{
  "schemaVersion": "artifactExample.v2",
  "artifactId": "IRPROC",
  "title": "Incident Response Procedure",
  "definitionRef": {
    "artifactId": "IRPROC",
    "definitionSchemaVersion": "artifactDefinition.v2",
    "definitionId": "IRPROC.artifactDefinition.v2",
    "title": "Incident Response Procedure"
  },
  "organization": "Arcfield",
  "sections": [
    {
      "id": "title_page",
      "title": "Title Page",
      "values": {
        "Workflow Title": "Incident Response Procedure",
        "Workflow ID": "IRPROC-WF-001",
        "Version": "1.1",
        "Status": "Approved",
        "Organization": "Arcfield",
        "Owner": "Incident Manager",
        "Approver": "ISMS Manager",
        "Classification": "Internal",
        "Effective Date": "2026-09-11",
        "Next Review Date": "2027-09-11"
      },
      "items": [
        "Workflow Title: Incident Response Procedure",
        "Workflow ID: IRPROC-WF-001",
        "Version: 1.1",
        "Status: Approved",
        "Organization: Arcfield",
        "Owner: Incident Manager",
        "Approver: ISMS Manager",
        "Classification: Internal",
        "Effective Date: 2026-09-11",
        "Next Review Date: 2027-09-11"
      ],
      "contentType": "metadata"
    },
    {
      "id": "abstract",
      "title": "Abstract",
      "text": "This example shows the master incident-response workflow from detection through triage, containment, evidence preservation, investigation, recovery, communication and closure. It highlights a common failure mode: incident tickets are closed before impact assessment, notification decision and corrective action evidence are complete. This is the operating method sampled on the 11 September 2026 freeze during the surveillance cycle after certificate ARC-ISMS-2025-001. It cites IL-005 / INC-2026-0822 as the High event of this freeze.",
      "contentType": "narrative"
    },
    {
      "id": "document_control",
      "title": "Document Control",
      "contentType": "control_table"
    },
    {
      "id": "change_log",
      "title": "Revision history",
      "groups": [
        {
          "text": "A published change is a new row. Do not edit an approved version in place."
        },
        {
          "rows": [
            {
              "Version": "1.0",
              "Date": "2026-08-29",
              "Change": "Initial Arcfield Platform publication.",
              "Approved by": "ISMS Manager"
            },
            {
              "Version": "1.1",
              "Date": "2026-09-11",
              "Change": "Approved Arcfield worked example after the 11 September 2026 internal audit.",
              "Approved by": "ISMS Manager"
            }
          ]
        }
      ],
      "contentType": "revision_table"
    },
    {
      "id": "instructions",
      "title": "Instructions",
      "groups": [
        {
          "text": "Copy this file as the controlled Word master for your ISMS. The Arcfield identity fields on the cover are the approved worked example. Complete the steps below when you adopt the file for your organization."
        },
        {
          "items": [
            "Fill the cover identity fields (Organization, Version, Classification, Owner, Approver, Effective Date and Next Review Date) when you adopt this file. The Arcfield values shown here are the approved worked example.",
            "Issue your own version and a new Revision history row. Do not edit an approved version in place.",
            "Cite this approved version from related records. Do not copy this file into those records."
          ]
        }
      ],
      "contentType": "ordered_list"
    },
    {
      "id": "workflow_schema",
      "title": "Workflow schema",
      "steps": [
        "Detect and report event",
        "Create incident record",
        "Triage severity and scope",
        "Assign incident owner",
        "Contain immediate risk",
        "Preserve evidence",
        "Investigate cause and impact",
        "Recover and validate controls",
        "Communicate and escalate",
        "Close with lessons learned"
      ],
      "groups": [
        {
          "id": "introduction",
          "heading": "What this procedure is",
          "level": 1,
          "text": "This document is Arcfield's Incident Response Procedure. Define the response flow, escalation logic, roles and outputs for security incidents. It is not the policy that sets the rule or the register that stores the live rows. This procedure applies to the Arcfield Platform (B2B SaaS for regulated fintech and health customers): production, customer data, CI/CD, privileged access and critical suppliers. Neighbouring records (IRRT, SIR, CAR) cite this Document Control version. Do not copy these paragraphs into them."
        },
        {
          "id": "scope",
          "heading": "Scope",
          "level": 1,
          "text": "Use this table before you copy a rule into another record or exclude a duty from this file.",
          "rows": [
            {
              "In this procedure": "The rules, roles, worked Arcfield example and the records this file owns.",
              "Not in this procedure": "The ISMS boundary (ISS), Annex A selection (SoA) or live rows in IRRT, SIR, CAR.",
              "Evidence reference": "IRPROC-EV-2026-Q3",
              "Evidence status": "Complete"
            },
            {
              "In this procedure": "Interfaces that must cite this Document Control version, including CI/CD, identity and suppliers where they affect CIA.",
              "Not in this procedure": "Live ISS scope rows, SoA applicability decisions, or neighbouring live registers. Those files keep their own approved versions.",
              "Evidence reference": "IRPROC-EV-2026-Q3",
              "Evidence status": "Complete"
            }
          ]
        },
        {
          "id": "terms",
          "heading": "Terms used here",
          "level": 1,
          "text": "These terms are local to this file. Expand every acronym on first use in the body.",
          "rows": [
            {
              "Term": "Owner",
              "Meaning": "The named role that can be called in an audit for an outcome. A team name is not an owner."
            },
            {
              "Term": "Exception",
              "Meaning": "A time-bound, approved departure with expiry and a compensating control."
            },
            {
              "Term": "CIA",
              "Meaning": "Confidentiality, Integrity and Availability of in-scope information and services."
            },
            {
              "Term": "Document Control version",
              "Meaning": "The approved version cited from neighbouring records. Do not copy this body into those records."
            }
          ]
        },
        {
          "id": "workflow_steps",
          "heading": "Workflow steps",
          "level": 1,
          "text": "Use this table for workflow steps in the Arcfield Platform ISMS. Step ID Trigger Activity Responsible Role Input Output Evidence Reference Status IRPROC-STEP-001 Security alert or user report received Detect, report and log the event. Reporter or Security Analyst Alert, user report or supplier notice Initial event record SIR-2026-0829-003 Complete IRPROC-STEP-002 Event record created Triage severity, scope, affected assets and immediate risk. Incident Manager Initial event record and affected service data Incident classification IRRT-TRIAGE-2026-0829-003 Complete IRPROC-STEP-003 Incident classified as security incident Assign incident owner and activate response channel. Incident Manager Classification result Assigned response team ICL-2026-Q3 Complete IRPROC-STEP-004 Immediate risk confirmed Contain affected account, endpoint, service or supplier route. Security Lead Triage data and runbook selection Containment action record IR-RB-PHISH-2026-0829 Complete IRPROC-STEP-005 Containment started Preserve evidence and build incident timeline. Security Analyst Logs, tickets, headers and system snapshots Evidence package SIR-EV-2026-0829-003 Complete IRPROC-STEP-006 Evidence package available Investigate root cause, impact and notification obligations. Incident Manager Evidence package and impact data Impact assessment IRRT-IMPACT-2026-0829-003 Open follow-up IRPROC-STEP-007 Recovery conditions met Recover service, validate controls and close with lessons learned. Service Owner Impact assessment and recovery plan Closure and corrective actions CAR-IR-2026-0829-003 Scheduled Cite this Document Control version from neighbouring records.",
          "rows": [
            {
              "Step ID": "IRPROC-STEP-001",
              "Trigger": "Security alert or user report received",
              "Activity": "Detect, report and log the event.",
              "Responsible Role": "Reporter or Security Analyst",
              "Input": "Alert, user report or supplier notice",
              "Output": "Initial event record",
              "Evidence Reference": "SIR-2026-0829-003",
              "Status": "Complete",
              "Evidence reference": "SIR-2026-0829-003"
            },
            {
              "Step ID": "IRPROC-STEP-002",
              "Trigger": "Event record created",
              "Activity": "Triage severity, scope, affected assets and immediate risk.",
              "Responsible Role": "Incident Manager",
              "Input": "Initial event record and affected service data",
              "Output": "Incident classification",
              "Evidence Reference": "IRRT-TRIAGE-2026-0829-003",
              "Status": "Complete",
              "Evidence reference": "IRRT-TRIAGE-2026-0829-003"
            },
            {
              "Step ID": "IRPROC-STEP-003",
              "Trigger": "Incident classified as security incident",
              "Activity": "Assign incident owner and activate response channel.",
              "Responsible Role": "Incident Manager",
              "Input": "Classification result",
              "Output": "Assigned response team",
              "Evidence Reference": "ICL-2026-Q3",
              "Status": "Complete",
              "Evidence reference": "ICL-2026-Q3"
            },
            {
              "Step ID": "IRPROC-STEP-004",
              "Trigger": "Immediate risk confirmed",
              "Activity": "Contain affected account, endpoint, service or supplier route.",
              "Responsible Role": "Security Lead",
              "Input": "Triage data and runbook selection",
              "Output": "Containment action record",
              "Evidence Reference": "IR-RB-PHISH-2026-0829",
              "Status": "Complete",
              "Evidence reference": "IR-RB-PHISH-2026-0829"
            },
            {
              "Step ID": "IRPROC-STEP-005",
              "Trigger": "Containment started",
              "Activity": "Preserve evidence and build incident timeline.",
              "Responsible Role": "Security Analyst",
              "Input": "Logs, tickets, headers and system snapshots",
              "Output": "Evidence package",
              "Evidence Reference": "SIR-EV-2026-0829-003",
              "Status": "Complete",
              "Evidence reference": "SIR-EV-2026-0829-003"
            },
            {
              "Step ID": "IRPROC-STEP-006",
              "Trigger": "Evidence package available",
              "Activity": "Investigate root cause, impact and notification obligations.",
              "Responsible Role": "Incident Manager",
              "Input": "Evidence package and impact data",
              "Output": "Impact assessment",
              "Evidence Reference": "IRRT-IMPACT-2026-0829-003",
              "Status": "Open follow-up",
              "Evidence reference": "IRRT-IMPACT-2026-0829-003"
            },
            {
              "Step ID": "IRPROC-STEP-007",
              "Trigger": "Recovery conditions met",
              "Activity": "Recover service, validate controls and close with lessons learned.",
              "Responsible Role": "Service Owner",
              "Input": "Impact assessment and recovery plan",
              "Output": "Closure and corrective actions",
              "Evidence Reference": "CAR-IR-2026-0829-003",
              "Status": "Scheduled",
              "Evidence reference": "CAR-IR-2026-0829-003"
            }
          ]
        },
        {
          "id": "roles_and_responsibilities",
          "heading": "Roles and responsibilities",
          "level": 1,
          "text": "Use this table for roles and responsibilities in the Arcfield Platform ISMS. Role Responsibility Incident Manager Coordinates response, classification, escalation, closure and lessons learned. Security Lead Leads containment, eradication and security decisions. Security Analyst Collects evidence, timeline and technical analysis. Service Owner Owns service recovery and operational validation. Legal or Privacy Lead Assesses notification and contractual communication obligations. Cite this Document Control version from neighbouring records.",
          "rows": [
            {
              "Role": "Incident Manager",
              "Responsibility": "Coordinates response, classification, escalation, closure and lessons learned.",
              "Evidence reference": "IRPROC-EV-2026-Q3",
              "Evidence status": "Complete"
            },
            {
              "Role": "Security Lead",
              "Responsibility": "Leads containment, eradication and security decisions.",
              "Evidence reference": "IRPROC-EV-2026-Q3",
              "Evidence status": "Complete"
            },
            {
              "Role": "Security Analyst",
              "Responsibility": "Collects evidence, timeline and technical analysis.",
              "Evidence reference": "IRPROC-EV-2026-Q3",
              "Evidence status": "Complete"
            },
            {
              "Role": "Service Owner",
              "Responsibility": "Owns service recovery and operational validation.",
              "Evidence reference": "IRPROC-EV-2026-Q3",
              "Evidence status": "Complete"
            },
            {
              "Role": "Legal or Privacy Lead",
              "Responsibility": "Assesses notification and contractual communication obligations.",
              "Evidence reference": "IRPROC-EV-2026-Q3",
              "Evidence status": "Complete"
            }
          ]
        },
        {
          "id": "review_and_decision",
          "heading": "Review and decision",
          "level": 1,
          "text": "Use this table for review and decision in the Arcfield Platform ISMS. Field Value Decision Incident workflow activated and containment completed; impact assessment and corrective action remain open. Incidents reviewed 1 Major incidents 0 Open corrective actions 1 Customer or regulator assessment No notification required based on current impact assessment. Reviewed by Incident Manager Decision date 2026-08-29 Evidence reference IRPROC-REVIEW-2026-0829-003 Cite this Document Control version from neighbouring records.",
          "rows": [
            {
              "Field": "Decision",
              "Value": "Incident workflow activated and containment completed; impact assessment and corrective action remain open.",
              "Evidence reference": "IRPROC-REVIEW-2026-0829-003",
              "Evidence status": "Complete"
            },
            {
              "Field": "Incidents reviewed",
              "Value": "1",
              "Evidence reference": "IRPROC-REVIEW-2026-0829-003",
              "Evidence status": "Complete"
            },
            {
              "Field": "Major incidents",
              "Value": "0",
              "Evidence reference": "IRPROC-REVIEW-2026-0829-003",
              "Evidence status": "Complete"
            },
            {
              "Field": "Open corrective actions",
              "Value": "1",
              "Evidence reference": "IRPROC-REVIEW-2026-0829-003",
              "Evidence status": "Complete"
            },
            {
              "Field": "Customer or regulator assessment",
              "Value": "No notification required based on current impact assessment.",
              "Evidence reference": "IRPROC-REVIEW-2026-0829-003",
              "Evidence status": "Complete"
            },
            {
              "Field": "Reviewed by",
              "Value": "Incident Manager",
              "Evidence reference": "IRPROC-REVIEW-2026-0829-003",
              "Evidence status": "Complete"
            },
            {
              "Field": "Decision date",
              "Value": "2026-08-29",
              "Evidence reference": "IRPROC-REVIEW-2026-0829-003",
              "Evidence status": "Complete"
            },
            {
              "Field": "Evidence reference",
              "Value": "IRPROC-REVIEW-2026-0829-003",
              "Evidence reference": "IRPROC-REVIEW-2026-0829-003",
              "Evidence status": "Complete"
            }
          ]
        }
      ],
      "contentType": "workflow_schema"
    },
    {
      "id": "workflow_steps",
      "title": "Workflow steps",
      "schemaRef": {
        "definitionId": "IRPROC.artifactDefinition.v2",
        "sectionId": "workflow_steps"
      },
      "steps": [
        {
          "Step ID": "IRPROC-STEP-001",
          "Trigger": "Security alert or user report received",
          "Activity": "Detect, report and log the event.",
          "Responsible Role": "Reporter or Security Analyst",
          "Input": "Alert, user report or supplier notice",
          "Output": "Initial event record",
          "Evidence Reference": "SIR-2026-0829-003",
          "Status": "Complete"
        },
        {
          "Step ID": "IRPROC-STEP-002",
          "Trigger": "Event record created",
          "Activity": "Triage severity, scope, affected assets and immediate risk.",
          "Responsible Role": "Incident Manager",
          "Input": "Initial event record and affected service data",
          "Output": "Incident classification",
          "Evidence Reference": "IRRT-TRIAGE-2026-0829-003",
          "Status": "Complete"
        },
        {
          "Step ID": "IRPROC-STEP-003",
          "Trigger": "Incident classified as security incident",
          "Activity": "Assign incident owner and activate response channel.",
          "Responsible Role": "Incident Manager",
          "Input": "Classification result",
          "Output": "Assigned response team",
          "Evidence Reference": "ICL-2026-Q3",
          "Status": "Complete"
        },
        {
          "Step ID": "IRPROC-STEP-004",
          "Trigger": "Immediate risk confirmed",
          "Activity": "Contain affected account, endpoint, service or supplier route.",
          "Responsible Role": "Security Lead",
          "Input": "Triage data and runbook selection",
          "Output": "Containment action record",
          "Evidence Reference": "IR-RB-PHISH-2026-0829",
          "Status": "Complete"
        },
        {
          "Step ID": "IRPROC-STEP-005",
          "Trigger": "Containment started",
          "Activity": "Preserve evidence and build incident timeline.",
          "Responsible Role": "Security Analyst",
          "Input": "Logs, tickets, headers and system snapshots",
          "Output": "Evidence package",
          "Evidence Reference": "SIR-EV-2026-0829-003",
          "Status": "Complete"
        },
        {
          "Step ID": "IRPROC-STEP-006",
          "Trigger": "Evidence package available",
          "Activity": "Investigate root cause, impact and notification obligations.",
          "Responsible Role": "Incident Manager",
          "Input": "Evidence package and impact data",
          "Output": "Impact assessment",
          "Evidence Reference": "IRRT-IMPACT-2026-0829-003",
          "Status": "Open follow-up"
        },
        {
          "Step ID": "IRPROC-STEP-007",
          "Trigger": "Recovery conditions met",
          "Activity": "Recover service, validate controls and close with lessons learned.",
          "Responsible Role": "Service Owner",
          "Input": "Impact assessment and recovery plan",
          "Output": "Closure and corrective actions",
          "Evidence Reference": "CAR-IR-2026-0829-003",
          "Status": "Scheduled"
        }
      ],
      "groups": [
        {
          "id": "introduction",
          "heading": "What this procedure is",
          "level": 1,
          "text": "This document is Arcfield's Incident Response Procedure. Define the response flow, escalation logic, roles and outputs for security incidents. It is not the policy that sets the rule or the register that stores the live rows. This procedure applies to the Arcfield Platform (B2B SaaS for regulated fintech and health customers): production, customer data, CI/CD, privileged access and critical suppliers. Neighbouring records (IRRT, SIR, CAR) cite this Document Control version. Do not copy these paragraphs into them."
        },
        {
          "id": "scope",
          "heading": "Scope",
          "level": 1,
          "text": "Use this table before you copy a rule into another record or exclude a duty from this file.",
          "rows": [
            {
              "In this procedure": "The rules, roles, worked Arcfield example and the records this file owns.",
              "Not in this procedure": "The ISMS boundary (ISS), Annex A selection (SoA) or live rows in IRRT, SIR, CAR.",
              "Evidence reference": "IRPROC-EV-2026-Q3",
              "Evidence status": "Complete"
            },
            {
              "In this procedure": "Interfaces that must cite this Document Control version, including CI/CD, identity and suppliers where they affect CIA.",
              "Not in this procedure": "Live ISS scope rows, SoA applicability decisions, or neighbouring live registers. Those files keep their own approved versions; this file does not duplicate them.",
              "Evidence reference": "IRPROC-EV-2026-Q3",
              "Evidence status": "Complete"
            }
          ]
        },
        {
          "id": "terms",
          "heading": "Terms used here",
          "level": 1,
          "text": "These terms are local to this file. Expand every acronym on first use in the body.",
          "rows": [
            {
              "Term": "Owner",
              "Meaning": "The named role that can be called in an audit for an outcome. A team name is not an owner."
            },
            {
              "Term": "Exception",
              "Meaning": "A time-bound, approved departure with expiry and a compensating control."
            },
            {
              "Term": "CIA",
              "Meaning": "Confidentiality, Integrity and Availability of in-scope information and services."
            },
            {
              "Term": "Document Control version",
              "Meaning": "The approved version cited from neighbouring records. Do not copy this body into those records."
            }
          ]
        },
        {
          "id": "workflow_steps",
          "heading": "Workflow steps",
          "level": 1,
          "text": "Use this table for workflow steps in the Arcfield Platform ISMS. Step ID Trigger Activity Responsible Role Input Output Evidence Reference Status IRPROC-STEP-001 Security alert or user report received Detect, report and log the event. Reporter or Security Analyst Alert, user report or supplier notice Initial event record SIR-2026-0829-003 Complete IRPROC-STEP-002 Event record created Triage severity, scope, affected assets and immediate risk. Incident Manager Initial event record and affected service data Incident classification IRRT-TRIAGE-2026-0829-003 Complete IRPROC-STEP-003 Incident classified as security incident Assign incident owner and activate response channel. Incident Manager Classification result Assigned response team ICL-2026-Q3 Complete IRPROC-STEP-004 Immediate risk confirmed Contain affected account, endpoint, service or supplier route. Security Lead Triage data and runbook selection Containment action record IR-RB-PHISH-2026-0829 Complete IRPROC-STEP-005 Containment started Preserve evidence and build incident timeline. Security Analyst Logs, tickets, headers and system snapshots Evidence package SIR-EV-2026-0829-003 Complete IRPROC-STEP-006 Evidence package available Investigate root cause, impact and notification obligations. Incident Manager Evidence package and impact data Impact assessment IRRT-IMPACT-2026-0829-003 Open follow-up IRPROC-STEP-007 Recovery conditions met Recover service, validate controls and close with lessons learned. Service Owner Impact assessment and recovery plan Closure and corrective actions CAR-IR-2026-0829-003 Scheduled Cite this Document Control version from neighbouring records.",
          "rows": [
            {
              "Step ID": "IRPROC-STEP-001",
              "Trigger": "Security alert or user report received",
              "Activity": "Detect, report and log the event.",
              "Responsible Role": "Reporter or Security Analyst",
              "Input": "Alert, user report or supplier notice",
              "Output": "Initial event record",
              "Evidence Reference": "SIR-2026-0829-003",
              "Status": "Complete",
              "Evidence reference": "SIR-2026-0829-003"
            },
            {
              "Step ID": "IRPROC-STEP-002",
              "Trigger": "Event record created",
              "Activity": "Triage severity, scope, affected assets and immediate risk.",
              "Responsible Role": "Incident Manager",
              "Input": "Initial event record and affected service data",
              "Output": "Incident classification",
              "Evidence Reference": "IRRT-TRIAGE-2026-0829-003",
              "Status": "Complete",
              "Evidence reference": "IRRT-TRIAGE-2026-0829-003"
            },
            {
              "Step ID": "IRPROC-STEP-003",
              "Trigger": "Incident classified as security incident",
              "Activity": "Assign incident owner and activate response channel.",
              "Responsible Role": "Incident Manager",
              "Input": "Classification result",
              "Output": "Assigned response team",
              "Evidence Reference": "ICL-2026-Q3",
              "Status": "Complete",
              "Evidence reference": "ICL-2026-Q3"
            },
            {
              "Step ID": "IRPROC-STEP-004",
              "Trigger": "Immediate risk confirmed",
              "Activity": "Contain affected account, endpoint, service or supplier route.",
              "Responsible Role": "Security Lead",
              "Input": "Triage data and runbook selection",
              "Output": "Containment action record",
              "Evidence Reference": "IR-RB-PHISH-2026-0829",
              "Status": "Complete",
              "Evidence reference": "IR-RB-PHISH-2026-0829"
            },
            {
              "Step ID": "IRPROC-STEP-005",
              "Trigger": "Containment started",
              "Activity": "Preserve evidence and build incident timeline.",
              "Responsible Role": "Security Analyst",
              "Input": "Logs, tickets, headers and system snapshots",
              "Output": "Evidence package",
              "Evidence Reference": "SIR-EV-2026-0829-003",
              "Status": "Complete",
              "Evidence reference": "SIR-EV-2026-0829-003"
            },
            {
              "Step ID": "IRPROC-STEP-006",
              "Trigger": "Evidence package available",
              "Activity": "Investigate root cause, impact and notification obligations.",
              "Responsible Role": "Incident Manager",
              "Input": "Evidence package and impact data",
              "Output": "Impact assessment",
              "Evidence Reference": "IRRT-IMPACT-2026-0829-003",
              "Status": "Open follow-up",
              "Evidence reference": "IRRT-IMPACT-2026-0829-003"
            },
            {
              "Step ID": "IRPROC-STEP-007",
              "Trigger": "Recovery conditions met",
              "Activity": "Recover service, validate controls and close with lessons learned.",
              "Responsible Role": "Service Owner",
              "Input": "Impact assessment and recovery plan",
              "Output": "Closure and corrective actions",
              "Evidence Reference": "CAR-IR-2026-0829-003",
              "Status": "Scheduled",
              "Evidence reference": "CAR-IR-2026-0829-003"
            }
          ]
        },
        {
          "id": "roles_and_responsibilities",
          "heading": "Roles and responsibilities",
          "level": 1,
          "text": "Use this table for roles and responsibilities in the Arcfield Platform ISMS. Role Responsibility Incident Manager Coordinates response, classification, escalation, closure and lessons learned. Security Lead Leads containment, eradication and security decisions. Security Analyst Collects evidence, timeline and technical analysis. Service Owner Owns service recovery and operational validation. Legal or Privacy Lead Assesses notification and contractual communication obligations. Cite this Document Control version from neighbouring records.",
          "rows": [
            {
              "Role": "Incident Manager",
              "Responsibility": "Coordinates response, classification, escalation, closure and lessons learned.",
              "Evidence reference": "IRPROC-EV-2026-Q3",
              "Evidence status": "Complete"
            },
            {
              "Role": "Security Lead",
              "Responsibility": "Leads containment, eradication and security decisions.",
              "Evidence reference": "IRPROC-EV-2026-Q3",
              "Evidence status": "Complete"
            },
            {
              "Role": "Security Analyst",
              "Responsibility": "Collects evidence, timeline and technical analysis.",
              "Evidence reference": "IRPROC-EV-2026-Q3",
              "Evidence status": "Complete"
            },
            {
              "Role": "Service Owner",
              "Responsibility": "Owns service recovery and operational validation.",
              "Evidence reference": "IRPROC-EV-2026-Q3",
              "Evidence status": "Complete"
            },
            {
              "Role": "Legal or Privacy Lead",
              "Responsibility": "Assesses notification and contractual communication obligations.",
              "Evidence reference": "IRPROC-EV-2026-Q3",
              "Evidence status": "Complete"
            }
          ]
        },
        {
          "id": "review_and_decision",
          "heading": "Review and decision",
          "level": 1,
          "text": "Use this table for review and decision in the Arcfield Platform ISMS. Field Value Decision Incident workflow activated and containment completed; impact assessment and corrective action remain open. Incidents reviewed 1 Major incidents 0 Open corrective actions 1 Customer or regulator assessment No notification required based on current impact assessment. Reviewed by Incident Manager Decision date 2026-08-29 Evidence reference IRPROC-REVIEW-2026-0829-003 Cite this Document Control version from neighbouring records.",
          "rows": [
            {
              "Field": "Decision",
              "Value": "Incident workflow activated and containment completed; impact assessment and corrective action remain open.",
              "Evidence reference": "IRPROC-REVIEW-2026-0829-003",
              "Evidence status": "Complete"
            },
            {
              "Field": "Incidents reviewed",
              "Value": "1",
              "Evidence reference": "IRPROC-REVIEW-2026-0829-003",
              "Evidence status": "Complete"
            },
            {
              "Field": "Major incidents",
              "Value": "0",
              "Evidence reference": "IRPROC-REVIEW-2026-0829-003",
              "Evidence status": "Complete"
            },
            {
              "Field": "Open corrective actions",
              "Value": "1",
              "Evidence reference": "IRPROC-REVIEW-2026-0829-003",
              "Evidence status": "Complete"
            },
            {
              "Field": "Customer or regulator assessment",
              "Value": "No notification required based on current impact assessment.",
              "Evidence reference": "IRPROC-REVIEW-2026-0829-003",
              "Evidence status": "Complete"
            },
            {
              "Field": "Reviewed by",
              "Value": "Incident Manager",
              "Evidence reference": "IRPROC-REVIEW-2026-0829-003",
              "Evidence status": "Complete"
            },
            {
              "Field": "Decision date",
              "Value": "2026-08-29",
              "Evidence reference": "IRPROC-REVIEW-2026-0829-003",
              "Evidence status": "Complete"
            },
            {
              "Field": "Evidence reference",
              "Value": "IRPROC-REVIEW-2026-0829-003",
              "Evidence reference": "IRPROC-REVIEW-2026-0829-003",
              "Evidence status": "Complete"
            }
          ]
        }
      ],
      "contentType": "workflow_steps"
    },
    {
      "id": "roles_and_responsibilities",
      "title": "Roles and responsibilities",
      "groups": [
        {
          "text": "Use this table or list as the working record. Name owners, systems and evidence so a second person can apply the same rule."
        },
        {
          "rows": [
            {
              "Role": "Incident Manager",
              "Responsibility": "Coordinates response, classification, escalation, closure and lessons learned.",
              "Evidence reference": "IRPROC-EV-2026-Q3",
              "Evidence status": "Complete"
            },
            {
              "Role": "Security Lead",
              "Responsibility": "Leads containment, eradication and security decisions.",
              "Evidence reference": "IRPROC-EV-2026-Q3",
              "Evidence status": "Complete"
            },
            {
              "Role": "Security Analyst",
              "Responsibility": "Collects evidence, timeline and technical analysis.",
              "Evidence reference": "IRPROC-EV-2026-Q3",
              "Evidence status": "Complete"
            },
            {
              "Role": "Service Owner",
              "Responsibility": "Owns service recovery and operational validation.",
              "Evidence reference": "IRPROC-EV-2026-Q3",
              "Evidence status": "Complete"
            },
            {
              "Role": "Legal or Privacy Lead",
              "Responsibility": "Assesses notification and contractual communication obligations.",
              "Evidence reference": "IRPROC-EV-2026-Q3",
              "Evidence status": "Complete"
            }
          ]
        }
      ],
      "contentType": "role_table"
    },
    {
      "id": "evidence_and_records",
      "title": "Evidence and records",
      "groups": [
        {
          "text": "Related records live in the companion documents named below. This file cites them by their approved version. It does not copy their content. The Owner named on the cover is accountable for those live records."
        },
        {
          "items": [
            "[Mandatory Documents and Records Register](MDR_Mandatory_Documents_and_Records_Register.xlsx) — The 27 mandatory ISO 27001 documents and records, with owner, required status, approval, review cadence, location and evidence readiness.",
            "[Document Register](DR_Document_Register.xlsx) — Controlled documented information: origin, owner, approver, version, review cycle, retention and location.",
            "[Records Retention Schedule](RRS_Records_Retention_Schedule_Register.xlsx) — Retention rules for ISMS, security, privacy, audit and operational records, with owner, period, disposal method and evidence."
          ],
          "ordered": true,
          "relationView": "evidence"
        }
      ],
      "contentType": "evidence_table"
    },
    {
      "id": "review_and_decision",
      "title": "Review and decision",
      "values": {
        "Decision": "Incident workflow activated and containment completed; impact assessment and corrective action remain open.",
        "Incidents reviewed": 1,
        "Major incidents": 0,
        "Open corrective actions": 1,
        "Customer or regulator assessment": "No notification required based on current impact assessment.",
        "Reviewed by": "Incident Manager",
        "Decision date": "2026-08-29",
        "Evidence reference": "IRPROC-REVIEW-2026-0829-003"
      },
      "groups": [
        {},
        {
          "rows": [
            {
              "Field": "Decision",
              "Value": "Incident workflow activated and containment completed; impact assessment and corrective action remain open.",
              "Evidence reference": "IRPROC-REVIEW-2026-0829-003",
              "Evidence status": "Complete"
            },
            {
              "Field": "Incidents reviewed",
              "Value": "1",
              "Evidence reference": "IRPROC-REVIEW-2026-0829-003",
              "Evidence status": "Complete"
            },
            {
              "Field": "Major incidents",
              "Value": "0",
              "Evidence reference": "IRPROC-REVIEW-2026-0829-003",
              "Evidence status": "Complete"
            },
            {
              "Field": "Open corrective actions",
              "Value": "1",
              "Evidence reference": "IRPROC-REVIEW-2026-0829-003",
              "Evidence status": "Complete"
            },
            {
              "Field": "Customer or regulator assessment",
              "Value": "No notification required based on current impact assessment.",
              "Evidence reference": "IRPROC-REVIEW-2026-0829-003",
              "Evidence status": "Complete"
            },
            {
              "Field": "Reviewed by",
              "Value": "Incident Manager",
              "Evidence reference": "IRPROC-REVIEW-2026-0829-003",
              "Evidence status": "Complete"
            },
            {
              "Field": "Decision date",
              "Value": "2026-08-29",
              "Evidence reference": "IRPROC-REVIEW-2026-0829-003",
              "Evidence status": "Complete"
            },
            {
              "Field": "Evidence reference",
              "Value": "IRPROC-REVIEW-2026-0829-003",
              "Evidence reference": "IRPROC-REVIEW-2026-0829-003",
              "Evidence status": "Complete"
            }
          ]
        }
      ],
      "contentType": "decision_table"
    },
    {
      "id": "external_references",
      "title": "References",
      "groups": [
        {
          "id": "linked_documents",
          "heading": "Linked documents",
          "level": 1,
          "text": "These companion files sit next to this document in the unpacked package. This file cites them by their approved version. It does not copy their content.",
          "rows": [
            {
              "Kind": "Artifact",
              "Reference": "MDR Mandatory Documents and Records Register",
              "How this document uses it": "The 27 mandatory ISO 27001 documents and records, with owner, required status, approval, review cadence, location and evidence readiness.",
              "href": "MDR_Mandatory_Documents_and_Records_Register.xlsx"
            },
            {
              "Kind": "Artifact",
              "Reference": "DR Document Register",
              "How this document uses it": "Controlled documented information: origin, owner, approver, version, review cycle, retention and location.",
              "href": "DR_Document_Register.xlsx"
            },
            {
              "Kind": "Artifact",
              "Reference": "RRS Records Retention Schedule",
              "How this document uses it": "Retention rules for ISMS, security, privacy, audit and operational records, with owner, period, disposal method and evidence.",
              "href": "RRS_Records_Retention_Schedule_Register.xlsx"
            },
            {
              "Kind": "Artifact",
              "Reference": "IRRT Incident Register and Reporting Template (Secure Engineering, Incident Response & Security Monitoring)",
              "href": "IRRT_Incident_Register_and_Reporting_Template.xlsx",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record."
            },
            {
              "Kind": "Artifact",
              "Reference": "SIR Security Incident Register (Secure Engineering, Incident Response & Security Monitoring)",
              "href": "SIR_Security_Incident_Register.xlsx",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record."
            },
            {
              "Kind": "Artifact",
              "Reference": "CAR Corrective Actions Register (Building the ISMS, Context of the Organization (Clause 4))",
              "href": "CAR_Corrective_Actions_Register.xlsx",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record."
            },
            {
              "Kind": "Artifact",
              "Reference": "ICL ISMS Communication Log (Building the ISMS, Context of the Organization (Clause 4))",
              "href": "ICL_ISMS_Communication_Log.xlsx",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record."
            }
          ]
        },
        {
          "id": "external_sources",
          "heading": "External references",
          "level": 1,
          "text": "Cite these ISO clauses and book chapters from workshops and audits.",
          "rows": [
            {
              "Kind": "ISO",
              "Reference": "ISO/IEC 27001:2022",
              "How this document uses it": "Normative ISMS requirements this companion artifact supports.",
              "href": "https://www.iso.org/standard/82875.html"
            },
            {
              "Kind": "Book",
              "Reference": "Secure Engineering, Incident Response & Security Monitoring",
              "How this document uses it": "Primary operating chapter for this companion artifact.",
              "href": "https://www.amazon.com/dp/9789908983455"
            }
          ]
        }
      ],
      "contentType": "reference_table"
    }
  ],
  "enrichment": {
    "source": "Example.json",
    "method": "curated-json",
    "note": "Completes Example JSON with renderer-native sections and generalized groups; no mdSource helper fields."
  },
  "snapshotRef": {
    "snapshotId": "arcfield.platform.surv.2026-09-11",
    "schemaVersion": "evidenceSnapshot.v1"
  },
  "scenarioRef": {
    "githubIssue": 64,
    "crId": "CR-TYPE-ARCFIELD-001",
    "family": "Procedure",
    "role": "Operating method used on the 11 September 2026 freeze"
  }
}
