{
  "schemaVersion": "artifactExample.v2",
  "artifactId": "IL",
  "title": "Incident Log",
  "definitionRef": {
    "artifactId": "IL",
    "definitionSchemaVersion": "artifactDefinition.v2",
    "definitionId": "IL.artifactDefinition.v2",
    "title": "Incident Log"
  },
  "organization": "Arcfield",
  "sections": [
    {
      "id": "title_page",
      "title": "Title Page",
      "values": {
        "Register Title": "Incident Log",
        "Register ID": "IL-REG-001",
        "Version": "1.1",
        "Status": "Approved",
        "Organization": "Arcfield",
        "Owner": "Incident Manager",
        "Approver": "ISMS Manager",
        "Classification": "Internal",
        "Effective Date": "2026-09-11",
        "Next Review Date": "2027-09-11"
      },
      "items": [
        "Register Title: Incident Log",
        "Register ID: IL-REG-001",
        "Version: 1.1",
        "Status: Approved",
        "Organization: Arcfield",
        "Owner: Incident Manager",
        "Approver: ISMS Manager",
        "Classification: Internal",
        "Effective Date: 2026-09-11",
        "Next Review Date: 2027-09-11"
      ],
      "contentType": "metadata"
    },
    {
      "id": "abstract",
      "title": "Abstract",
      "text": "This example records Arcfield security events and incidents from reporting through classification, containment, investigation, evidence preservation, corrective actions, closure and lessons learned. Entries are the dated Arcfield Platform operating log sampled on the 11 September 2026 freeze in the surveillance cycle after certificate ARC-ISMS-2025-001. It cites IL-005 / INC-2026-0822 as the High event of this freeze.",
      "contentType": "narrative"
    },
    {
      "id": "document_control",
      "title": "Document Control",
      "rows": [
        {
          "Property": "Purpose",
          "Value": "Maintain auditable incident records and follow-up evidence."
        },
        {
          "Property": "Used by",
          "Value": "Incident Manager, Security Lead, IT Operations, ISMS Manager, Internal Auditor"
        },
        {
          "Property": "Maintained by",
          "Value": "Incident Manager"
        },
        {
          "Property": "Evidence role",
          "Value": "Incident handling and corrective-action evidence"
        },
        {
          "Property": "ISO reference",
          "Value": "ISO/IEC 27001:2022 A.5.24, A.5.25, A.5.26, A.5.27 and A.5.28"
        },
        {
          "Property": "Review cadence",
          "Value": "Weekly for open incidents, monthly trend review and after high-severity closure"
        }
      ],
      "contentType": "control_table"
    },
    {
      "id": "instructions",
      "title": "Instructions",
      "items": [
        "Register every reported security event or incident.",
        "Capture timeline, detection source, classification, impact and owner.",
        "Preserve investigation and containment evidence.",
        "Link corrective actions for root-cause or control improvements.",
        "Close only when impact, evidence and lessons learned have been reviewed.",
        "Use sheets ending in “Ex” as read-only examples. Enter live data only on the matching “Wk” (Working) sheets.",
        "Every operative list is an Excel Table with frozen headers and filters. Add new rows on the next empty worksheet row beneath the table so Excel expands it — do not leave blank rows inside the table.",
        "Where a column offers a dropdown, choose a value from the list (Status, Owner role, Priority, Severity, Likelihood, Impact, Applicability, Evidence Status, Review Result). Do not invent free-text variants.",
        "Enter dates as YYYY-MM-DD. Date columns are validated and formatted accordingly.",
        "Review the Flag columns (Overdue, Review Due, Missing Owner, Missing Evidence). They calculate automatically and highlight gaps for follow-up.",
        "Keep Cover, Legal, Book, Lists and Metadata unchanged. System sheets are protected on purpose."
      ],
      "contentType": "ordered_list"
    },
    {
      "id": "incident_log",
      "title": "Incident log",
      "schemaRef": {
        "definitionId": "IL.artifactDefinition.v2",
        "sectionId": "incident_log",
        "columnsRef": "sections.incident_log.columns"
      },
      "rows": [
        {
          "Incident ID": "IL-001",
          "Reported Date": "2026-08-03",
          "Reporter Role": "Employee",
          "Detection Source": "Phishing report button",
          "Category": "Suspicious email",
          "Severity": "Low",
          "Status": "Closed",
          "Owner": "Incident Manager",
          "Affected Asset or Process": "Corporate email",
          "Impact Summary": "No credential submission; message removed from two mailboxes.",
          "Containment Action": "Message quarantined and sender blocked.",
          "Root Cause": "External phishing campaign",
          "Corrective Action Reference": "CAR-2026-021",
          "Evidence Reference": "INC-TKT-2026-0803",
          "Closure Date": "2026-08-04",
          "Lessons Learned": "Awareness reminder added to August newsletter."
        },
        {
          "Incident ID": "IL-002",
          "Reported Date": "2026-08-07",
          "Reporter Role": "Monitoring",
          "Detection Source": "EDR alert",
          "Category": "Malware detection",
          "Severity": "Medium",
          "Status": "Closed",
          "Owner": "Security Lead",
          "Affected Asset or Process": "Finance laptop",
          "Impact Summary": "Malware blocked before execution; no data loss identified.",
          "Containment Action": "Device isolated, scanned and reimaged.",
          "Root Cause": "Unapproved browser extension",
          "Corrective Action Reference": "CAR-2026-024",
          "Evidence Reference": "EDR-CASE-4481",
          "Closure Date": "2026-08-09",
          "Lessons Learned": "Extension allowlist review added."
        },
        {
          "Incident ID": "IL-003",
          "Reported Date": "2026-08-11",
          "Reporter Role": "Cloud monitoring",
          "Detection Source": "SIEM alert",
          "Category": "Unauthorized access attempt",
          "Severity": "Medium",
          "Status": "In review",
          "Owner": "IT Operations Manager",
          "Affected Asset or Process": "Cloud administration portal",
          "Impact Summary": "Repeated failed login attempts against disabled account.",
          "Containment Action": "Account confirmed disabled; source IP blocked.",
          "Root Cause": "Credential stuffing attempt",
          "Corrective Action Reference": "ARR-003",
          "Evidence Reference": "SIEM-ALERT-2026-811",
          "Closure Date": "",
          "Lessons Learned": "Review dormant account monitoring threshold."
        },
        {
          "Incident ID": "IL-004",
          "Reported Date": "2026-08-18",
          "Reporter Role": "Supplier notification",
          "Detection Source": "Supplier security advisory",
          "Category": "Supplier incident",
          "Severity": "Medium",
          "Status": "Open",
          "Owner": "Supplier Manager",
          "Affected Asset or Process": "CloudHost analytics service",
          "Impact Summary": "Supplier reports service disruption; no Arcfield data exposure confirmed.",
          "Containment Action": "Service dependency monitored; customer impact assessment started.",
          "Root Cause": "Supplier infrastructure outage",
          "Corrective Action Reference": "SINV-2026-009",
          "Evidence Reference": "SUP-ADV-2026-0818",
          "Closure Date": "",
          "Lessons Learned": "Pending supplier final report."
        },
        {
          "Incident ID": "IL-005",
          "Reported Date": "2026-08-22",
          "Reporter Role": "Engineering",
          "Detection Source": "Change validation failure",
          "Category": "Misconfiguration",
          "Severity": "High",
          "Status": "Contained",
          "Owner": "Engineering Lead",
          "Affected Asset or Process": "Customer support knowledge base",
          "Impact Summary": "Internal draft articles were world-readable for 12 minutes. No confirmed Arcfield Platform customer PII exposure.",
          "Containment Action": "Permission reverted and access logs preserved.",
          "Root Cause": "Manual change outside the standard deployment workflow",
          "Corrective Action Reference": "CAR-2026-027",
          "Evidence Reference": "CHG-POST-2026-0822",
          "Closure Date": "",
          "Lessons Learned": "Stage 2 had sampled change and access as Implemented. The event showed peer approval and configuration evidence were not as robust as that sample suggested. Evidence on this freeze is therefore Partial on many Implemented rows — honesty after re-sampling, not a drop in the Implemented count. CYB-CLM-2026-001 against Northbridge Cyber (worked example) was Denied: Unapproved production change (policy requires the documented change process); No evidenced first-party loss (12-minute internal drafts; no confirmed customer data) Risk treatment Transfer / insurance is not a control. A denied claim is residual risk still on Arcfield. Do not write Transfer on RISK-2026-041 as if the insurer paid.",
          "Notes": "CYB-CLM-2026-001 Denied 2026-09-03"
        },
        {
          "Incident ID": "IL-006",
          "Reported Date": "2026-08-27",
          "Reporter Role": "HR",
          "Detection Source": "Offboarding checklist review",
          "Category": "Access delay",
          "Severity": "Low",
          "Status": "Closed",
          "Owner": "HR Manager",
          "Affected Asset or Process": "Collaboration workspace",
          "Impact Summary": "Former contractor retained workspace access for six hours after end date.",
          "Containment Action": "Access removed; activity log reviewed.",
          "Root Cause": "Manual offboarding handover delay",
          "Corrective Action Reference": "OFC-2026-014",
          "Evidence Reference": "ACCESS-REVIEW-2026-0827",
          "Closure Date": "2026-08-28",
          "Lessons Learned": "Automated offboarding reminder added."
        }
      ],
      "contentType": "register_table"
    },
    {
      "id": "incident_review_decision",
      "title": "Incident review decision",
      "values": {
        "Review result": "Controlled with one open supplier incident and one contained high-severity incident under corrective action",
        "Incidents reviewed": 6,
        "Open incidents": 2,
        "High-severity incidents": 1,
        "Corrective actions open": 4,
        "Reviewed by": "Incident Manager",
        "Decision date": "2026-08-29",
        "Evidence reference": "IL-REVIEW-2026-08"
      },
      "rows": [
        {
          "Field": "Review result",
          "Value": "Controlled with one open supplier incident and one contained high-severity incident under corrective action"
        },
        {
          "Field": "Incidents reviewed",
          "Value": "6"
        },
        {
          "Field": "Open incidents",
          "Value": "2"
        },
        {
          "Field": "High-severity incidents",
          "Value": "1"
        },
        {
          "Field": "Corrective actions open",
          "Value": "4"
        },
        {
          "Field": "Reviewed by",
          "Value": "Incident Manager"
        },
        {
          "Field": "Decision date",
          "Value": "2026-08-29"
        },
        {
          "Field": "Evidence reference",
          "Value": "IL-REVIEW-2026-08"
        }
      ],
      "contentType": "decision_table"
    },
    {
      "id": "external_references",
      "title": "References",
      "groups": [
        {
          "text": "Cite these sources from workshops and audits. This list names ISO clauses, book chapters and companion artifacts used by this file."
        },
        {
          "rows": [
            {
              "Kind": "ISO",
              "Reference": "ISO/IEC 27001:2022",
              "How this document uses it": "Normative source this artifact implements or cites.",
              "href": "https://www.iso.org/standard/82875.html"
            },
            {
              "Kind": "Book",
              "Reference": "Secure Engineering, Incident Response & Security Monitoring",
              "How this document uses it": "Primary operating chapter for this companion artifact.",
              "href": "https://www.amazon.com/dp/9789908983455"
            },
            {
              "Kind": "Artifact",
              "Reference": "CAR Corrective Actions Register (Building the ISMS, Context of the Organization (Clause 4))",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/dp/9789908983448"
            },
            {
              "Kind": "Artifact",
              "Reference": "ISO Information Security Objectives (Building the ISMS, Information Security Policies & Risk Management)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/dp/9789908983448"
            },
            {
              "Kind": "Artifact",
              "Reference": "ARR Access Rights Register (Secure Engineering, Access Control & Identity Management)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/dp/9789908983455"
            },
            {
              "Kind": "Artifact",
              "Reference": "OFC Offboarding Checklist (Building the ISMS, Context of the Organization (Clause 4))",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/dp/9789908983448"
            }
          ]
        }
      ],
      "contentType": "reference_table"
    }
  ],
  "enrichment": {
    "source": "Example.json",
    "method": "curated-json",
    "note": "Completes Example JSON with renderer-native sections and generalized groups; no mdSource helper fields."
  },
  "snapshotRef": {
    "snapshotId": "arcfield.platform.surv.2026-09-11",
    "schemaVersion": "evidenceSnapshot.v1"
  },
  "scenarioRef": {
    "githubIssue": 64,
    "crId": "CR-TYPE-ARCFIELD-001",
    "family": "Log",
    "role": "Dated operating log sampled on the freeze"
  }
}
