{
  "schemaVersion": "artifactExample.v2",
  "artifactId": "ROAR",
  "title": "ISMS Risks and Opportunities Register",
  "definitionRef": {
    "artifactId": "ROAR",
    "definitionSchemaVersion": "artifactDefinition.v2",
    "definitionId": "ROAR.artifactDefinition.v2",
    "title": "ISMS Risks and Opportunities Register"
  },
  "organization": "Arcfield",
  "sections": [
    {
      "id": "title_page",
      "title": "Title Page",
      "values": {
        "Register Title": "ISMS Risks and Opportunities Register",
        "Register ID": "ROAR-REG-001",
        "Version": "1.1",
        "Status": "Approved",
        "Organization": "Arcfield",
        "Owner": "ISMS Manager",
        "Approver": "Top Management",
        "Classification": "Internal",
        "Effective Date": "2026-09-11",
        "Next Review Date": "2027-09-11"
      },
      "items": [
        "Register Title: ISMS Risks and Opportunities Register",
        "Register ID: ROAR-REG-001",
        "Version: 1.1",
        "Status: Approved",
        "Organization: Arcfield",
        "Owner: ISMS Manager",
        "Approver: Top Management",
        "Classification: Internal",
        "Effective Date: 2026-09-11",
        "Next Review Date: 2027-09-11"
      ],
      "contentType": "metadata"
    },
    {
      "id": "abstract",
      "title": "Abstract",
      "text": "This example tracks Arcfield ISMS risks and opportunities with sources, affected ISMS elements, prioritization, ownership, decisions, actions, due dates, status and evidence. Rows are the 11 September 2026 operating sample of the certified Arcfield Platform ISMS in the surveillance cycle after certificate ARC-ISMS-2025-001.",
      "contentType": "narrative"
    },
    {
      "id": "document_control",
      "title": "Document Control",
      "rows": [
        {
          "Property": "Purpose",
          "Value": "Track ISMS risks and opportunities and planned actions."
        },
        {
          "Property": "Used by",
          "Value": "ISMS Manager, Risk Owners, Top Management, Internal Auditor"
        },
        {
          "Property": "Maintained by",
          "Value": "ISMS Manager"
        },
        {
          "Property": "Evidence role",
          "Value": "Clause 6.1 risks-and-opportunities planning evidence"
        },
        {
          "Property": "ISO reference",
          "Value": "ISO/IEC 27001:2022 Clause 6.1, Clause 8.1, Clause 9.3 and Clause 10.2"
        },
        {
          "Property": "Review cadence",
          "Value": "Monthly and before management review"
        }
      ],
      "contentType": "control_table"
    },
    {
      "id": "instructions",
      "title": "Instructions",
      "items": [
        "Record ISMS risks and opportunities from context, audits, incidents, suppliers, metrics and management review.",
        "Assess likelihood, impact and priority.",
        "Assign an owner and decision.",
        "Define treatment, monitoring or exploitation action.",
        "Link evidence and due dates.",
        "Review open actions before management review.",
        "Use sheets ending in “Ex” as read-only examples. Enter live data only on the matching “Wk” (Working) sheets.",
        "Every operative list is an Excel Table with frozen headers and filters. Add new rows on the next empty worksheet row beneath the table so Excel expands it — do not leave blank rows inside the table.",
        "Where a column offers a dropdown, choose a value from the list (Status, Owner role, Priority, Severity, Likelihood, Impact, Applicability, Evidence Status, Review Result). Do not invent free-text variants.",
        "Enter dates as YYYY-MM-DD. Date columns are validated and formatted accordingly.",
        "Review the Flag columns (Overdue, Review Due, Missing Owner, Missing Evidence). They calculate automatically and highlight gaps for follow-up.",
        "Keep Cover, Legal, Book, Lists and Metadata unchanged. System sheets are protected on purpose."
      ],
      "contentType": "ordered_list"
    },
    {
      "id": "risks_opportunities_register",
      "title": "Risks and opportunities register",
      "schemaRef": {
        "definitionId": "ROAR.artifactDefinition.v2",
        "sectionId": "risks_opportunities_register",
        "columnsRef": "sections.risks_opportunities_register.columns"
      },
      "rows": [
        {
          "Item ID": "ROAR-001",
          "Type": "Risk",
          "Source": "Supplier review",
          "Description": "Critical cloud supplier notification addendum is not finalized.",
          "Affected ISMS Element": "Supplier relationship security",
          "Likelihood": "Medium",
          "Impact": "High",
          "Priority": "High",
          "Owner": "Supplier Manager",
          "Decision": "Treat",
          "Action": "Complete contractual addendum and update LRR.",
          "Due Date": "2026-10-15",
          "Evidence Reference": "LRR-005",
          "Status": "Open",
          "Review Notes": "Related to EXR-002."
        },
        {
          "Item ID": "ROAR-002",
          "Type": "Risk",
          "Source": "Access review",
          "Description": "Cloud privileged access review is incomplete for one critical system.",
          "Affected ISMS Element": "Access control",
          "Likelihood": "Medium",
          "Impact": "Medium",
          "Priority": "High",
          "Owner": "IT Operations Manager",
          "Decision": "Treat",
          "Action": "Complete review and close exception.",
          "Due Date": "2026-09-05",
          "Evidence Reference": "ARR-2026-08",
          "Status": "In progress",
          "Review Notes": "Linked to EXR-001."
        },
        {
          "Item ID": "ROAR-003",
          "Type": "Opportunity",
          "Source": "Audit preparation",
          "Description": "Automated evidence collection can reduce missed access-review evidence.",
          "Affected ISMS Element": "Evidence management",
          "Likelihood": "High",
          "Impact": "Medium",
          "Priority": "Medium",
          "Owner": "Security Lead",
          "Decision": "Exploit",
          "Action": "Pilot evidence integration for access reviews.",
          "Due Date": "2026-10-01",
          "Evidence Reference": "ISMS-CHG-002",
          "Status": "Planned",
          "Review Notes": "Resource allocated in RAE-002."
        },
        {
          "Item ID": "ROAR-004",
          "Type": "Risk",
          "Source": "Incident log",
          "Description": "Supplier final incident report is delayed.",
          "Affected ISMS Element": "Incident management and supplier monitoring",
          "Likelihood": "Medium",
          "Impact": "Medium",
          "Priority": "Medium",
          "Owner": "Incident Manager",
          "Decision": "Monitor",
          "Action": "Follow up weekly until closure.",
          "Due Date": "2026-09-06",
          "Evidence Reference": "IL-004",
          "Status": "Open",
          "Review Notes": "Customer-impact assessment drafted."
        },
        {
          "Item ID": "ROAR-005",
          "Type": "Opportunity",
          "Source": "Management review",
          "Description": "Quarterly management review improves visibility of certification blockers.",
          "Affected ISMS Element": "Management review",
          "Likelihood": "High",
          "Impact": "Medium",
          "Priority": "Medium",
          "Owner": "ISMS Manager",
          "Decision": "Exploit",
          "Action": "Use quarterly cadence for readiness steering.",
          "Due Date": "2026-11-12",
          "Evidence Reference": "MR-2026-Q3",
          "Status": "Active",
          "Review Notes": "Implemented through ISMS-CHG-004."
        },
        {
          "Item ID": "ROAR-006",
          "Type": "Risk",
          "Source": "Secure development review",
          "Description": "Production-like test data masking is incomplete.",
          "Affected ISMS Element": "Secure development and privacy controls",
          "Likelihood": "Medium",
          "Impact": "High",
          "Priority": "High",
          "Owner": "Engineering Lead",
          "Decision": "Treat",
          "Action": "Implement masking remediation and privacy checkpoint.",
          "Due Date": "2026-09-10",
          "Evidence Reference": "EXR-004",
          "Status": "Open",
          "Review Notes": "Resource approved in RAE-006."
        }
      ],
      "contentType": "register_table"
    },
    {
      "id": "roar_review_decision",
      "title": "ROAR review decision",
      "values": {
        "Review result": "Six risks and opportunities reviewed; three high-priority risks have assigned treatment actions.",
        "Items reviewed": 6,
        "Risks open": 4,
        "Opportunities open": 2,
        "Actions overdue": 0,
        "Reviewed by": "ISMS Manager",
        "Decision date": "2026-08-29",
        "Evidence reference": "ROAR-REVIEW-2026-Q3"
      },
      "rows": [
        {
          "Field": "Review result",
          "Value": "Six risks and opportunities reviewed; three high-priority risks have assigned treatment actions."
        },
        {
          "Field": "Items reviewed",
          "Value": "6"
        },
        {
          "Field": "Risks open",
          "Value": "4"
        },
        {
          "Field": "Opportunities open",
          "Value": "2"
        },
        {
          "Field": "Actions overdue",
          "Value": "0"
        },
        {
          "Field": "Reviewed by",
          "Value": "ISMS Manager"
        },
        {
          "Field": "Decision date",
          "Value": "2026-08-29"
        },
        {
          "Field": "Evidence reference",
          "Value": "ROAR-REVIEW-2026-Q3"
        }
      ],
      "contentType": "decision_table"
    },
    {
      "id": "external_references",
      "title": "References",
      "groups": [
        {
          "text": "Cite these sources from workshops and audits. This list names ISO clauses, book chapters and companion artifacts used by this file."
        },
        {
          "rows": [
            {
              "Kind": "ISO",
              "Reference": "ISO/IEC 27001:2022 6.1",
              "How this document uses it": "Normative source this artifact implements or cites.",
              "href": "https://www.iso.org/standard/82875.html"
            },
            {
              "Kind": "Book",
              "Reference": "Implementation & Certification, Risk Assessment & Risk Treatment Process",
              "How this document uses it": "Primary operating chapter for this companion artifact.",
              "href": "https://www.amazon.com/s?k=ISO+27001+for+Software+Companies+Implementation+and+Certification"
            },
            {
              "Kind": "Artifact",
              "Reference": "EXR Exceptions Register (Implementation & Certification, Asset Management & Information Classification)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/s?k=ISO+27001+for+Software+Companies+Implementation+and+Certification"
            },
            {
              "Kind": "Artifact",
              "Reference": "ISO Information Security Objectives (Building the ISMS, Information Security Policies & Risk Management)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/dp/9789908983448"
            },
            {
              "Kind": "Artifact",
              "Reference": "LRR Legal, Regulatory and Contractual Requirements Register (Building the ISMS, Legal, Regulatory & Contractual Requirements)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/dp/9789908983448"
            },
            {
              "Kind": "Artifact",
              "Reference": "RAE Resource Allocation Evidence (Building the ISMS, Context of the Organization (Clause 4))",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/dp/9789908983448"
            }
          ]
        }
      ],
      "contentType": "reference_table"
    }
  ],
  "enrichment": {
    "source": "Example.json",
    "method": "curated-json",
    "note": "Completes Example JSON with renderer-native sections and generalized groups; no mdSource helper fields."
  },
  "snapshotRef": {
    "snapshotId": "arcfield.platform.surv.2026-09-11",
    "schemaVersion": "evidenceSnapshot.v1"
  },
  "scenarioRef": {
    "githubIssue": 64,
    "crId": "CR-TYPE-ARCFIELD-001",
    "family": "Register",
    "role": "Operating sample of the 11 September 2026 freeze"
  }
}
