{
  "schemaVersion": "artifactExample.v2",
  "artifactId": "REQT",
  "title": "ISO 27001 Clauses 4-10 Requirements Tracker",
  "definitionRef": {
    "artifactId": "REQT",
    "definitionSchemaVersion": "artifactDefinition.v2",
    "definitionId": "REQT.artifactDefinition.v2",
    "title": "ISO 27001 Clauses 4-10 Requirements Tracker"
  },
  "organization": "Arcfield",
  "sections": [
    {
      "id": "title_page",
      "title": "Title Page",
      "values": {
        "Register Title": "ISO 27001 Clauses 4-10 Requirements Tracker",
        "Register ID": "REQT-REG-001",
        "Version": "1.1",
        "Status": "Approved",
        "Organization": "Arcfield",
        "Owner": "ISMS Manager",
        "Approver": "Top Management",
        "Classification": "Internal",
        "Effective Date": "2026-09-11",
        "Next Review Date": "2027-09-11"
      },
      "items": [
        "Register Title: ISO 27001 Clauses 4-10 Requirements Tracker",
        "Register ID: REQT-REG-001",
        "Version: 1.1",
        "Status: Approved",
        "Organization: Arcfield",
        "Owner: ISMS Manager",
        "Approver: Top Management",
        "Classification: Internal",
        "Effective Date: 2026-09-11",
        "Next Review Date: 2027-09-11"
      ],
      "contentType": "metadata"
    },
    {
      "id": "abstract",
      "title": "Abstract",
      "text": "This example tracks implementation of ISO/IEC 27001:2022 management-system clauses 4.1 through 10.2 for Arcfield. Unlike ISOCL, which is reference data, this tracker records owners, implementation status, evidence status, operating effectiveness, linked artifacts, gaps and review dates. Rows are the 11 September 2026 operating sample of the certified Arcfield Platform ISMS in the surveillance cycle after certificate ARC-ISMS-2025-001.",
      "contentType": "narrative"
    },
    {
      "id": "document_control",
      "title": "Document Control",
      "values": {
        "Document owner": "ISMS Manager",
        "Approved by": "Top Management",
        "Version": "1.1",
        "Status": "Example",
        "Review cadence": "Monthly during certification preparation",
        "Last reviewed": "2026-08-29",
        "Next review": "2026-10-31"
      },
      "rows": [
        {
          "Property": "Purpose",
          "Value": "Track implementation status, ownership, evidence and open actions for all ISO 27001 Clauses 4-10."
        },
        {
          "Property": "Used by",
          "Value": "ISMS Manager, Process Owners, Top Management, Internal Auditor"
        },
        {
          "Property": "Maintained by",
          "Value": "ISMS Manager"
        },
        {
          "Property": "Evidence role",
          "Value": "ISO 27001 clause implementation and audit-readiness evidence"
        },
        {
          "Property": "ISO reference",
          "Value": "ISO/IEC 27001:2022 Clauses 4.1-10.2"
        },
        {
          "Property": "Review cadence",
          "Value": "Monthly during implementation, before internal audit, before management review and before certification audit"
        }
      ],
      "contentType": "control_table"
    },
    {
      "id": "instructions",
      "title": "Instructions",
      "items": [
        "Keep one row for every ISO/IEC 27001:2022 management-system clause.",
        "Assign an accountable role for each clause.",
        "Record implementation status, maturity, evidence, gaps and next action.",
        "Keep evidence references aligned with the document register, risk register, SoA, audit programme, management review and improvement log.",
        "Treat missing evidence for mandatory clauses as an audit-readiness blocker.",
        "Review the tracker before internal audit, management review and certification audit.",
        "Use sheets ending in “Ex” as read-only examples. Enter live data only on the matching “Wk” (Working) sheets.",
        "Every operative list is an Excel Table with frozen headers and filters. Add new rows on the next empty worksheet row beneath the table so Excel expands it — do not leave blank rows inside the table.",
        "Where a column offers a dropdown, choose a value from the list (Status, Owner role, Priority, Severity, Likelihood, Impact, Applicability, Evidence Status, Review Result). Do not invent free-text variants.",
        "Enter dates as YYYY-MM-DD. Date columns are validated and formatted accordingly.",
        "Review the Flag columns (Overdue, Review Due, Missing Owner, Missing Evidence). They calculate automatically and highlight gaps for follow-up.",
        "Keep Cover, Legal, Book, Lists and Metadata unchanged. System sheets are protected on purpose."
      ],
      "contentType": "ordered_list"
    },
    {
      "id": "register_schema",
      "title": "Register schema",
      "schemaRef": {
        "definitionId": "REQT.artifactDefinition.v2",
        "sectionId": "register_schema"
      },
      "columns": [
        "Clause ID",
        "Clause title",
        "Requirement summary",
        "Implementation expectation",
        "Owner",
        "Implementation status",
        "Documentation status",
        "Evidence status",
        "Operating effectiveness",
        "Linked artifact(s)",
        "Evidence reference",
        "Gap / action",
        "Target date",
        "Review date"
      ],
      "rows": [
        {
          "Column": "Clause ID",
          "Type": "text",
          "Required": "yes",
          "Description": "ISO/IEC 27001:2022 clause identifier.",
          "Example": "4.3"
        },
        {
          "Column": "Clause title",
          "Type": "text",
          "Required": "yes",
          "Description": "Clause title or short name.",
          "Example": "Scope of the ISMS"
        },
        {
          "Column": "Requirement summary",
          "Type": "text",
          "Required": "yes",
          "Description": "Practical implementation-oriented requirement summary.",
          "Example": "Define and maintain the ISMS scope."
        },
        {
          "Column": "Done looks like",
          "Type": "text",
          "Required": "yes",
          "Description": "Completion criterion.",
          "Example": "Approved scope statement exists and matches actual boundaries."
        },
        {
          "Column": "Owner",
          "Type": "text",
          "Required": "yes",
          "Description": "Accountable role.",
          "Example": "ISMS Manager"
        },
        {
          "Column": "Status",
          "Type": "select",
          "Required": "yes",
          "Description": "Implementation status.",
          "Example": "Implemented"
        },
        {
          "Column": "Maturity",
          "Type": "select",
          "Required": "yes",
          "Description": "Implementation maturity.",
          "Example": "Managed"
        },
        {
          "Column": "Typical evidence",
          "Type": "text",
          "Required": "yes",
          "Description": "Expected evidence artifact.",
          "Example": "ISMS Scope Statement"
        },
        {
          "Column": "Evidence reference",
          "Type": "text",
          "Required": "conditional",
          "Description": "Concrete evidence reference.",
          "Example": "ISS-001"
        },
        {
          "Column": "Gap / action",
          "Type": "text",
          "Required": "no",
          "Description": "Open gap or next action.",
          "Example": "Update supplier boundary statement."
        },
        {
          "Column": "Next review",
          "Type": "date",
          "Required": "yes",
          "Description": "Planned review date.",
          "Example": "2026-11-29"
        }
      ],
      "contentType": "schema_table"
    },
    {
      "id": "requirements_tracker_entries",
      "title": "Requirements tracker entries",
      "schemaRef": {
        "definitionId": "REQT.artifactDefinition.v2",
        "sectionId": "requirements_tracker_entries",
        "columnsRef": "sections.requirements_tracker_entries.columns"
      },
      "rows": [
        {
          "Clause ID": "4.1",
          "Clause title": "Understanding the organization and its context",
          "Requirement summary": "Determine internal and external issues relevant to ISMS purpose.",
          "Implementation expectation": "Context issues are documented, reviewed and linked to risks and objectives.",
          "Owner": "ISMS Manager",
          "Implementation status": "Implemented",
          "Documentation status": "Approved",
          "Evidence status": "Complete",
          "Operating effectiveness": "Effective",
          "Linked artifact(s)": "OS; GS; ERR",
          "Evidence reference": "CTX-2026-Q3",
          "Gap / action": "None",
          "Target date": null,
          "Review date": "2026-10-31"
        },
        {
          "Clause ID": "4.2",
          "Clause title": "Interested parties",
          "Requirement summary": "Identify interested parties and their information security requirements.",
          "Implementation expectation": "Interested-party needs are mapped to external requirements and controls.",
          "Owner": "Compliance Manager",
          "Implementation status": "Implemented",
          "Documentation status": "Approved",
          "Evidence status": "Complete",
          "Operating effectiveness": "Effective",
          "Linked artifact(s)": "ERR; SRP; SOC2-SD",
          "Evidence reference": "IP-REQ-2026-Q3",
          "Gap / action": "Refresh after new enterprise customer contract.",
          "Target date": "2026-10-15",
          "Review date": "2026-10-31"
        },
        {
          "Clause ID": "4.3",
          "Clause title": "Scope of the ISMS",
          "Requirement summary": "Define ISMS boundaries and applicability.",
          "Implementation expectation": "Scope statement is approved and aligned to services, locations, suppliers and technologies.",
          "Owner": "ISMS Manager",
          "Implementation status": "Implemented",
          "Documentation status": "Approved",
          "Evidence status": "Complete",
          "Operating effectiveness": "Effective",
          "Linked artifact(s)": "ISS; SAS; SINV",
          "Evidence reference": "ISS-APPROVAL-2026-Q3",
          "Gap / action": "None",
          "Target date": null,
          "Review date": "2026-10-31"
        },
        {
          "Clause ID": "4.4",
          "Clause title": "Information security management system",
          "Requirement summary": "Establish, implement, maintain and continually improve the ISMS.",
          "Implementation expectation": "ISMS process model, registers, policies and review cadence are operating.",
          "Owner": "ISMS Manager",
          "Implementation status": "Implemented",
          "Documentation status": "Approved",
          "Evidence status": "Complete",
          "Operating effectiveness": "Partially effective",
          "Linked artifact(s)": "GS; WIR-S1; MRART; MRMT",
          "Evidence reference": "ISMS-OPS-2026-Q3",
          "Gap / action": "Improve evidence freshness dashboard.",
          "Target date": "2026-09-30",
          "Review date": "2026-10-31"
        },
        {
          "Clause ID": "5.1",
          "Clause title": "Leadership and commitment",
          "Requirement summary": "Top Management demonstrates leadership and commitment to the ISMS.",
          "Implementation expectation": "Management commitment, resource decisions and review outputs are evidenced.",
          "Owner": "Top Management",
          "Implementation status": "Implemented",
          "Documentation status": "Approved",
          "Evidence status": "Complete",
          "Operating effectiveness": "Effective",
          "Linked artifact(s)": "ISP; MRMT; GS",
          "Evidence reference": "MRMT-2026-Q3",
          "Gap / action": "None",
          "Target date": null,
          "Review date": "2026-10-31"
        },
        {
          "Clause ID": "5.2",
          "Clause title": "Information security policy",
          "Requirement summary": "Establish and communicate an appropriate information security policy.",
          "Implementation expectation": "Policy is approved, communicated, acknowledged and reviewed.",
          "Owner": "ISMS Manager",
          "Implementation status": "Implemented",
          "Documentation status": "Approved",
          "Evidence status": "Complete",
          "Operating effectiveness": "Effective",
          "Linked artifact(s)": "ISP; TRC",
          "Evidence reference": "ISP-ACK-2026-Q3",
          "Gap / action": "None",
          "Target date": null,
          "Review date": "2026-10-31"
        },
        {
          "Clause ID": "5.3",
          "Clause title": "Organizational roles, responsibilities and authorities",
          "Requirement summary": "Assign and communicate ISMS roles and authorities.",
          "Implementation expectation": "Roles, deputies, decision rights and RACI are documented.",
          "Owner": "ISMS Manager",
          "Implementation status": "Implemented",
          "Documentation status": "Approved",
          "Evidence status": "Complete",
          "Operating effectiveness": "Effective",
          "Linked artifact(s)": "RACI; GS; OS",
          "Evidence reference": "RACI-2026-Q3",
          "Gap / action": "None",
          "Target date": null,
          "Review date": "2026-10-31"
        },
        {
          "Clause ID": "6.1.1",
          "Clause title": "Actions to address risks and opportunities",
          "Requirement summary": "Plan actions for ISMS risks and opportunities.",
          "Implementation expectation": "Risk and opportunity actions are linked to objectives, controls and reviews.",
          "Owner": "Risk Manager",
          "Implementation status": "Implemented",
          "Documentation status": "Approved",
          "Evidence status": "Complete",
          "Operating effectiveness": "Partially effective",
          "Linked artifact(s)": "RR; RTP; RAMT",
          "Evidence reference": "RR-COMPLETE-2026-Q3",
          "Gap / action": "Add opportunity tracking to management review input pack.",
          "Target date": "2026-10-20",
          "Review date": "2026-10-31"
        },
        {
          "Clause ID": "6.1.2",
          "Clause title": "Information security risk assessment",
          "Requirement summary": "Define and apply an information security risk assessment process.",
          "Implementation expectation": "Risk methodology is approved and applied consistently.",
          "Owner": "Risk Manager",
          "Implementation status": "Implemented",
          "Documentation status": "Approved",
          "Evidence status": "Complete",
          "Operating effectiveness": "Effective",
          "Linked artifact(s)": "RAM; RAMT; RASM; RR",
          "Evidence reference": "RAM-APPROVAL-2026-Q3",
          "Gap / action": "None",
          "Target date": null,
          "Review date": "2026-10-31"
        },
        {
          "Clause ID": "6.1.3",
          "Clause title": "Information security risk treatment",
          "Requirement summary": "Select controls, prepare risk treatment plan and produce SoA.",
          "Implementation expectation": "RTP, SoA and residual-risk decisions are approved and traceable.",
          "Owner": "Risk Manager",
          "Implementation status": "Implemented",
          "Documentation status": "Approved",
          "Evidence status": "Complete",
          "Operating effectiveness": "Partially effective",
          "Linked artifact(s)": "RTP; SOA; ISOCTRL",
          "Evidence reference": "RTP-COMPLETE-2026-Q3",
          "Gap / action": "Complete effectiveness checks for open treatments.",
          "Target date": "2026-10-31",
          "Review date": "2026-10-31"
        },
        {
          "Clause ID": "6.2",
          "Clause title": "Information security objectives",
          "Requirement summary": "Set measurable objectives and plans to achieve them.",
          "Implementation expectation": "Objectives include measures, owners, due dates and review cadence.",
          "Owner": "Top Management",
          "Implementation status": "Implemented",
          "Documentation status": "Approved",
          "Evidence status": "Partial",
          "Operating effectiveness": "Partially effective",
          "Linked artifact(s)": "ISP; IMPL-WB; MRMT",
          "Evidence reference": "OBJ-2026-Q3",
          "Gap / action": "Add trend evidence for two objectives.",
          "Target date": "2026-09-30",
          "Review date": "2026-10-31"
        },
        {
          "Clause ID": "6.3",
          "Clause title": "Planning of changes",
          "Requirement summary": "Plan ISMS changes in a controlled manner.",
          "Implementation expectation": "Changes are reviewed for purpose, consequences, resources and responsibilities.",
          "Owner": "Change Manager",
          "Implementation status": "Implemented",
          "Documentation status": "Approved",
          "Evidence status": "Complete",
          "Operating effectiveness": "Effective",
          "Linked artifact(s)": "CMP; CR; ISMS-CL",
          "Evidence reference": "ISMS-CL-2026-Q3",
          "Gap / action": "None",
          "Target date": null,
          "Review date": "2026-10-31"
        },
        {
          "Clause ID": "7.1",
          "Clause title": "Resources",
          "Requirement summary": "Determine and provide resources needed for the ISMS.",
          "Implementation expectation": "Resource needs and decisions are visible in planning and management review.",
          "Owner": "Top Management",
          "Implementation status": "Implemented",
          "Documentation status": "Approved",
          "Evidence status": "Partial",
          "Operating effectiveness": "Partially effective",
          "Linked artifact(s)": "MRART; MRMT; GS",
          "Evidence reference": "MRMT-RES-2026-Q3",
          "Gap / action": "Record decision on monitoring tooling capacity.",
          "Target date": "2026-10-15",
          "Review date": "2026-10-31"
        },
        {
          "Clause ID": "7.2",
          "Clause title": "Competence",
          "Requirement summary": "Ensure people are competent for ISMS responsibilities.",
          "Implementation expectation": "Competence needs, training and evidence are role-based.",
          "Owner": "HR Manager",
          "Implementation status": "Implemented",
          "Documentation status": "Approved",
          "Evidence status": "Complete",
          "Operating effectiveness": "Effective",
          "Linked artifact(s)": "CMTP; TR; TRC; HRP",
          "Evidence reference": "TRC-ROLE-2026-Q3",
          "Gap / action": "None",
          "Target date": null,
          "Review date": "2026-10-31"
        },
        {
          "Clause ID": "7.3",
          "Clause title": "Awareness",
          "Requirement summary": "Ensure people are aware of policy, contribution and consequences.",
          "Implementation expectation": "Awareness completion and role-specific campaigns are evidenced.",
          "Owner": "Security Lead",
          "Implementation status": "Implemented",
          "Documentation status": "Approved",
          "Evidence status": "Complete",
          "Operating effectiveness": "Partially effective",
          "Linked artifact(s)": "TRC; HRSP",
          "Evidence reference": "AWARE-2026-Q3",
          "Gap / action": "Add targeted incident-reporting campaign after OAuth scenario.",
          "Target date": "2026-09-30",
          "Review date": "2026-10-31"
        },
        {
          "Clause ID": "7.4",
          "Clause title": "Communication",
          "Requirement summary": "Determine ISMS communication needs.",
          "Implementation expectation": "Internal and external communication routes and responsibilities are documented.",
          "Owner": "Communications Owner",
          "Implementation status": "Implemented",
          "Documentation status": "Approved",
          "Evidence status": "Complete",
          "Operating effectiveness": "Effective",
          "Linked artifact(s)": "COMM-P; SICT; IRP",
          "Evidence reference": "COMM-PLAN-2026-Q3",
          "Gap / action": "None",
          "Target date": null,
          "Review date": "2026-10-31"
        },
        {
          "Clause ID": "7.5",
          "Clause title": "Documented information",
          "Requirement summary": "Control documented information required by the ISMS.",
          "Implementation expectation": "Document control, approvals, versioning and evidence retention are operating.",
          "Owner": "Document Owner",
          "Implementation status": "Implemented",
          "Documentation status": "Approved",
          "Evidence status": "Complete",
          "Operating effectiveness": "Effective",
          "Linked artifact(s)": "DCP; DR; WIR-S1",
          "Evidence reference": "DR-2026-Q3",
          "Gap / action": "None",
          "Target date": null,
          "Review date": "2026-10-31"
        },
        {
          "Clause ID": "8.1",
          "Clause title": "Operational planning and control",
          "Requirement summary": "Plan, implement and control ISMS processes.",
          "Implementation expectation": "Operational processes are controlled, evidenced and changed through approved routes.",
          "Owner": "ISMS Manager",
          "Implementation status": "Implemented",
          "Documentation status": "Approved",
          "Evidence status": "Complete",
          "Operating effectiveness": "Partially effective",
          "Linked artifact(s)": "WIR-S1; CMP; ISOCTRL",
          "Evidence reference": "OPS-CONTROL-2026-Q3",
          "Gap / action": "Improve monthly evidence freshness checks.",
          "Target date": "2026-09-30",
          "Review date": "2026-10-31"
        },
        {
          "Clause ID": "8.2",
          "Clause title": "Information security risk assessment",
          "Requirement summary": "Perform risk assessments at planned intervals and when changes occur.",
          "Implementation expectation": "Risk assessments are performed and reviewed after trigger events.",
          "Owner": "Risk Manager",
          "Implementation status": "Implemented",
          "Documentation status": "Approved",
          "Evidence status": "Complete",
          "Operating effectiveness": "Effective",
          "Linked artifact(s)": "RR; RAM; ISMS-CL",
          "Evidence reference": "RR-REVIEW-2026-Q3",
          "Gap / action": "None",
          "Target date": null,
          "Review date": "2026-10-31"
        },
        {
          "Clause ID": "8.3",
          "Clause title": "Information security risk treatment",
          "Requirement summary": "Implement the information security risk treatment plan.",
          "Implementation expectation": "Treatment status, residual decisions and effectiveness are tracked.",
          "Owner": "Risk Manager",
          "Implementation status": "In progress",
          "Documentation status": "Approved",
          "Evidence status": "Partial",
          "Operating effectiveness": "Partially effective",
          "Linked artifact(s)": "RTP; SOA; CAR",
          "Evidence reference": "RTP-OPEN-2026-Q3",
          "Gap / action": "Close open treatment effectiveness checks.",
          "Target date": "2026-10-31",
          "Review date": "2026-10-31"
        },
        {
          "Clause ID": "9.1",
          "Clause title": "Monitoring, measurement, analysis and evaluation",
          "Requirement summary": "Evaluate ISMS performance and effectiveness.",
          "Implementation expectation": "Metrics, reviews and analysis are defined and linked to decisions.",
          "Owner": "Security Lead",
          "Implementation status": "Implemented",
          "Documentation status": "Approved",
          "Evidence status": "Partial",
          "Operating effectiveness": "Partially effective",
          "Linked artifact(s)": "MME; IMPL-WB; MRART",
          "Evidence reference": "MME-2026-Q3",
          "Gap / action": "Add trend analysis for supplier and incident metrics.",
          "Target date": "2026-10-15",
          "Review date": "2026-10-31"
        },
        {
          "Clause ID": "9.2",
          "Clause title": "Internal audit",
          "Requirement summary": "Conduct internal audits at planned intervals.",
          "Implementation expectation": "Audit programme, plan, independence, samples, findings and follow-up are evidenced.",
          "Owner": "Internal Auditor",
          "Implementation status": "Implemented",
          "Documentation status": "Approved",
          "Evidence status": "Complete",
          "Operating effectiveness": "Effective",
          "Linked artifact(s)": "IAP; CAR; MRMT",
          "Evidence reference": "IAP-2026-Q3",
          "Gap / action": "None",
          "Target date": null,
          "Review date": "2026-10-31"
        },
        {
          "Clause ID": "9.3",
          "Clause title": "Management review",
          "Requirement summary": "Top Management reviews ISMS suitability, adequacy and effectiveness.",
          "Implementation expectation": "Required inputs, decisions, resources and actions are recorded.",
          "Owner": "Top Management",
          "Implementation status": "Implemented",
          "Documentation status": "Approved",
          "Evidence status": "Complete",
          "Operating effectiveness": "Effective",
          "Linked artifact(s)": "MRART; MRMT",
          "Evidence reference": "MRMT-2026-Q3",
          "Gap / action": "None",
          "Target date": null,
          "Review date": "2026-10-31"
        },
        {
          "Clause ID": "10.1",
          "Clause title": "Continual improvement",
          "Requirement summary": "Continually improve the ISMS.",
          "Implementation expectation": "Improvement actions are identified, prioritized and tracked.",
          "Owner": "ISMS Manager",
          "Implementation status": "Implemented",
          "Documentation status": "Approved",
          "Evidence status": "Partial",
          "Operating effectiveness": "Partially effective",
          "Linked artifact(s)": "CIL; CAR; WIR-S1",
          "Evidence reference": "CIL-2026-Q3",
          "Gap / action": "Add linkage from recurring incident themes to improvement backlog.",
          "Target date": "2026-10-15",
          "Review date": "2026-10-31"
        },
        {
          "Clause ID": "10.2",
          "Clause title": "Nonconformity and corrective action",
          "Requirement summary": "React to nonconformities and implement corrective action.",
          "Implementation expectation": "Root cause, correction, corrective action, owner, due date and effectiveness are tracked.",
          "Owner": "ISMS Manager",
          "Implementation status": "Implemented",
          "Documentation status": "Approved",
          "Evidence status": "Complete",
          "Operating effectiveness": "Effective",
          "Linked artifact(s)": "CAR; IAP; MRMT",
          "Evidence reference": "CAR-2026-Q3",
          "Gap / action": "None",
          "Target date": null,
          "Review date": "2026-10-31"
        }
      ],
      "contentType": "register_table"
    },
    {
      "id": "register_completeness_decision",
      "title": "Register completeness decision",
      "values": {
        "Completeness result": "Complete",
        "Reviewed by": "ISMS Manager",
        "Clause rows covered": 24,
        "Clauses without owner": 0,
        "Clauses without evidence status": 0,
        "Clauses without review or target date": 0,
        "Final status": "Audit-ready",
        "Decision date": "2026-08-29",
        "Evidence reference": "REQT-COMPLETE-2026-Q3"
      },
      "rows": [
        {
          "Field": "Completeness result",
          "Value": "Complete",
          "Evidence reference": "REQT-COMPLETE-2026-Q3",
          "Evidence status": "Complete"
        },
        {
          "Field": "Reviewed by",
          "Value": "ISMS Manager",
          "Evidence reference": "REQT-COMPLETE-2026-Q3",
          "Evidence status": "Complete"
        },
        {
          "Field": "Required clauses covered",
          "Value": "23 of 23",
          "Evidence reference": "REQT-COMPLETE-2026-Q3",
          "Evidence status": "Complete"
        },
        {
          "Field": "Clauses without owner",
          "Value": "0",
          "Evidence reference": "REQT-COMPLETE-2026-Q3",
          "Evidence status": "Complete"
        },
        {
          "Field": "Clauses without evidence expectation",
          "Value": "0",
          "Evidence reference": "REQT-COMPLETE-2026-Q3",
          "Evidence status": "Complete"
        },
        {
          "Field": "Clauses without review date",
          "Value": "0",
          "Evidence reference": "REQT-COMPLETE-2026-Q3",
          "Evidence status": "Complete"
        },
        {
          "Field": "Final status",
          "Value": "Audit-ready",
          "Evidence reference": "REQT-COMPLETE-2026-Q3",
          "Evidence status": "Complete"
        },
        {
          "Field": "Decision date",
          "Value": "2026-08-29",
          "Evidence reference": "REQT-COMPLETE-2026-Q3",
          "Evidence status": "Complete"
        },
        {
          "Field": "Evidence reference",
          "Value": "REQT-COMPLETE-2026-Q3",
          "Evidence reference": "REQT-COMPLETE-2026-Q3",
          "Evidence status": "Complete"
        }
      ],
      "contentType": "decision_table"
    },
    {
      "id": "requirements_tracker",
      "title": "Requirements tracker",
      "rows": [
        {
          "Clause ID": "4.1",
          "Clause title": "Understanding the organization and its context",
          "Requirement summary": "Determine internal and external issues relevant to the ISMS.",
          "Done looks like": "Context analysis is documented and reviewed.",
          "Owner": "ISMS Manager",
          "Status": "Implemented",
          "Maturity": "Managed",
          "Typical evidence": "Context analysis",
          "Evidence reference": "CTX-2026-001",
          "Gap / action": "None",
          "Next review": "2026-11-29"
        },
        {
          "Clause ID": "4.2",
          "Clause title": "Interested parties",
          "Requirement summary": "Determine interested parties and their requirements.",
          "Done looks like": "Interested-party register is approved and linked to requirements.",
          "Owner": "ISMS Manager",
          "Status": "Implemented",
          "Maturity": "Managed",
          "Typical evidence": "Interested Parties Register",
          "Evidence reference": "IPR-2026-Q3",
          "Gap / action": "None",
          "Next review": "2026-11-29"
        },
        {
          "Clause ID": "4.3",
          "Clause title": "Scope of the ISMS",
          "Requirement summary": "Define ISMS boundaries and applicability.",
          "Done looks like": "Scope statement is approved and reflects assets, locations, services and interfaces.",
          "Owner": "ISMS Manager",
          "Status": "Implemented",
          "Maturity": "Managed",
          "Typical evidence": "ISMS Scope Statement",
          "Evidence reference": "ISS-001",
          "Gap / action": "None",
          "Next review": "2026-11-29"
        },
        {
          "Clause ID": "4.4",
          "Clause title": "Information security management system",
          "Requirement summary": "Establish, implement, maintain and continually improve the ISMS.",
          "Done looks like": "ISMS process model, evidence plan and operating cadence exist.",
          "Owner": "ISMS Manager",
          "Status": "Implemented",
          "Maturity": "Managed",
          "Typical evidence": "ISMS operating model",
          "Evidence reference": "ISMS-OM-2026",
          "Gap / action": "None",
          "Next review": "2026-11-29"
        },
        {
          "Clause ID": "5.1",
          "Clause title": "Leadership and commitment",
          "Requirement summary": "Top management demonstrates commitment to the ISMS.",
          "Done looks like": "Management review, policy approval, objectives and resource decisions evidence commitment.",
          "Owner": "Top Management",
          "Status": "Implemented",
          "Maturity": "Managed",
          "Typical evidence": "Management review records",
          "Evidence reference": "MR-2026-Q3",
          "Gap / action": "None",
          "Next review": "2026-11-29"
        },
        {
          "Clause ID": "5.2",
          "Clause title": "Policy",
          "Requirement summary": "Establish an information security policy.",
          "Done looks like": "Policy is approved, communicated and reviewed.",
          "Owner": "ISMS Manager",
          "Status": "Implemented",
          "Maturity": "Managed",
          "Typical evidence": "Information Security Policy",
          "Evidence reference": "ISP-001",
          "Gap / action": "None",
          "Next review": "2026-11-29"
        },
        {
          "Clause ID": "5.3",
          "Clause title": "Organizational roles, responsibilities and authorities",
          "Requirement summary": "Assign ISMS roles and responsibilities.",
          "Done looks like": "RACI and role assignments are approved.",
          "Owner": "ISMS Manager",
          "Status": "Implemented",
          "Maturity": "Managed",
          "Typical evidence": "RACI matrix",
          "Evidence reference": "RACI-2026-Q3",
          "Gap / action": "None",
          "Next review": "2026-11-29"
        },
        {
          "Clause ID": "6.1",
          "Clause title": "Actions to address risks and opportunities",
          "Requirement summary": "Plan actions for risks and opportunities, including risk assessment and treatment.",
          "Done looks like": "Risk assessment, risk treatment plan and SoA are current.",
          "Owner": "Risk Manager",
          "Status": "Implemented",
          "Maturity": "Managed",
          "Typical evidence": "Risk Register; RTP; SoA",
          "Evidence reference": "RR-2026-Q3; RTP-2026-Q3; SOA-2026-Q3",
          "Gap / action": "None",
          "Next review": "2026-10-31"
        },
        {
          "Clause ID": "6.2",
          "Clause title": "Information security objectives and planning to achieve them",
          "Requirement summary": "Define measurable objectives and plans.",
          "Done looks like": "Objectives have owners, measures, deadlines and review evidence.",
          "Owner": "ISMS Manager",
          "Status": "In progress",
          "Maturity": "Defined",
          "Typical evidence": "Objectives register",
          "Evidence reference": "OBJ-2026-Q3",
          "Gap / action": "Add Q4 target values.",
          "Next review": "2026-10-15"
        },
        {
          "Clause ID": "6.3",
          "Clause title": "Planning of changes",
          "Requirement summary": "Plan ISMS changes in a controlled manner.",
          "Done looks like": "Change impacts, owners, approvals and evidence are recorded.",
          "Owner": "Change Manager",
          "Status": "Implemented",
          "Maturity": "Managed",
          "Typical evidence": "ISMS Change Log",
          "Evidence reference": "ISMS-CL-2026-Q3",
          "Gap / action": "None",
          "Next review": "2026-11-29"
        },
        {
          "Clause ID": "7.1",
          "Clause title": "Resources",
          "Requirement summary": "Determine and provide ISMS resources.",
          "Done looks like": "Resource needs and decisions are recorded.",
          "Owner": "Top Management",
          "Status": "Implemented",
          "Maturity": "Managed",
          "Typical evidence": "Resource plan / management review",
          "Evidence reference": "MR-2026-Q3",
          "Gap / action": "None",
          "Next review": "2026-11-29"
        },
        {
          "Clause ID": "7.2",
          "Clause title": "Competence",
          "Requirement summary": "Ensure competence of persons doing ISMS work.",
          "Done looks like": "Competence matrix and training records exist.",
          "Owner": "HR Manager",
          "Status": "Implemented",
          "Maturity": "Managed",
          "Typical evidence": "Competence Matrix and Training Plan",
          "Evidence reference": "CMTP-2026-Q3",
          "Gap / action": "None",
          "Next review": "2026-11-29"
        },
        {
          "Clause ID": "7.3",
          "Clause title": "Awareness",
          "Requirement summary": "Ensure relevant people are aware of policy and responsibilities.",
          "Done looks like": "Awareness training and acknowledgement evidence exist.",
          "Owner": "HR Manager",
          "Status": "Implemented",
          "Maturity": "Managed",
          "Typical evidence": "Awareness records",
          "Evidence reference": "TRAIN-REC-2026-188",
          "Gap / action": "None",
          "Next review": "2026-11-29"
        },
        {
          "Clause ID": "7.4",
          "Clause title": "Communication",
          "Requirement summary": "Determine ISMS communication needs.",
          "Done looks like": "Communication plan identifies audience, message, frequency, owner and channel.",
          "Owner": "ISMS Manager",
          "Status": "Implemented",
          "Maturity": "Managed",
          "Typical evidence": "Communication Plan",
          "Evidence reference": "COMM-P-2026",
          "Gap / action": "None",
          "Next review": "2026-11-29"
        },
        {
          "Clause ID": "7.5",
          "Clause title": "Documented information",
          "Requirement summary": "Control ISMS documented information.",
          "Done looks like": "Document register, versioning, approvals and retention rules are operating.",
          "Owner": "Document Owner",
          "Status": "Implemented",
          "Maturity": "Managed",
          "Typical evidence": "Document Register",
          "Evidence reference": "DR-2026-Q3",
          "Gap / action": "None",
          "Next review": "2026-11-29"
        },
        {
          "Clause ID": "8.1",
          "Clause title": "Operational planning and control",
          "Requirement summary": "Plan and control ISMS operations.",
          "Done looks like": "Operational controls, registers and recurring reviews are tracked.",
          "Owner": "ISMS Manager",
          "Status": "Implemented",
          "Maturity": "Managed",
          "Typical evidence": "ISMS calendar; control records",
          "Evidence reference": "ISMS-CAL-2026",
          "Gap / action": "None",
          "Next review": "2026-11-29"
        },
        {
          "Clause ID": "8.2",
          "Clause title": "Information security risk assessment",
          "Requirement summary": "Perform risk assessments at planned intervals and upon changes.",
          "Done looks like": "Risk assessment method and current risk register exist.",
          "Owner": "Risk Manager",
          "Status": "Implemented",
          "Maturity": "Managed",
          "Typical evidence": "Risk Register",
          "Evidence reference": "RR-2026-Q3",
          "Gap / action": "None",
          "Next review": "2026-10-31"
        },
        {
          "Clause ID": "8.3",
          "Clause title": "Information security risk treatment",
          "Requirement summary": "Implement treatment plans and retain evidence.",
          "Done looks like": "Treatment actions, SoA links, approvals and evidence are current.",
          "Owner": "Risk Manager",
          "Status": "In progress",
          "Maturity": "Managed",
          "Typical evidence": "Risk Treatment Plan",
          "Evidence reference": "RTP-2026-Q3",
          "Gap / action": "Close one delayed supplier SLA action.",
          "Next review": "2026-10-31"
        },
        {
          "Clause ID": "9.1",
          "Clause title": "Monitoring, measurement, analysis and evaluation",
          "Requirement summary": "Monitor and evaluate ISMS performance.",
          "Done looks like": "Measurement plan and KPI evidence exist.",
          "Owner": "ISMS Manager",
          "Status": "Implemented",
          "Maturity": "Managed",
          "Typical evidence": "Measurement Plan",
          "Evidence reference": "MME-2026-Q3",
          "Gap / action": "None",
          "Next review": "2026-11-29"
        },
        {
          "Clause ID": "9.2",
          "Clause title": "Internal audit",
          "Requirement summary": "Conduct internal audits at planned intervals.",
          "Done looks like": "Audit programme, audit reports, findings and corrective actions exist.",
          "Owner": "Internal Auditor",
          "Status": "Implemented",
          "Maturity": "Managed",
          "Typical evidence": "Internal Audit Programme",
          "Evidence reference": "IAP-2026",
          "Gap / action": "None",
          "Next review": "2026-11-29"
        },
        {
          "Clause ID": "9.3",
          "Clause title": "Management review",
          "Requirement summary": "Top management reviews the ISMS.",
          "Done looks like": "Management review input, decisions, actions and minutes exist.",
          "Owner": "Top Management",
          "Status": "Implemented",
          "Maturity": "Managed",
          "Typical evidence": "Management Review Minutes",
          "Evidence reference": "MR-2026-Q3",
          "Gap / action": "None",
          "Next review": "2026-11-29"
        },
        {
          "Clause ID": "10.1",
          "Clause title": "Continual improvement",
          "Requirement summary": "Continually improve the ISMS.",
          "Done looks like": "Improvement log and implemented improvements are tracked.",
          "Owner": "ISMS Manager",
          "Status": "Implemented",
          "Maturity": "Managed",
          "Typical evidence": "Continual Improvement Log",
          "Evidence reference": "CIL-2026-Q3",
          "Gap / action": "None",
          "Next review": "2026-11-29"
        },
        {
          "Clause ID": "10.2",
          "Clause title": "Nonconformity and corrective action",
          "Requirement summary": "React to nonconformities and take corrective action.",
          "Done looks like": "Corrective actions have root cause, owner, due date, evidence and effectiveness check.",
          "Owner": "ISMS Manager",
          "Status": "Implemented",
          "Maturity": "Managed",
          "Typical evidence": "Corrective Actions Register",
          "Evidence reference": "CAR-2026-Q3",
          "Gap / action": "None",
          "Next review": "2026-11-29"
        }
      ],
      "contentType": "section"
    },
    {
      "id": "evidence_and_records",
      "title": "Evidence and records",
      "groups": [
        {
          "text": "Related records live in the companion documents named below. This file cites them by their approved version. It does not copy their content. The Owner named on the cover is accountable for those live records."
        },
        {
          "items": [
            "[ISO 27001 Clauses](ISOCL_ISO_27001_2022_Clauses.xlsx) — Clause coverage map this tracker implements.",
            "[Information Security Policy](ISP_Information_Security_Policy.docx) — Approved intent for clauses 5 and 6.",
            "[Internal Audit Plan](IAP_Internal_Audit_Plan.docx) — How clauses 4–10 will be sampled."
          ],
          "ordered": true,
          "relationView": "evidence"
        }
      ],
      "contentType": "evidence_table"
    },
    {
      "id": "external_references",
      "title": "References",
      "groups": [
        {
          "text": "Cite these sources from workshops and audits. This list names ISO clauses, book chapters and companion artifacts used by this file."
        },
        {
          "rows": [
            {
              "Kind": "ISO",
              "Reference": "ISO/IEC 27001:2022",
              "How this document uses it": "Normative source this artifact implements or cites.",
              "href": "https://www.iso.org/standard/82875.html"
            },
            {
              "Kind": "Book",
              "Reference": "Dual Compliance, ISO 27001 & NIS2",
              "How this document uses it": "Primary operating chapter for this companion artifact.",
              "href": "https://www.amazon.com/dp/9789908983479"
            },
            {
              "Kind": "Artifact",
              "Reference": "ISO Information Security Objectives (Building the ISMS, Information Security Policies & Risk Management)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/dp/9789908983448"
            },
            {
              "Kind": "Artifact",
              "Reference": "MRMT Management Review Minutes Template (Implementation & Certification, Internal Audit & Management Review)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/s?k=ISO+27001+for+Software+Companies+Implementation+and+Certification"
            },
            {
              "Kind": "Artifact",
              "Reference": "RTP Risk Treatment Plan (Implementation & Certification, Risk Assessment & Risk Treatment Process)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/s?k=ISO+27001+for+Software+Companies+Implementation+and+Certification"
            },
            {
              "Kind": "Artifact",
              "Reference": "RR Risk Register (Building the ISMS, Planning, Risk & Objectives (Clause 6))",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/dp/9789908983448"
            }
          ]
        }
      ],
      "contentType": "reference_table"
    }
  ],
  "enrichment": {
    "source": "Example.json",
    "method": "curated-json",
    "note": "Completes Example JSON with renderer-native sections and generalized groups; no mdSource helper fields."
  },
  "snapshotRef": {
    "snapshotId": "arcfield.platform.surv.2026-09-11",
    "schemaVersion": "evidenceSnapshot.v1"
  },
  "scenarioRef": {
    "githubIssue": 64,
    "crId": "CR-TYPE-ARCFIELD-001",
    "family": "Register",
    "role": "Operating sample of the 11 September 2026 freeze"
  }
}
