{
  "schemaVersion": "artifactDefinition.v2",
  "definitionId": "RRS.artifactDefinition.v2",
  "artifactId": "RRS",
  "title": "Records Retention Schedule",
  "artifactType": "Register",
  "format": "xlsx",
  "productTier": "Premium",
  "definitionRole": "contract",
  "sourceModel": {
    "body": "canonical human-readable register maintained in the Artifact Candidate page",
    "jsonDefinition": "machine-readable contract and validation model",
    "jsonExample": "curated realistic example data fixture"
  },
  "purpose": "Define the required structure for documenting retention rules for ISMS, security, privacy, audit and operational records, including owner, retention period, disposal method and evidence.",
  "sections": [
    {
      "order": 1,
      "id": "title_page",
      "title": "Title Page",
      "contentType": "metadata",
      "required": true,
      "hint": null
    },
    {
      "order": 2,
      "id": "abstract",
      "title": "Abstract",
      "contentType": "narrative",
      "required": true,
      "hint": {
        "text": "Use RRS to prove that security and compliance records are retained for the right period and disposed of in a controlled way.",
        "bookReference": "Volume 2, S-09-06-00 Audit Process"
      }
    },
    {
      "order": 3,
      "id": "document_control",
      "title": "Document Control",
      "contentType": "control_table",
      "required": true,
      "hint": null
    },
    {
      "order": 4,
      "id": "instructions",
      "title": "Instructions",
      "contentType": "ordered_list",
      "required": true,
      "hint": {
        "text": "Retention rules should connect legal, contractual and audit needs with practical storage and disposal controls.",
        "bookReference": "Volume 2, S-09-06-00 Audit Process"
      },
      "intro": "Complete the Working sheets using the example tabs as a model. Follow the workbook usage rules below."
    },
    {
      "order": 5,
      "id": "records_retention_schedule",
      "title": "Records retention schedule",
      "contentType": "register_table",
      "required": true,
      "minimumExampleRows": 6,
      "columns": [
        {
          "name": "Record Class ID",
          "type": "text",
          "required": "yes",
          "description": "Unique record class identifier.",
          "example": "RRS-001"
        },
        {
          "name": "Record Class",
          "type": "text",
          "required": "yes",
          "description": "Record category.",
          "example": "Incident records"
        },
        {
          "name": "Record Examples",
          "type": "text",
          "required": "yes",
          "description": "Examples of records in scope.",
          "example": "Incident log"
        },
        {
          "name": "Legal or Business Driver",
          "type": "text",
          "required": "yes",
          "description": "Reason for retention.",
          "example": "Audit trail"
        },
        {
          "name": "Retention Period",
          "type": "text",
          "required": "yes",
          "description": "Retention period.",
          "example": "5 years"
        },
        {
          "name": "Retention Trigger",
          "type": "text",
          "required": "yes",
          "description": "Event that starts retention.",
          "example": "Incident closed"
        },
        {
          "name": "Storage Location",
          "type": "text",
          "required": "yes",
          "description": "Controlled storage location.",
          "example": "Evidence folder"
        },
        {
          "name": "Owner",
          "type": "select",
          "required": "yes",
          "description": "Accountable owner.",
          "example": "Incident Manager",
          "valueSet": "domain.owner",
          "options": [
            "ISMS Manager",
            "Control Owner",
            "Risk Owner",
            "Process Owner",
            "Asset Owner",
            "IT Security",
            "HR",
            "Legal",
            "Executive Management",
            "Internal Audit"
          ],
          "validation": {
            "allowBlank": false,
            "errorTitle": "Invalid value",
            "error": "Select a value from the list."
          }
        },
        {
          "name": "Access Restriction",
          "type": "text",
          "required": "yes",
          "description": "Access restriction.",
          "example": "Security restricted"
        },
        {
          "name": "Disposal Method",
          "type": "text",
          "required": "yes",
          "description": "Disposal method.",
          "example": "Secure deletion"
        },
        {
          "name": "Review Frequency",
          "type": "text",
          "required": "yes",
          "description": "Review cadence.",
          "example": "Annual"
        },
        {
          "name": "Evidence Reference",
          "type": "text",
          "required": "yes",
          "description": "Evidence record.",
          "example": "RRS-REVIEW-2026-Q3"
        },
        {
          "name": "Status",
          "type": "select",
          "required": "yes",
          "description": "Active, action open, retired or under review.",
          "example": "Active",
          "valueSet": "domain.status.generic",
          "options": [
            "Draft",
            "In Progress",
            "Under Review",
            "Approved",
            "Closed",
            "Deferred"
          ],
          "validation": {
            "allowBlank": false,
            "errorTitle": "Invalid value",
            "error": "Select a value from the list."
          }
        },
        {
          "name": "Notes",
          "type": "text",
          "required": "no",
          "description": "Additional context.",
          "example": "Legal hold check required."
        }
      ],
      "hint": {
        "text": "Each row should show what record class is retained, why, for how long, where it is stored and how it is disposed.",
        "bookReference": "Volume 2, S-09-06-00 Audit Process"
      }
    },
    {
      "order": 6,
      "id": "retention_review_decision",
      "title": "Retention review decision",
      "contentType": "decision_table",
      "required": true,
      "fields": [
        {
          "name": "Review result",
          "type": "select",
          "required": "yes",
          "valueSet": "domain.reviewResult",
          "options": [
            "Pass",
            "Pass with observations",
            "Fail",
            "Deferred"
          ],
          "validation": {
            "allowBlank": false,
            "errorTitle": "Invalid value",
            "error": "Select a value from the list."
          }
        },
        {
          "name": "Record classes reviewed",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Rules active",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Rules needing update",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Disposal actions due",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Reviewed by",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Decision date",
          "type": "date",
          "required": "yes"
        },
        {
          "name": "Evidence reference",
          "type": "text",
          "required": "yes"
        }
      ],
      "hint": {
        "text": "Close with a review decision so retention gaps and disposal actions are visible before audits or legal reviews.",
        "bookReference": "Volume 2, S-09-06-00 Audit Process"
      }
    },
    {
      "order": 7,
      "id": "external_references",
      "title": "References",
      "contentType": "reference_table",
      "required": true
    }
  ],
  "validationRules": [
    "JSON Example must contain definitionRef pointing to RRS.artifactDefinition.v2.",
    "JSON Example register sections must contain schemaRef pointing to the matching definition section.",
    "Rows must include record class, driver, retention period, trigger, storage location, owner, disposal method and evidence reference.",
    "Body must render the contract schema and the example data.",
    "No standalone Book reference section and no generic Sample placeholders are allowed."
  ],
  "enrichment": {
    "source": "Contract.json",
    "method": "curated-json",
    "note": "Completes Contract JSON from MD-only schema/sections, removes duplicate alias sections, and normalizes string columns into structured column objects."
  },
  "editorialStandard": {
    "isoAnchors": [
      {
        "label": "ISO/IEC 27001:2022 7.5",
        "href": "https://www.iso.org/standard/82875.html",
        "role": "Normative source this artifact implements or cites."
      },
      {
        "label": "ISO/IEC 27001:2022",
        "href": "https://www.iso.org/standard/82875.html",
        "role": "Normative source this artifact implements or cites."
      }
    ],
    "bookSources": [
      {
        "series": "ISO 27001 for Software Companies",
        "volume": 2,
        "volumeTitle": "Implementation & Certification",
        "chapterId": "S-09-06-00",
        "chapterTitle": "Audit Process",
        "primary": true,
        "role": "Primary operating chapter for this companion artifact.",
        "href": "https://www.amazon.com/s?k=ISO+27001+for+Software+Companies+Implementation+and+Certification"
      },
      {
        "series": "ISO 27001 for Software Companies",
        "volume": 1,
        "volumeTitle": "Building the ISMS",
        "chapterId": "S-00-03-00",
        "chapterTitle": "Planning, Risk & Objectives (Clause 6)",
        "primary": false,
        "role": "Documented information, review and version discipline.",
        "href": "https://www.amazon.com/dp/9789908983448"
      }
    ],
    "acronyms": [
      {
        "abbr": "ISMS",
        "longForm": "Information Security Management System"
      },
      {
        "abbr": "SaaS",
        "longForm": "Software as a Service"
      },
      {
        "abbr": "CIA",
        "longForm": "Confidentiality, Integrity, and Availability"
      },
      {
        "abbr": "CI/CD",
        "longForm": "Continuous Integration / Continuous Delivery"
      },
      {
        "abbr": "CI",
        "longForm": "Continuous Integration"
      },
      {
        "abbr": "CD",
        "longForm": "Continuous Delivery"
      },
      {
        "abbr": "HR",
        "longForm": "Human Resources"
      },
      {
        "abbr": "IL",
        "longForm": "Impact Level"
      },
      {
        "abbr": "JSON",
        "longForm": "JavaScript Object Notation"
      },
      {
        "abbr": "MDR",
        "longForm": "Managed Detection and Response"
      },
      {
        "abbr": "RR",
        "longForm": "Risk Register"
      },
      {
        "abbr": "SoA",
        "longForm": "Statement of Applicability"
      }
    ],
    "must": [
      "Keep one live row per record on Working sheets. Do not merge several cases into one row.",
      "Example sheets must contain realistic Arcfield rows for every required sheet. Empty required cells are not an example."
    ],
    "mustNot": [
      "Do not invent live rows in the renderer. Example data lives in the Example JSON.",
      "Do not treat Ex example tabs as working sheets. Do not put live data on system sheets."
    ],
    "softwareCompanyAdaptations": [
      "Use Arcfield as the worked example (cover variant A).",
      "Name SaaS, CI/CD, privileged access or supplier interfaces in example rows where they affect this register."
    ],
    "exampleWorkbook": {
      "workedExampleOrg": "Arcfield",
      "requiredSheets": [
        "records_retention_schedule",
        "retention_review_decision"
      ],
      "minExampleRows": 6,
      "coverFromExample": true
    }
  },
  "editorialContractId": "editorial.xlsx.register.v1",
  "contentContractId": "content.register.items.v1"
}
