{
  "schemaVersion": "artifactExample.v2",
  "artifactId": "MDR",
  "title": "Mandatory Documents and Records Register",
  "definitionRef": {
    "artifactId": "MDR",
    "definitionSchemaVersion": "artifactDefinition.v2",
    "definitionId": "MDR.artifactDefinition.v2",
    "title": "Mandatory Documents and Records Register"
  },
  "organization": "Arcfield",
  "sections": [
    {
      "id": "title_page",
      "title": "Title Page",
      "values": {
        "Register Title": "Mandatory Documents and Records Register",
        "Register ID": "MDR-REG-001",
        "Version": "1.1",
        "Status": "Approved",
        "Organization": "Arcfield",
        "Owner": "ISMS Manager",
        "Approver": "Top Management",
        "Classification": "Internal",
        "Effective Date": "2026-09-11",
        "Next Review Date": "2027-09-11"
      },
      "items": [
        "Register Title: Mandatory Documents and Records Register",
        "Register ID: MDR-REG-001",
        "Version: 1.1",
        "Status: Approved",
        "Organization: Arcfield",
        "Owner: ISMS Manager",
        "Approver: Top Management",
        "Classification: Internal",
        "Effective Date: 2026-09-11",
        "Next Review Date: 2027-09-11"
      ],
      "contentType": "metadata"
    },
    {
      "id": "abstract",
      "title": "Abstract",
      "text": "This example tracks the complete Arcfield mandatory ISO 27001 document and record set with ownership, approval, location, version, review dates, evidence references and readiness notes. Rows are the 11 September 2026 operating sample of the certified Arcfield Platform ISMS in the surveillance cycle after certificate ARC-ISMS-2025-001.",
      "contentType": "narrative"
    },
    {
      "id": "document_control",
      "title": "Document Control",
      "rows": [
        {
          "Property": "Purpose",
          "Value": "Track the 27 mandatory ISO 27001 documents and records."
        },
        {
          "Property": "Used by",
          "Value": "ISMS Manager, Document Owners, Internal Auditor, Top Management"
        },
        {
          "Property": "Maintained by",
          "Value": "ISMS Manager"
        },
        {
          "Property": "Evidence role",
          "Value": "Mandatory documented-information and audit-readiness evidence"
        },
        {
          "Property": "ISO reference",
          "Value": "ISO/IEC 27001:2022 Clauses 4.3, 5.2, 6.1.2, 6.1.3, 6.2, 7.2, 7.5, 8.1, 8.2, 8.3, 9.1, 9.2, 9.3, 10.1 and Annex A controls A 5.9, A 5.10, A 5.15, A 5.16, A 5.17, A 8.2, A 8.3, A 8.9, A 8.10 and A 8.15"
        },
        {
          "Property": "Review cadence",
          "Value": "Monthly during implementation and before audits"
        }
      ],
      "contentType": "control_table"
    },
    {
      "id": "instructions",
      "title": "Instructions",
      "items": [
        "List each of the 27 mandatory documents or records required for the ISMS.",
        "Record the ISO reference, purpose, owner, approver and controlled location.",
        "Track version, status and review dates.",
        "Link the evidence reference used for audits.",
        "Review missing or outdated items before readiness reviews and management review.",
        "Use sheets ending in “Ex” as read-only examples. Enter live data only on the matching “Wk” (Working) sheets.",
        "Every operative list is an Excel Table with frozen headers and filters. Add new rows on the next empty worksheet row beneath the table so Excel expands it — do not leave blank rows inside the table.",
        "Where a column offers a dropdown, choose a value from the list (Status, Owner role, Priority, Severity, Likelihood, Impact, Applicability, Evidence Status, Review Result). Do not invent free-text variants.",
        "Enter dates as YYYY-MM-DD. Date columns are validated and formatted accordingly.",
        "Review the Flag columns (Overdue, Review Due, Missing Owner, Missing Evidence). They calculate automatically and highlight gaps for follow-up.",
        "Keep Cover, Legal, Book, Lists and Metadata unchanged. System sheets are protected on purpose."
      ],
      "contentType": "ordered_list"
    },
    {
      "id": "mandatory_documents_register",
      "title": "Mandatory documents and records register",
      "schemaRef": {
        "definitionId": "MDR.artifactDefinition.v2",
        "sectionId": "mandatory_documents_register",
        "columnsRef": "sections.mandatory_documents_register.columns"
      },
      "rows": [
        {
          "Record ID": "MDR-001",
          "Document or Record": "ISMS scope statement",
          "ISO Reference": "Clause 4.3",
          "Mandatory Status": "Mandatory document",
          "Purpose": "Define ISMS boundaries and applicability.",
          "Owner": "ISMS Manager",
          "Approver": "Top Management",
          "Location": "ISS-2026",
          "Version": "1.0",
          "Status": "Approved",
          "Last Review Date": "2026-08-12",
          "Next Review Date": "2026-11-12",
          "Evidence Reference": "ISS-SCOPE-2026-Q3",
          "Notes": "Customer support scope change pending.",
          "Evidence reference": "ISS-SCOPE-2026-Q3"
        },
        {
          "Record ID": "MDR-002",
          "Document or Record": "Information security policy",
          "ISO Reference": "Clause 5.2",
          "Mandatory Status": "Mandatory document",
          "Purpose": "Set management direction and security commitments.",
          "Owner": "ISMS Manager",
          "Approver": "CEO",
          "Location": "ISP-001",
          "Version": "2.0",
          "Status": "Approved",
          "Last Review Date": "2026-08-01",
          "Next Review Date": "2027-08-01",
          "Evidence Reference": "AUP-ACK-2026-Q3",
          "Notes": "Published to all employees.",
          "Evidence reference": "AUP-ACK-2026-Q3"
        },
        {
          "Record ID": "MDR-003",
          "Document or Record": "Information security risk assessment process",
          "ISO Reference": "Clause 6.1.2",
          "Mandatory Status": "Mandatory document",
          "Purpose": "Define consistent risk assessment criteria.",
          "Owner": "Compliance Lead",
          "Approver": "Risk Committee",
          "Location": "RAM-APP-2026",
          "Version": "1.1",
          "Status": "Update in progress",
          "Last Review Date": "2026-08-20",
          "Next Review Date": "2026-09-20",
          "Evidence Reference": "RAM-SUP-2026-Q3",
          "Notes": "Supplier concentration scoring being added.",
          "Evidence reference": "RAM-SUP-2026-Q3"
        },
        {
          "Record ID": "MDR-004",
          "Document or Record": "Information security risk treatment process",
          "ISO Reference": "Clause 6.1.3",
          "Mandatory Status": "Mandatory document",
          "Purpose": "Define risk treatment selection, approval and tracking rules.",
          "Owner": "ISMS Manager",
          "Approver": "Top Management",
          "Location": "RTP-STD-2026",
          "Version": "1.0",
          "Status": "Active",
          "Last Review Date": "2026-08-29",
          "Next Review Date": "2026-09-15",
          "Evidence Reference": "RTP-REVIEW-2026-Q3",
          "Notes": "Aligned with current risk register workflow.",
          "Evidence reference": "RTP-REVIEW-2026-Q3"
        },
        {
          "Record ID": "MDR-005",
          "Document or Record": "Statement of Applicability",
          "ISO Reference": "Clause 6.1.3 d",
          "Mandatory Status": "Mandatory document",
          "Purpose": "Document Annex A applicability and justification.",
          "Owner": "ISMS Manager",
          "Approver": "Top Management",
          "Location": "SOA-2026-Q3",
          "Version": "1.0",
          "Status": "Approved",
          "Last Review Date": "2026-08-29",
          "Next Review Date": "2026-11-29",
          "Evidence Reference": "SOA-FULL-93-2026",
          "Notes": "All 93 Annex A controls covered.",
          "Evidence reference": "SOA-FULL-93-2026"
        },
        {
          "Record ID": "MDR-006",
          "Document or Record": "Information security objectives",
          "ISO Reference": "Clause 6.2",
          "Mandatory Status": "Mandatory document",
          "Purpose": "Track measurable ISMS objectives.",
          "Owner": "ISMS Manager",
          "Approver": "Top Management",
          "Location": "ISO-REG-001",
          "Version": "1.0",
          "Status": "Active",
          "Last Review Date": "2026-08-29",
          "Next Review Date": "2026-11-29",
          "Evidence Reference": "ISO-REVIEW-2026-Q3",
          "Notes": "Two objectives at risk.",
          "Evidence reference": "ISO-REVIEW-2026-Q3"
        },
        {
          "Record ID": "MDR-007",
          "Document or Record": "Evidence of competence",
          "ISO Reference": "Clause 7.2",
          "Mandatory Status": "Mandatory record",
          "Purpose": "Evidence competence and role-specific training.",
          "Owner": "HR Manager",
          "Approver": "ISMS Manager",
          "Location": "TR-2026-Q3",
          "Version": "1.0",
          "Status": "Active",
          "Last Review Date": "2026-08-29",
          "Next Review Date": "2026-09-30",
          "Evidence Reference": "TRAIN-REC-2026-188",
          "Notes": "Contractor reminders open.",
          "Evidence reference": "TRAIN-REC-2026-188"
        },
        {
          "Record ID": "MDR-008",
          "Document or Record": "Documented information required by the ISMS",
          "ISO Reference": "Clause 7.5",
          "Mandatory Status": "Mandatory document",
          "Purpose": "Control required ISMS policies, procedures and records.",
          "Owner": "Document Control Owner",
          "Approver": "ISMS Manager",
          "Location": "DOC-CONTROL-2026",
          "Version": "1.0",
          "Status": "Approved",
          "Last Review Date": "2026-08-29",
          "Next Review Date": "2026-11-29",
          "Evidence Reference": "DOC-LIST-2026-Q3",
          "Notes": "Linked to controlled document repository.",
          "Evidence reference": "DOC-LIST-2026-Q3"
        },
        {
          "Record ID": "MDR-009",
          "Document or Record": "Operational planning and control records",
          "ISO Reference": "Clause 8.1",
          "Mandatory Status": "Mandatory record",
          "Purpose": "Evidence planned ISMS operations and controlled changes.",
          "Owner": "Operations Manager",
          "Approver": "ISMS Manager",
          "Location": "OPC-2026-Q3",
          "Version": "1.0",
          "Status": "Active",
          "Last Review Date": "2026-08-29",
          "Next Review Date": "2026-10-31",
          "Evidence Reference": "OPC-CHANGE-LOG-2026-Q3",
          "Notes": "Includes security change approvals.",
          "Evidence reference": "OPC-CHANGE-LOG-2026-Q3"
        },
        {
          "Record ID": "MDR-010",
          "Document or Record": "Risk assessment results",
          "ISO Reference": "Clause 8.2",
          "Mandatory Status": "Mandatory record",
          "Purpose": "Evidence completed information security risk assessments.",
          "Owner": "Compliance Lead",
          "Approver": "Risk Committee",
          "Location": "RAR-2026-Q3",
          "Version": "1.0",
          "Status": "Approved",
          "Last Review Date": "2026-08-29",
          "Next Review Date": "2026-11-29",
          "Evidence Reference": "RISK-ASSESS-2026-Q3",
          "Notes": "Includes supplier and cloud platform risks.",
          "Evidence reference": "RISK-ASSESS-2026-Q3"
        },
        {
          "Record ID": "MDR-011",
          "Document or Record": "Risk treatment results",
          "ISO Reference": "Clause 8.3",
          "Mandatory Status": "Mandatory record",
          "Purpose": "Evidence implemented and monitored risk treatments.",
          "Owner": "ISMS Manager",
          "Approver": "Top Management",
          "Location": "RTR-2026-Q3",
          "Version": "1.0",
          "Status": "Active",
          "Last Review Date": "2026-08-29",
          "Next Review Date": "2026-10-15",
          "Evidence Reference": "RTP-STATUS-2026-Q3",
          "Notes": "One high-risk treatment overdue.",
          "Evidence reference": "RTP-STATUS-2026-Q3"
        },
        {
          "Record ID": "MDR-012",
          "Document or Record": "Monitoring and measurement results",
          "ISO Reference": "Clause 9.1",
          "Mandatory Status": "Mandatory record",
          "Purpose": "Evidence ISMS performance monitoring and measurement.",
          "Owner": "Internal Auditor",
          "Approver": "ISMS Manager",
          "Location": "MME-2026-Q3",
          "Version": "1.0",
          "Status": "Draft",
          "Last Review Date": "2026-08-29",
          "Next Review Date": "2026-09-20",
          "Evidence Reference": "MME-DASH-2026-Q3",
          "Notes": "Dashboard SLA chart pending.",
          "Evidence reference": "MME-DASH-2026-Q3"
        },
        {
          "Record ID": "MDR-013",
          "Document or Record": "Internal audit programme",
          "ISO Reference": "Clause 9.2",
          "Mandatory Status": "Mandatory record",
          "Purpose": "Evidence planned internal audit scope, cadence and responsibilities.",
          "Owner": "Internal Auditor",
          "Approver": "ISMS Manager",
          "Location": "IAP-2026-Q4",
          "Version": "1.0",
          "Status": "Planned",
          "Last Review Date": "2026-08-29",
          "Next Review Date": "2026-11-22",
          "Evidence Reference": "IAP-PLAN-2026-Q4",
          "Notes": "Evidence freeze pending.",
          "Evidence reference": "IAP-PLAN-2026-Q4"
        },
        {
          "Record ID": "MDR-014",
          "Document or Record": "Internal audit results",
          "ISO Reference": "Clause 9.2",
          "Mandatory Status": "Mandatory record",
          "Purpose": "Evidence audit findings, conclusions and follow-up actions.",
          "Owner": "Internal Auditor",
          "Approver": "ISMS Manager",
          "Location": "IAR-2026-Q4",
          "Version": "1.0",
          "Status": "Planned",
          "Last Review Date": "2026-08-29",
          "Next Review Date": "2026-12-15",
          "Evidence Reference": "IAR-FINDINGS-2026-Q4",
          "Notes": "To be completed after Q4 audit.",
          "Evidence reference": "IAR-FINDINGS-2026-Q4"
        },
        {
          "Record ID": "MDR-015",
          "Document or Record": "Management review results",
          "ISO Reference": "Clause 9.3",
          "Mandatory Status": "Mandatory record",
          "Purpose": "Evidence management review decisions and actions.",
          "Owner": "ISMS Manager",
          "Approver": "Top Management",
          "Location": "MR-2026-Q3",
          "Version": "1.0",
          "Status": "Approved",
          "Last Review Date": "2026-08-12",
          "Next Review Date": "2026-11-12",
          "Evidence Reference": "MRART-2026-Q3",
          "Notes": "Quarterly cadence approved.",
          "Evidence reference": "MRART-2026-Q3"
        },
        {
          "Record ID": "MDR-016",
          "Document or Record": "Nonconformity records",
          "ISO Reference": "Clause 10.1",
          "Mandatory Status": "Mandatory record",
          "Purpose": "Track nonconformities, causes and containment actions.",
          "Owner": "ISMS Manager",
          "Approver": "Top Management",
          "Location": "NC-LOG-2026",
          "Version": "1.0",
          "Status": "Active",
          "Last Review Date": "2026-08-29",
          "Next Review Date": "2026-09-30",
          "Evidence Reference": "NC-2026-Q3",
          "Notes": "One minor nonconformity under review.",
          "Evidence reference": "NC-2026-Q3"
        },
        {
          "Record ID": "MDR-017",
          "Document or Record": "Corrective action results",
          "ISO Reference": "Clause 10.1",
          "Mandatory Status": "Mandatory record",
          "Purpose": "Evidence corrective actions and effectiveness checks.",
          "Owner": "Process Owner",
          "Approver": "ISMS Manager",
          "Location": "CAPA-2026",
          "Version": "1.0",
          "Status": "Active",
          "Last Review Date": "2026-08-29",
          "Next Review Date": "2026-10-31",
          "Evidence Reference": "CAPA-EFF-2026-Q3",
          "Notes": "Effectiveness review scheduled.",
          "Evidence reference": "CAPA-EFF-2026-Q3"
        },
        {
          "Record ID": "MDR-018",
          "Document or Record": "Inventory of information and associated assets",
          "ISO Reference": "A 5.9",
          "Mandatory Status": "Mandatory record",
          "Purpose": "Maintain ownership and classification of information assets.",
          "Owner": "Asset Manager",
          "Approver": "ISMS Manager",
          "Location": "AAR-2026",
          "Version": "1.0",
          "Status": "Active",
          "Last Review Date": "2026-08-29",
          "Next Review Date": "2026-11-29",
          "Evidence Reference": "ASSET-INV-2026-Q3",
          "Notes": "Cloud service inventory reconciliation pending.",
          "Evidence reference": "ASSET-INV-2026-Q3"
        },
        {
          "Record ID": "MDR-019",
          "Document or Record": "Acceptable use rules for information and associated assets",
          "ISO Reference": "A 5.10",
          "Mandatory Status": "Mandatory document",
          "Purpose": "Define acceptable use of information, systems and assets.",
          "Owner": "ISMS Manager",
          "Approver": "Top Management",
          "Location": "AUP-001",
          "Version": "2.1",
          "Status": "Approved",
          "Last Review Date": "2026-08-01",
          "Next Review Date": "2027-08-01",
          "Evidence Reference": "AUP-ACK-2026-Q3",
          "Notes": "Acknowledgement campaign completed.",
          "Evidence reference": "AUP-ACK-2026-Q3"
        },
        {
          "Record ID": "MDR-020",
          "Document or Record": "Access control policy or rules",
          "ISO Reference": "A 5.15",
          "Mandatory Status": "Mandatory document",
          "Purpose": "Define access control principles and authorization rules.",
          "Owner": "IT Manager",
          "Approver": "ISMS Manager",
          "Location": "ACP-001",
          "Version": "1.2",
          "Status": "Approved",
          "Last Review Date": "2026-08-10",
          "Next Review Date": "2027-02-10",
          "Evidence Reference": "ACCESS-POL-2026-Q3",
          "Notes": "Aligned with privileged access review.",
          "Evidence reference": "ACCESS-POL-2026-Q3"
        },
        {
          "Record ID": "MDR-021",
          "Document or Record": "Identity management records",
          "ISO Reference": "A 5.16",
          "Mandatory Status": "Mandatory record",
          "Purpose": "Evidence identity lifecycle management.",
          "Owner": "IT Operations",
          "Approver": "IT Manager",
          "Location": "IAM-REC-2026",
          "Version": "1.0",
          "Status": "Active",
          "Last Review Date": "2026-08-29",
          "Next Review Date": "2026-09-30",
          "Evidence Reference": "JOINER-MOVER-LEAVER-2026-Q3",
          "Notes": "Leaver evidence sampled for audit.",
          "Evidence reference": "JOINER-MOVER-LEAVER-2026-Q3"
        },
        {
          "Record ID": "MDR-022",
          "Document or Record": "Authentication information allocation and management records",
          "ISO Reference": "A 5.17",
          "Mandatory Status": "Mandatory record",
          "Purpose": "Evidence controlled allocation and management of authentication information.",
          "Owner": "IT Operations",
          "Approver": "IT Manager",
          "Location": "AUTH-REC-2026",
          "Version": "1.0",
          "Status": "Active",
          "Last Review Date": "2026-08-29",
          "Next Review Date": "2026-10-31",
          "Evidence Reference": "MFA-SECRETS-2026-Q3",
          "Notes": "MFA exceptions tracked separately.",
          "Evidence reference": "MFA-SECRETS-2026-Q3"
        },
        {
          "Record ID": "MDR-023",
          "Document or Record": "Privileged access rights records",
          "ISO Reference": "A 8.2",
          "Mandatory Status": "Mandatory record",
          "Purpose": "Evidence approval and review of privileged access rights.",
          "Owner": "IT Manager",
          "Approver": "ISMS Manager",
          "Location": "PAR-2026-Q3",
          "Version": "1.0",
          "Status": "Active",
          "Last Review Date": "2026-08-29",
          "Next Review Date": "2026-09-29",
          "Evidence Reference": "PRIV-ACCESS-REVIEW-2026-Q3",
          "Notes": "Two stale admin accounts removed.",
          "Evidence reference": "PRIV-ACCESS-REVIEW-2026-Q3"
        },
        {
          "Record ID": "MDR-024",
          "Document or Record": "Information access restriction rules",
          "ISO Reference": "A 8.3",
          "Mandatory Status": "Mandatory document",
          "Purpose": "Define restrictions for access to information and application functions.",
          "Owner": "Application Owner",
          "Approver": "IT Manager",
          "Location": "IAR-RULES-2026",
          "Version": "1.0",
          "Status": "Approved",
          "Last Review Date": "2026-08-29",
          "Next Review Date": "2027-02-28",
          "Evidence Reference": "APP-RBAC-2026-Q3",
          "Notes": "Role matrix updated for support team.",
          "Evidence reference": "APP-RBAC-2026-Q3"
        },
        {
          "Record ID": "MDR-025",
          "Document or Record": "Secure configuration records",
          "ISO Reference": "A 8.9",
          "Mandatory Status": "Mandatory record",
          "Purpose": "Evidence baseline configurations and configuration changes.",
          "Owner": "Platform Lead",
          "Approver": "IT Manager",
          "Location": "SCB-2026",
          "Version": "1.0",
          "Status": "Active",
          "Last Review Date": "2026-08-29",
          "Next Review Date": "2026-11-29",
          "Evidence Reference": "CIS-BASELINE-2026-Q3",
          "Notes": "Linux baseline exceptions approved.",
          "Evidence reference": "CIS-BASELINE-2026-Q3"
        },
        {
          "Record ID": "MDR-026",
          "Document or Record": "Information deletion records",
          "ISO Reference": "A 8.10",
          "Mandatory Status": "Mandatory record",
          "Purpose": "Evidence secure deletion of information according to retention rules.",
          "Owner": "Data Protection Lead",
          "Approver": "ISMS Manager",
          "Location": "DEL-LOG-2026",
          "Version": "1.0",
          "Status": "Active",
          "Last Review Date": "2026-08-29",
          "Next Review Date": "2026-10-31",
          "Evidence Reference": "RETENTION-DELETE-2026-Q3",
          "Notes": "Deletion evidence linked to DSAR workflow.",
          "Evidence reference": "RETENTION-DELETE-2026-Q3"
        },
        {
          "Record ID": "MDR-027",
          "Document or Record": "Event log records",
          "ISO Reference": "A 8.15",
          "Mandatory Status": "Mandatory record",
          "Purpose": "Evidence collection, protection and review of event logs.",
          "Owner": "Security Operations Lead",
          "Approver": "ISMS Manager",
          "Location": "LOG-REC-2026",
          "Version": "1.0",
          "Status": "Active",
          "Last Review Date": "2026-08-29",
          "Next Review Date": "2026-09-29",
          "Evidence Reference": "SIEM-LOG-REVIEW-2026-Q3",
          "Notes": "Critical alert review cadence confirmed.",
          "Evidence reference": "SIEM-LOG-REVIEW-2026-Q3"
        }
      ],
      "contentType": "register_table"
    },
    {
      "id": "mandatory_documents_review",
      "title": "Mandatory documents review",
      "values": {
        "Review result": "Mandatory document set contains all 27 required documents and records; five items require follow-up before readiness review.",
        "Items reviewed": 27,
        "Approved items": 10,
        "Items needing update": 5,
        "Missing items": 0,
        "Reviewed by": "ISMS Manager",
        "Decision date": "2026-08-29",
        "Evidence reference": "MDR-REVIEW-2026-Q3"
      },
      "rows": [
        {
          "Field": "Review result",
          "Value": "Mandatory document set contains all 27 required documents and records; five items require follow-up before readiness review.",
          "Evidence reference": "MDR-REVIEW-2026-Q3",
          "Evidence status": "Complete"
        },
        {
          "Field": "Items reviewed",
          "Value": "27",
          "Evidence reference": "MDR-REVIEW-2026-Q3",
          "Evidence status": "Complete"
        },
        {
          "Field": "Approved items",
          "Value": "10",
          "Evidence reference": "MDR-REVIEW-2026-Q3",
          "Evidence status": "Complete"
        },
        {
          "Field": "Items needing update",
          "Value": "5",
          "Evidence reference": "MDR-REVIEW-2026-Q3",
          "Evidence status": "Complete"
        },
        {
          "Field": "Missing items",
          "Value": "0",
          "Evidence reference": "MDR-REVIEW-2026-Q3",
          "Evidence status": "Complete"
        },
        {
          "Field": "Reviewed by",
          "Value": "ISMS Manager",
          "Evidence reference": "MDR-REVIEW-2026-Q3",
          "Evidence status": "Complete"
        },
        {
          "Field": "Decision date",
          "Value": "2026-08-29",
          "Evidence reference": "MDR-REVIEW-2026-Q3",
          "Evidence status": "Complete"
        },
        {
          "Field": "Evidence reference",
          "Value": "MDR-REVIEW-2026-Q3",
          "Evidence reference": "MDR-REVIEW-2026-Q3",
          "Evidence status": "Complete"
        }
      ],
      "contentType": "decision_table"
    },
    {
      "id": "evidence_and_records",
      "title": "Evidence and records",
      "groups": [
        {
          "text": "Related records live in the companion documents named below. This file cites them by their approved version. It does not copy their content. The Owner named on the cover is accountable for those live records."
        },
        {
          "items": [
            "[Document Control Procedure](DCP_Document_Control_Procedure.docx) — How these mandatory files are issued and reviewed.",
            "[Document Register](DR_Document_Register.xlsx) — Controlled documented information listed here.",
            "[ISMS Scope Statement](ISS_ISMS_Scope_Statement.docx) — Boundary these mandatory documents must cover."
          ],
          "ordered": true,
          "relationView": "evidence"
        }
      ],
      "contentType": "evidence_table"
    },
    {
      "id": "external_references",
      "title": "References",
      "groups": [
        {
          "text": "Cite these sources from workshops and audits. This list names ISO clauses, book chapters and companion artifacts used by this file."
        },
        {
          "rows": [
            {
              "Kind": "ISO",
              "Reference": "ISO/IEC 27001:2022",
              "How this document uses it": "Normative source this artifact implements or cites.",
              "href": "https://www.iso.org/standard/82875.html"
            },
            {
              "Kind": "Book",
              "Reference": "Implementation & Certification, Implementation Readiness & Planning",
              "How this document uses it": "Primary operating chapter for this companion artifact.",
              "href": "https://www.amazon.com/s?k=ISO+27001+for+Software+Companies+Implementation+and+Certification"
            },
            {
              "Kind": "Artifact",
              "Reference": "ISO Information Security Objectives (Building the ISMS, Information Security Policies & Risk Management)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/dp/9789908983448"
            },
            {
              "Kind": "Artifact",
              "Reference": "RTP Risk Treatment Plan (Implementation & Certification, Risk Assessment & Risk Treatment Process)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/s?k=ISO+27001+for+Software+Companies+Implementation+and+Certification"
            },
            {
              "Kind": "Artifact",
              "Reference": "IAP Internal Audit Plan (Implementation & Certification, Internal Audit & Management Review)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/s?k=ISO+27001+for+Software+Companies+Implementation+and+Certification"
            },
            {
              "Kind": "Artifact",
              "Reference": "ISS ISMS Scope Statement (Building the ISMS, Context of the Organization (Clause 4))",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/dp/9789908983448"
            }
          ]
        }
      ],
      "contentType": "reference_table"
    }
  ],
  "enrichment": {
    "source": "Example.json",
    "method": "curated-json",
    "note": "Completes Example JSON with renderer-native sections and generalized groups; no mdSource helper fields."
  },
  "snapshotRef": {
    "snapshotId": "arcfield.platform.surv.2026-09-11",
    "schemaVersion": "evidenceSnapshot.v1"
  },
  "scenarioRef": {
    "githubIssue": 64,
    "crId": "CR-TYPE-ARCFIELD-001",
    "family": "Register",
    "role": "Operating sample of the 11 September 2026 freeze"
  }
}
