organization approach.",
          "example": "Maintain DPAR"
        },
        {
          "name": "Owner",
          "type": "select",
          "required": "yes",
          "description": "Accountable owner.",
          "example": "Legal Counsel",
          "valueSet": "domain.owner",
          "options": [
            "ISMS Manager",
            "Control Owner",
            "Risk Owner",
            "Process Owner",
            "Asset Owner",
            "IT Security",
            "HR",
            "Legal",
            "Executive Management",
            "Internal Audit"
          ],
          "validation": {
            "allowBlank": false,
            "errorTitle": "Invalid value",
            "error": "Select a value from the list."
          }
        },
        {
          "name": "Affected Process or Control",
          "type": "text",
          "required": "yes",
          "description": "Linked process, clause, control or artifact.",
          "example": "A.5.34"
        },
        {
          "name": "Evidence Reference",
          "type": "text",
          "required": "yes",
          "description": "Evidence record.",
          "example": "DPAR-2026-Q3"
        },
        {
          "name": "Review Frequency",
          "type": "text",
          "required": "yes",
          "description": "Review cadence.",
          "example": "Quarterly"
        },
        {
          "name": "Status",
          "type": "select",
          "required": "yes",
          "description": "Active, action open, retired or to assess.",
          "example": "Active",
          "valueSet": "domain.status.generic",
          "options": [
            "Draft",
            "In Progress",
            "Under Review",
            "Approved",
            "Closed",
            "Deferred"
          ],
          "validation": {
            "allowBlank": false,
            "errorTitle": "Invalid value",
            "error": "Select a value from the list."
          }
        },
        {
          "name": "Notes",
          "type": "text",
          "required": "no",
          "description": "Additional context.",
          "example": "Review after service change."
        }
      ],
      "hint": {
        "text": "Each row should explain the obligation, why it applies, how it is satisfied and what evidence proves it.",
        "bookReference": "Volume 1, S-02-04-00 Legal, Regulatory & Contractual Requi"
      }
    },
    {
      "order": 6,
      "id": "requirements_review_decision",
      "title": "Requirements review decision",
      "contentType": "decision_table",
      "required": true,
      "fields": [
        {
          "name": "Review result",
          "type": "select",
          "required": "yes",
          "valueSet": "domain.reviewResult",
          "options": [
            "Pass",
            "Pass with observations",
            "Fail",
            "Deferred"
          ],
          "validation": {
            "allowBlank": false,
            "errorTitle": "Invalid value",
            "error": "Select a value from the list."
          }
        },
        {
          "name": "Requirements reviewed",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "New or changed requirements",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Open actions",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Reviewed by",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Decision date",
          "type": "date",
          "required": "yes"
        },
        {
          "name": "Evidence reference",
          "type": "text",
          "required": "yes"
        }
      ],
      "hint": {
        "text": "Close with a review decision so changed obligations feed risk treatment, supplier management and management review.",
        "bookReference": "Volume 1, S-02-04-00 Legal, Regulatory & Contractual Requi"
      }
    },
    {
      "order": 7,
      "id": "external_references",
      "title": "References",
      "contentType": "reference_table",
      "required": true
    }
  ],
  "validationRules": [
    "JSON Example must contain definitionRef pointing to LRR.artifactDefinition.v2.",
    "JSON Example register sections must contain schemaRef pointing to the matching definition section.",
    "Requirement rows must include source, summary, applicability, ISMS relevance, satisfaction approach, owner, evidence reference and review frequency.",
    "Body must render the contract schema and the example data.",
    "No standalone Book reference section and no generic Sample placeholders are allowed."
  ],
  "enrichment": {
    "source": "Contract.json",
    "method": "curated-json",
    "note": "Completes Contract JSON from MD-only schema/sections, removes duplicate alias sections, and normalizes string columns into structured column objects."
  },
  "editorialStandard": {
    "isoAnchors": [
      {
        "label": "ISO/IEC 27001:2022 4.2",
        "href": "https://www.iso.org/standard/82875.html",
        "role": "Normative source this artifact implements or cites."
      },
      {
        "label": "ISO/IEC 27001:2022",
        "href": "https://www.iso.org/standard/82875.html",
        "role": "Normative source this artifact implements or cites."
      },
      {
        "label": "ISO/IEC 27001:2022 7.5",
        "href": "https://www.iso.org/standard/82875.html",
        "role": "Documented information: identify, review and cite this workbook by version."
      }
    ],
    "bookSources": [
      {
        "series": "ISO 27001 for Software Companies",
        "volume": 1,
        "volumeTitle": "Building the ISMS",
        "chapterId": "S-02-04-00",
        "chapterTitle": "Legal, Regulatory & Contractual Requi",
        "primary": true,
        "role": "Primary operating chapter for this companion artifact.",
        "href": "https://www.amazon.com/dp/9789908983448"
      },
      {
        "series": "ISO 27001 for Software Companies",
        "volume": 1,
        "volumeTitle": "Building the ISMS",
        "chapterId": "S-00-03-00",
        "chapterTitle": "Planning, Risk & Objectives (Clause 6)",
        "primary": false,
        "role": "Documented information, review and version discipline.",
        "href": "https://www.amazon.com/dp/9789908983448"
      }
    ],
    "acronyms": [
      {
        "abbr": "ISMS",
        "longForm": "Information Security Management System"
      },
      {
        "abbr": "SaaS",
        "longForm": "Software as a Service"
      },
      {
        "abbr": "CIA",
        "longForm": "Confidentiality, Integrity, and Availability"
      },
      {
        "abbr": "CI/CD",
        "longForm": "Continuous Integration / Continuous Delivery"
      },
      {
        "abbr": "CI",
        "longForm": "Continuous Integration"
      },
      {
        "abbr": "CD",
        "longForm": "Continuous Delivery"
      },
      {
        "abbr": "BCP",
        "longForm": "Business Continuity Plan"
      },
      {
        "abbr": "CSR",
        "longForm": "Certificate Signing Request"
      },
      {
        "abbr": "DRP",
        "longForm": "Disaster Recovery Plan"
      },
      {
        "abbr": "GDPR",
        "longForm": "General Data Protection Regulation"
      },
      {
        "abbr": "IP",
        "longForm": "Internet Protocol"
      },
      {
        "abbr": "JSON",
        "longForm": "JavaScript Object Notation"
      },
      {
        "abbr": "SoA",
        "longForm": "Statement of Applicability"
      }
    ],
    "must": [
      "Keep one live row per record on Working sheets. Do not merge several cases into one row.",
      "Example sheets must contain realistic Arcfield rows for every required sheet. Empty required cells are not an example."
    ],
    "mustNot": [
      "Do not invent live rows in the renderer. Example data lives in the Example JSON.",
      "Do not treat Ex example tabs as working sheets. Do not put live data on system sheets."
    ],
    "softwareCompanyAdaptations": [
      "Use Arcfield as the worked example (cover variant A).",
      "Name SaaS, CI/CD, privileged access or supplier interfaces in example rows where they affect this register."
    ],
    "exampleWorkbook": {
      "workedExampleOrg": "Arcfield",
      "requiredSheets": [
        "requirements_register",
        "requirements_review_decision"
      ],
      "minExampleRows": 6,
      "coverFromExample": true
    }
  },
  "editorialContractId": "editorial.xlsx.register.v1",
  "contentContractId": "content.register.items.v1"
}
