{
  "schemaVersion": "artifactDefinition.v2",
  "definitionId": "IRPROC.artifactDefinition.v2",
  "artifactId": "IRPROC",
  "title": "Incident Response Procedure",
  "artifactType": "Procedure",
  "format": "docx",
  "productTier": "Premium",
  "definitionRole": "contract",
  "sourceModel": {
    "body": "canonical human-readable workflow maintained in the Artifact Candidate page",
    "jsonDefinition": "machine-readable contract and validation model",
    "jsonExample": "curated realistic example workflow data fixture"
  },
  "purpose": "Define the response flow, escalation logic, roles and outputs for security incidents.",
  "sections": [
    {
      "order": 1,
      "id": "title_page",
      "title": "Title Page",
      "contentType": "metadata",
      "required": true,
      "hint": null
    },
    {
      "order": 2,
      "id": "abstract",
      "title": "Abstract",
      "contentType": "narrative",
      "required": true,
      "hint": {
        "text": "Use IRPROC as the master incident workflow before selecting incident-type procedures or detailed runbooks.",
        "bookReference": "Volume 3, S-01-07-00 Incident Response & Security Monitori"
      }
    },
    {
      "order": 3,
      "id": "document_control",
      "title": "Document Control",
      "contentType": "control_table",
      "required": true,
      "hint": null
    },
    {
      "order": 4,
      "id": "change_log",
      "title": "Revision history",
      "contentType": "revision_table",
      "required": true
    },
    {
      "order": 5,
      "id": "instructions",
      "title": "Instructions",
      "contentType": "ordered_list",
      "required": true,
      "hint": {
        "text": "Capture timeline, decisions, evidence and communications while the incident is active, not after memory fades.",
        "bookReference": "Volume 3, S-01-07-00 Incident Response & Security Monitori"
      }
    },
    {
      "order": 6,
      "id": "workflow_schema",
      "title": "Workflow schema",
      "contentType": "workflow_schema",
      "required": true,
      "steps": [
        "Detect and report event",
        "Create incident record",
        "Triage severity and scope",
        "Assign incident owner",
        "Contain immediate risk",
        "Preserve evidence",
        "Investigate cause and impact",
        "Recover and validate controls",
        "Communicate and escalate",
        "Close with lessons learned"
      ],
      "hint": {
        "text": "The schema should make escalation, containment, evidence and closure decisions auditable.",
        "bookReference": "Volume 3, S-01-07-00 Incident Response & Security Monitori"
      }
    },
    {
      "order": 7,
      "id": "workflow_steps",
      "title": "Workflow steps",
      "contentType": "workflow_steps",
      "required": true,
      "hint": {
        "text": "Each step should show trigger, role, output, evidence reference and current status.",
        "bookReference": "Volume 3, S-01-07-00 Incident Response & Security Monitori"
      }
    },
    {
      "order": 8,
      "id": "roles_and_responsibilities",
      "title": "Roles and responsibilities",
      "contentType": "role_table",
      "required": true,
      "hint": {
        "text": "Separate command, technical response, communication and business decision roles.",
        "bookReference": "Volume 3, S-01-07-00 Incident Response & Security Monitori"
      }
    },
    {
      "order": 9,
      "id": "evidence_and_records",
      "title": "Evidence and records",
      "contentType": "evidence_table",
      "required": true,
      "hint": {
        "text": "Preserve evidence in a way that supports root-cause analysis, legal review and lessons learned.",
        "bookReference": "Volume 3, S-01-07-00 Incident Response & Security Monitori"
      }
    },
    {
      "order": 10,
      "id": "review_and_decision",
      "title": "Review and decision",
      "contentType": "decision_table",
      "required": true,
      "fields": [
        {
          "name": "Decision",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Incidents reviewed",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Major incidents",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Open corrective actions",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Customer or regulator assessment",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Reviewed by",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Decision date",
          "type": "date",
          "required": "yes"
        },
        {
          "name": "Evidence reference",
          "type": "text",
          "required": "yes"
        }
      ],
      "hint": {
        "text": "Close with a decision so lessons learned and corrective actions feed continual improvement.",
        "bookReference": "Volume 3, S-01-07-00 Incident Response & Security Monitori"
      }
    },
    {
      "order": 11,
      "id": "external_references",
      "title": "References",
      "contentType": "reference_table",
      "required": true,
      "hint": {
        "text": "Apply References with named owners, systems and exportable evidence. Do not leave this chapter as a heading plus a bare table.",
        "bookReference": "Volume 3, S-01-07-00 Incident Response & Security Monitori"
      }
    }
  ],
  "validationRules": [
    "JSON Example must contain definitionRef pointing to IRPROC.artifactDefinition.v2.",
    "JSON Example workflow sections must contain schemaRef pointing to the matching definition section.",
    "Workflow steps must include step ID, trigger, activity, responsible role, input, output, evidence reference and status.",
    "Body must render workflow schema, example steps, roles, evidence and review decision.",
    "No standalone Book reference section, mdDefinition, mdExample or generic Sample placeholders are allowed."
  ],
  "enrichment": {
    "source": "Contract.json",
    "method": "curated-json",
    "note": "Completes Contract JSON from MD-only schema/sections, removes duplicate alias sections, and normalizes string columns into structured column objects."
  },
  "editorialStandard": {
    "isoAnchors": [
      {
        "label": "ISO/IEC 27001:2022 A.5.24",
        "href": "https://www.iso.org/standard/82875.html",
        "role": "Annex A control this artifact implements."
      },
      {
        "label": "ISO/IEC 27001:2022 A.5.25",
        "href": "https://www.iso.org/standard/82875.html",
        "role": "Annex A control this artifact implements."
      },
      {
        "label": "ISO/IEC 27001:2022 A.5.26",
        "href": "https://www.iso.org/standard/82875.html",
        "role": "Annex A control this artifact implements."
      },
      {
        "label": "ISO/IEC 27001:2022 A.5.27",
        "href": "https://www.iso.org/standard/82875.html",
        "role": "Annex A control this artifact implements."
      },
      {
        "label": "ISO/IEC 27001:2022 A.5.28",
        "href": "https://www.iso.org/standard/82875.html",
        "role": "Annex A control this artifact implements."
      },
      {
        "label": "ISO/IEC 27001:2022",
        "href": "https://www.iso.org/standard/82875.html",
        "role": "Normative source this artifact implements or cites."
      }
    ],
    "bookSources": [
      {
        "series": "ISO 27001 for Software Companies",
        "volume": 3,
        "volumeTitle": "Secure Engineering",
        "chapterId": "S-01-07-00",
        "chapterTitle": "Incident Response & Security Monitoring",
        "primary": true,
        "role": "Primary operating chapter for this companion artifact.",
        "href": "https://www.amazon.com/dp/9789908983455"
      },
      {
        "series": "ISO 27001 for Software Companies",
        "volume": 1,
        "volumeTitle": "Building the ISMS",
        "chapterId": "S-00-03-00",
        "chapterTitle": "Planning, Risk & Objectives (Clause 6)",
        "primary": false,
        "role": "Documented information, review and version discipline.",
        "href": "https://www.amazon.com/dp/9789908983448"
      }
    ],
    "purpose": "Define the response flow, escalation logic, roles and outputs for security incidents.",
    "requiredEditorialElements": [
      "introduction as purpose prose",
      "scope of this document versus neighbouring records",
      "terms as a first-class group",
      "worked Arcfield example",
      "practical examples, pitfalls, evidence and external references"
    ],
    "acronyms": [
      {
        "abbr": "ISMS",
        "longForm": "Information Security Management System"
      },
      {
        "abbr": "SaaS",
        "longForm": "Software as a Service"
      },
      {
        "abbr": "CIA",
        "longForm": "Confidentiality, Integrity, and Availability"
      },
      {
        "abbr": "CI/CD",
        "longForm": "Continuous Integration / Continuous Delivery"
      },
      {
        "abbr": "CI",
        "longForm": "Continuous Integration"
      },
      {
        "abbr": "CD",
        "longForm": "Continuous Delivery"
      },
      {
        "abbr": "EV",
        "longForm": "Extended Validation"
      },
      {
        "abbr": "IR",
        "longForm": "Incident Response"
      },
      {
        "abbr": "JSON",
        "longForm": "JavaScript Object Notation"
      },
      {
        "abbr": "MFA",
        "longForm": "Multi-Factor Authentication"
      },
      {
        "abbr": "RAM",
        "longForm": "Risk Assessment Methodology"
      },
      {
        "abbr": "RAMT",
        "longForm": "Risk Acceptance Minutes"
      },
      {
        "abbr": "RR",
        "longForm": "Risk Register"
      },
      {
        "abbr": "SSO",
        "longForm": "Single Sign-On"
      },
      {
        "abbr": "SoA",
        "longForm": "Statement of Applicability"
      }
    ],
    "must": [
      "This file's function is: Define the response flow, escalation logic, roles and outputs for security incidents. It must not be rewritten as a generic operating-rules essay.",
      "Log every suspected incident in the incident register.",
      "Triage severity, scope, affected assets and immediate risk.",
      "Assign an incident owner and activate the response channel.",
      "Select the applicable incident-type procedure or runbook.",
      "Preserve evidence and maintain an incident timeline.",
      "Close only after recovery, validation, communication assessment and lessons learned."
    ],
    "mustNot": [
      "Do not replace this artifact's function with a shared family skeleton (operating_rules, systems_and_records)."
    ],
    "softwareCompanyAdaptations": [
      "Use Arcfield as the worked example (cover variant A).",
      "Name SaaS, cloud, CI/CD, privileged access or supplier interfaces where they affect this artifact's function."
    ],
    "exampleBody": {
      "sectionId": "workflow_steps",
      "workedExampleOrg": "Arcfield",
      "minBodyWords": 400,
      "requiredGroups": [
        {
          "id": "introduction",
          "heading": "What this procedure is",
          "mustInclude": [
            "procedure"
          ]
        },
        {
          "id": "scope",
          "heading": "Scope",
          "mustInclude": [
            "Scope"
          ]
        },
        {
          "id": "terms",
          "heading": "Terms used here",
          "mustInclude": [
            "Terms"
          ]
        },
        {
          "id": "workflow_steps",
          "heading": "Workflow steps",
          "mustInclude": [
            "Workflow",
            "steps"
          ]
        },
        {
          "id": "roles_and_responsibilities",
          "heading": "Roles and responsibilities",
          "mustInclude": [
            "Roles",
            "responsibilities"
          ]
        },
        {
          "id": "review_and_decision",
          "heading": "Review and decision",
          "mustInclude": [
            "Review",
            "decision"
          ]
        }
      ],
      "requiredSections": [
        {
          "id": "change_log",
          "title": "Revision history",
          "role": "Versioned freeze log with how-to sentence and rows Version, Date, Change, Approved by. Last Version matches title_page.values.Version."
        },
        {
          "id": "external_references",
          "title": "References",
          "role": "ISO clauses, book chapters and companion artifacts. Not a series catalogue."
        }
      ]
    }
  },
  "editorialContractId": "editorial.docx.workflow.v1",
  "contentContractId": "content.procedure.v1",
  "relations": [
    {
      "kind": "cites",
      "artifactId": "MDR",
      "role": "evidence_register",
      "expectedType": "Register",
      "rank": 30
    },
    {
      "kind": "cites",
      "artifactId": "DR",
      "role": "evidence_register",
      "expectedType": "Register",
      "rank": 31
    },
    {
      "kind": "cites",
      "artifactId": "RRS",
      "role": "evidence_register",
      "expectedType": "Register",
      "rank": 32
    }
  ]
}
