{
  "schemaVersion": "artifactExample.v2",
  "artifactId": "SIR",
  "title": "Security Incident Register",
  "definitionRef": {
    "artifactId": "SIR",
    "definitionSchemaVersion": "artifactDefinition.v2",
    "definitionId": "SIR.artifactDefinition.v2",
    "title": "Security Incident Register"
  },
  "organization": "Arcfield",
  "sections": [
    {
      "id": "title_page",
      "title": "Title Page",
      "values": {
        "Register Title": "Security Incident Register",
        "Register ID": "SIR-REG-001",
        "Version": "1.1",
        "Status": "Approved",
        "Organization": "Arcfield",
        "Owner": "Incident Manager",
        "Approver": "ISMS Manager",
        "Classification": "Internal",
        "Effective Date": "2026-09-11",
        "Next Review Date": "2027-09-11"
      },
      "items": [
        "Register Title: Security Incident Register",
        "Register ID: SIR-REG-001",
        "Version: 1.1",
        "Status: Approved",
        "Organization: Arcfield",
        "Owner: Incident Manager",
        "Approver: ISMS Manager",
        "Classification: Internal",
        "Effective Date: 2026-09-11",
        "Next Review Date: 2027-09-11"
      ],
      "contentType": "metadata"
    },
    {
      "id": "abstract",
      "title": "Abstract",
      "text": "This example records Arcfield security incidents from detection through triage, severity, ownership, affected system or data, containment, communication, notification, corrective action, evidence, closure and lessons learned. Rows are the 11 September 2026 operating sample of the certified Arcfield Platform ISMS in the surveillance cycle after certificate ARC-ISMS-2025-001. It cites IL-005 / INC-2026-0822 as the High event of this freeze.",
      "contentType": "narrative"
    },
    {
      "id": "document_control",
      "title": "Document Control",
      "rows": [
        {
          "Property": "Purpose",
          "Value": "Track security incidents and response evidence consistently."
        },
        {
          "Property": "Used by",
          "Value": "Incident Manager, Security Lead, IT Operations, ISMS Manager, Internal Auditor"
        },
        {
          "Property": "Maintained by",
          "Value": "Incident Manager"
        },
        {
          "Property": "Evidence role",
          "Value": "Security incident handling and corrective-action evidence"
        },
        {
          "Property": "ISO reference",
          "Value": "ISO/IEC 27001:2022 A.5.24, A.5.25, A.5.26, A.5.27 and A.5.28"
        },
        {
          "Property": "Review cadence",
          "Value": "Weekly for open incidents; monthly and after significant incidents"
        }
      ],
      "contentType": "control_table"
    },
    {
      "id": "instructions",
      "title": "Instructions",
      "items": [
        "Register each security incident or event requiring triage.",
        "Record detection source, category, severity, owner, affected system or data and impact.",
        "Preserve evidence for containment, investigation and communication.",
        "Link corrective actions where root-cause or control improvement is required.",
        "Close incidents only after evidence, lessons learned and closure decision are documented.",
        "Use sheets ending in “Ex” as read-only examples. Enter live data only on the matching “Wk” (Working) sheets.",
        "Every operative list is an Excel Table with frozen headers and filters. Add new rows on the next empty worksheet row beneath the table so Excel expands it — do not leave blank rows inside the table.",
        "Where a column offers a dropdown, choose a value from the list (Status, Owner role, Priority, Severity, Likelihood, Impact, Applicability, Evidence Status, Review Result). Do not invent free-text variants.",
        "Enter dates as YYYY-MM-DD. Date columns are validated and formatted accordingly.",
        "Review the Flag columns (Overdue, Review Due, Missing Owner, Missing Evidence). They calculate automatically and highlight gaps for follow-up.",
        "Keep Cover, Legal, Book, Lists and Metadata unchanged. System sheets are protected on purpose."
      ],
      "contentType": "ordered_list"
    },
    {
      "id": "security_incident_register",
      "title": "Security incident register",
      "schemaRef": {
        "definitionId": "SIR.artifactDefinition.v2",
        "sectionId": "security_incident_register",
        "columnsRef": "sections.security_incident_register.columns"
      },
      "rows": [
        {
          "Incident ID": "SIR-001",
          "Detected Date": "2026-08-03",
          "Detection Source": "Phishing report button",
          "Category": "Suspicious email",
          "Severity": "Low",
          "Status": "Closed",
          "Owner": "Incident Manager",
          "Affected System or Data": "Corporate email",
          "Impact Summary": "No credential submission; message removed from two mailboxes.",
          "Containment Action": "Message quarantined and sender blocked.",
          "Communication Required": "No external notification",
          "Notification Status": "Not applicable",
          "Corrective Action": "CAR-2026-021",
          "Evidence Reference": "INC-TKT-2026-0803",
          "Closure Date": "2026-08-04",
          "Lessons Learned": "Awareness reminder added to August newsletter."
        },
        {
          "Incident ID": "SIR-002",
          "Detected Date": "2026-08-07",
          "Detection Source": "EDR alert",
          "Category": "Malware detection",
          "Severity": "Medium",
          "Status": "Closed",
          "Owner": "Security Lead",
          "Affected System or Data": "Finance endpoint",
          "Impact Summary": "Malware blocked before execution; no data loss identified.",
          "Containment Action": "Device isolated, scanned and reimaged.",
          "Communication Required": "Internal owner notification",
          "Notification Status": "Completed",
          "Corrective Action": "CAR-2026-024",
          "Evidence Reference": "EDR-CASE-4481",
          "Closure Date": "2026-08-09",
          "Lessons Learned": "Extension allowlist review added."
        },
        {
          "Incident ID": "SIR-003",
          "Detected Date": "2026-08-11",
          "Detection Source": "SIEM alert",
          "Category": "Unauthorized access attempt",
          "Severity": "Medium",
          "Status": "In review",
          "Owner": "IT Operations Manager",
          "Affected System or Data": "Cloud administration portal",
          "Impact Summary": "Repeated failed login attempts against disabled account.",
          "Containment Action": "Account confirmed disabled; source IP blocked.",
          "Communication Required": "Internal security update",
          "Notification Status": "Completed",
          "Corrective Action": "ARR-003",
          "Evidence Reference": "SIEM-ALERT-2026-811",
          "Closure Date": "",
          "Lessons Learned": "Review dormant account monitoring threshold."
        },
        {
          "Incident ID": "SIR-004",
          "Detected Date": "2026-08-18",
          "Detection Source": "Supplier security advisory",
          "Category": "Supplier incident",
          "Severity": "Medium",
          "Status": "Open",
          "Owner": "Supplier Manager",
          "Affected System or Data": "CloudHost analytics service",
          "Impact Summary": "Supplier outage; no Arcfield data exposure confirmed.",
          "Containment Action": "Service dependency monitored; customer impact assessment started.",
          "Communication Required": "Customer-impact assessment",
          "Notification Status": "Drafted",
          "Corrective Action": "SINV-2026-009",
          "Evidence Reference": "SUP-ADV-2026-0818",
          "Closure Date": "",
          "Lessons Learned": "Pending supplier final report. Open supplier incident; A.5.21 remains Planned (STALL-2026-Q3)."
        },
        {
          "Incident ID": "SIR-005",
          "Detected Date": "2026-08-22",
          "Detection Source": "Change validation failure",
          "Category": "Misconfiguration",
          "Severity": "High",
          "Status": "Contained",
          "Owner": "Engineering Lead",
          "Affected System or Data": "Customer support knowledge base",
          "Impact Summary": "Internal draft articles were world-readable for 12 minutes. No confirmed Arcfield Platform customer PII exposure.",
          "Containment Action": "Permission reverted and access logs preserved.",
          "Communication Required": "Internal management briefing",
          "Notification Status": "Completed",
          "Corrective Action": "CAR-2026-027",
          "Evidence Reference": "CHG-POST-2026-0822",
          "Closure Date": "",
          "Lessons Learned": "Stage 2 had sampled change and access as Implemented. The event showed peer approval and configuration evidence were not as robust as that sample suggested. Evidence on this freeze is therefore Partial on many Implemented rows — honesty after re-sampling, not a drop in the Implemented count. CYB-CLM-2026-001 against Northbridge Cyber (worked example) was Denied: Unapproved production change (policy requires the documented change process); No evidenced first-party loss (12-minute internal drafts; no confirmed customer data) Risk treatment Transfer / insurance is not a control. A denied claim is residual risk still on Arcfield. Do not write Transfer on RISK-2026-041 as if the insurer paid."
        },
        {
          "Incident ID": "SIR-006",
          "Detected Date": "2026-08-27",
          "Detection Source": "Offboarding checklist review",
          "Category": "Access delay",
          "Severity": "Low",
          "Status": "Closed",
          "Owner": "HR Manager",
          "Affected System or Data": "Collaboration workspace",
          "Impact Summary": "Former contractor retained workspace access for six hours after end date.",
          "Containment Action": "Access removed; activity log reviewed.",
          "Communication Required": "No external notification",
          "Notification Status": "Not applicable",
          "Corrective Action": "OFC-2026-014",
          "Evidence Reference": "ACCESS-REVIEW-2026-0827",
          "Closure Date": "2026-08-28",
          "Lessons Learned": "Automated offboarding reminder added."
        }
      ],
      "contentType": "register_table"
    },
    {
      "id": "incident_review_decision",
      "title": "Incident review decision",
      "values": {
        "Review result": "Six security incidents reviewed; one high-severity incident remains contained pending corrective-action verification.",
        "Incidents reviewed": 6,
        "Open incidents": 2,
        "High or critical incidents": 1,
        "Corrective actions open": 4,
        "Reviewed by": "Incident Manager",
        "Decision date": "2026-08-29",
        "Evidence reference": "SIR-REVIEW-2026-08"
      },
      "rows": [
        {
          "Field": "Review result",
          "Value": "Six security incidents reviewed; one high-severity incident remains contained pending corrective-action verification."
        },
        {
          "Field": "Incidents reviewed",
          "Value": "6"
        },
        {
          "Field": "Open incidents",
          "Value": "2"
        },
        {
          "Field": "High or critical incidents",
          "Value": "1"
        },
        {
          "Field": "Corrective actions open",
          "Value": "4"
        },
        {
          "Field": "Reviewed by",
          "Value": "Incident Manager"
        },
        {
          "Field": "Decision date",
          "Value": "2026-08-29"
        },
        {
          "Field": "Evidence reference",
          "Value": "SIR-REVIEW-2026-08"
        }
      ],
      "contentType": "decision_table"
    },
    {
      "id": "external_references",
      "title": "References",
      "groups": [
        {
          "text": "Cite these sources from workshops and audits. This list names ISO clauses, book chapters and companion artifacts used by this file."
        },
        {
          "rows": [
            {
              "Kind": "ISO",
              "Reference": "ISO/IEC 27001:2022",
              "How this document uses it": "Normative source this artifact implements or cites.",
              "href": "https://www.iso.org/standard/82875.html"
            },
            {
              "Kind": "Book",
              "Reference": "Secure Engineering, Incident Response & Security Monitoring",
              "How this document uses it": "Primary operating chapter for this companion artifact.",
              "href": "https://www.amazon.com/dp/9789908983455"
            },
            {
              "Kind": "Artifact",
              "Reference": "CAR Corrective Actions Register (Building the ISMS, Context of the Organization (Clause 4))",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/dp/9789908983448"
            },
            {
              "Kind": "Artifact",
              "Reference": "ISO Information Security Objectives (Building the ISMS, Information Security Policies & Risk Management)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/dp/9789908983448"
            },
            {
              "Kind": "Artifact",
              "Reference": "ARR Access Rights Register (Secure Engineering, Access Control & Identity Management)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/dp/9789908983455"
            },
            {
              "Kind": "Artifact",
              "Reference": "OFC Offboarding Checklist (Building the ISMS, Context of the Organization (Clause 4))",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/dp/9789908983448"
            }
          ]
        }
      ],
      "contentType": "reference_table"
    }
  ],
  "enrichment": {
    "source": "Example.json",
    "method": "curated-json",
    "note": "Completes Example JSON with renderer-native sections and generalized groups; no mdSource helper fields."
  },
  "snapshotRef": {
    "snapshotId": "arcfield.platform.surv.2026-09-11",
    "schemaVersion": "evidenceSnapshot.v1"
  },
  "scenarioRef": {
    "githubIssue": 64,
    "crId": "CR-TYPE-ARCFIELD-001",
    "family": "Register",
    "role": "Operating sample of the 11 September 2026 freeze"
  }
}
