{
  "schemaVersion": "artifactDefinition.v2",
  "definitionId": "SI.artifactDefinition.v2",
  "artifactId": "SI",
  "title": "Software Inventory",
  "artifactType": "Inventory",
  "format": "xlsx",
  "productTier": "Premium",
  "definitionRole": "contract",
  "sourceModel": {
    "body": "canonical human-readable register maintained in the Artifact Candidate page",
    "jsonDefinition": "machine-readable contract and validation model",
    "jsonExample": "curated realistic example data fixture"
  },
  "purpose": "Define the required structure for maintaining a software inventory with ownership, business purpose, licensing, data classification, supplier, update status, risk relevance and evidence.",
  "sections": [
    {
      "order": 1,
      "id": "title_page",
      "title": "Title Page",
      "contentType": "metadata",
      "required": true,
      "hint": null
    },
    {
      "order": 2,
      "id": "abstract",
      "title": "Abstract",
      "contentType": "narrative",
      "required": true,
      "hint": {
        "text": "Use SI to keep software assets visible, owned, licensed, patched and linked to risk and supplier evidence.",
        "bookReference": "Volume 3, S-05-01-00 Data Lifecycle & Classification"
      }
    },
    {
      "order": 3,
      "id": "document_control",
      "title": "Document Control",
      "contentType": "control_table",
      "required": true,
      "hint": null
    },
    {
      "order": 4,
      "id": "instructions",
      "title": "Instructions",
      "contentType": "ordered_list",
      "required": true,
      "hint": {
        "text": "Record business-critical and security-relevant software with enough detail to support licensing, patching, risk and supplier review.",
        "bookReference": "Volume 3, S-05-01-00 Data Lifecycle & Classification"
      },
      "intro": "Complete the Working sheets using the example tabs as a model. Follow the workbook usage rules below."
    },
    {
      "order": 5,
      "id": "software_inventory",
      "title": "Software inventory",
      "contentType": "register_table",
      "required": true,
      "minimumExampleRows": 6,
      "columns": [
        {
          "name": "Software ID",
          "type": "text",
          "required": "yes",
          "description": "Unique software identifier.",
          "example": "SI-001"
        },
        {
          "name": "Software Name",
          "type": "text",
          "required": "yes",
          "description": "Software, SaaS or library name.",
          "example": "CloudDesk"
        },
        {
          "name": "Business Purpose",
          "type": "text",
          "required": "yes",
          "description": "Why the software is used.",
          "example": "Support case handling"
        },
        {
          "name": "Owner",
          "type": "select",
          "required": "yes",
          "description": "Accountable owner.",
          "example": "IT Operations Manager",
          "valueSet": "domain.owner",
          "options": [
            "ISMS Manager",
            "Control Owner",
            "Risk Owner",
            "Process Owner",
            "Asset Owner",
            "IT Security",
            "HR",
            "Legal",
            "Executive Management",
            "Internal Audit"
          ],
          "validation": {
            "allowBlank": false,
            "errorTitle": "Invalid value",
            "error": "Select a value from the list."
          }
        },
        {
          "name": "Supplier or Maintainer",
          "type": "text",
          "required": "yes",
          "description": "Supplier or maintainer.",
          "example": "SaaS provider"
        },
        {
          "name": "Deployment Model",
          "type": "select",
          "required": "yes",
          "description": "SaaS, endpoint, embedded library or managed platform.",
          "example": "SaaS"
        },
        {
          "name": "Data Classification",
          "type": "text",
          "required": "yes",
          "description": "Data handled by the software.",
          "example": "Confidential"
        },
        {
          "name": "Criticality",
          "type": "select",
          "required": "yes",
          "description": "Criticality rating.",
          "example": "High"
        },
        {
          "name": "License Status",
          "type": "text",
          "required": "yes",
          "description": "Licensing status.",
          "example": "Active subscription"
        },
        {
          "name": "Version or Release",
          "type": "text",
          "required": "yes",
          "description": "Current version or release.",
          "example": "2026.08"
        },
        {
          "name": "Patch or Update Status",
          "type": "text",
          "required": "yes",
          "description": "Patch or update status.",
          "example": "Current"
        },
        {
          "name": "Related Asset or Process",
          "type": "text",
          "required": "yes",
          "description": "Linked asset or process.",
          "example": "Access control"
        },
        {
          "name": "Evidence Reference",
          "type": "text",
          "required": "yes",
          "description": "Evidence record.",
          "example": "SI-REVIEW-2026-Q3"
        },
        {
          "name": "Status",
          "type": "select",
          "required": "yes",
          "description": "Active, pilot, update planned or retired.",
          "example": "Active",
          "valueSet": "domain.status.generic",
          "options": [
            "Draft",
            "In Progress",
            "Under Review",
            "Approved",
            "Closed",
            "Deferred"
          ],
          "validation": {
            "allowBlank": false,
            "errorTitle": "Invalid value",
            "error": "Select a value from the list."
          }
        },
        {
          "name": "Notes",
          "type": "text",
          "required": "no",
          "description": "Additional context.",
          "example": "Privileged access review pending."
        }
      ],
      "hint": {
        "text": "Each row should show what software is used, why, who owns it, how it is maintained and what evidence supports control operation.",
        "bookReference": "Volume 3, S-05-01-00 Data Lifecycle & Classification"
      }
    },
    {
      "order": 6,
      "id": "software_inventory_review",
      "title": "Software inventory review",
      "contentType": "decision_table",
      "required": true,
      "fields": [
        {
          "name": "Review result",
          "type": "select",
          "required": "yes",
          "valueSet": "domain.reviewResult",
          "options": [
            "Pass",
            "Pass with observations",
            "Fail",
            "Deferred"
          ],
          "validation": {
            "allowBlank": false,
            "errorTitle": "Invalid value",
            "error": "Select a value from the list."
          }
        },
        {
          "name": "Software items reviewed",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Critical items",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Items needing update",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "License issues",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Reviewed by",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Decision date",
          "type": "date",
          "required": "yes"
        },
        {
          "name": "Evidence reference",
          "type": "text",
          "required": "yes"
        }
      ],
      "hint": {
        "text": "Close with a review decision so unsupported, unlicensed or unpatched software becomes visible before audit.",
        "bookReference": "Volume 3, S-05-01-00 Data Lifecycle & Classification"
      }
    },
    {
      "order": 7,
      "id": "external_references",
      "title": "References",
      "contentType": "reference_table",
      "required": true
    }
  ],
  "validationRules": [
    "JSON Example must contain definitionRef pointing to SI.artifactDefinition.v2.",
    "JSON Example register sections must contain schemaRef pointing to the matching definition section.",
    "Rows must include software name, business purpose, owner, supplier or maintainer, deployment model, criticality, license status, patch status and evidence reference.",
    "Body must render the contract schema and the example data.",
    "No standalone Book reference section and no generic Sample placeholders are allowed."
  ],
  "enrichment": {
    "source": "Contract.json",
    "method": "curated-json",
    "note": "Completes Contract JSON from MD-only schema/sections, removes duplicate alias sections, and normalizes string columns into structured column objects."
  },
  "editorialStandard": {
    "isoAnchors": [
      {
        "label": "ISO/IEC 27001:2022",
        "href": "https://www.iso.org/standard/82875.html",
        "role": "Normative source this artifact implements or cites."
      },
      {
        "label": "ISO/IEC 27001:2022 8.1",
        "href": "https://www.iso.org/standard/82875.html",
        "role": "Operational planning and control this register evidences."
      },
      {
        "label": "ISO/IEC 27001:2022 7.5",
        "href": "https://www.iso.org/standard/82875.html",
        "role": "Documented information: identify, review and cite this workbook by version."
      }
    ],
    "bookSources": [
      {
        "series": "ISO 27001 for Software Companies",
        "volume": 3,
        "volumeTitle": "Secure Engineering",
        "chapterId": "S-05-01-00",
        "chapterTitle": "Data Lifecycle & Classification",
        "primary": true,
        "role": "Primary operating chapter for this companion artifact.",
        "href": "https://www.amazon.com/dp/9789908983455"
      },
      {
        "series": "ISO 27001 for Software Companies",
        "volume": 1,
        "volumeTitle": "Building the ISMS",
        "chapterId": "S-00-03-00",
        "chapterTitle": "Planning, Risk & Objectives (Clause 6)",
        "primary": false,
        "role": "Documented information, review and version discipline.",
        "href": "https://www.amazon.com/dp/9789908983448"
      }
    ],
    "acronyms": [
      {
        "abbr": "ISMS",
        "longForm": "Information Security Management System"
      },
      {
        "abbr": "SaaS",
        "longForm": "Software as a Service"
      },
      {
        "abbr": "CIA",
        "longForm": "Confidentiality, Integrity, and Availability"
      },
      {
        "abbr": "CI/CD",
        "longForm": "Continuous Integration / Continuous Delivery"
      },
      {
        "abbr": "CI",
        "longForm": "Continuous Integration"
      },
      {
        "abbr": "CD",
        "longForm": "Continuous Delivery"
      },
      {
        "abbr": "EDR",
        "longForm": "Endpoint Detection and Response"
      },
      {
        "abbr": "IL",
        "longForm": "Impact Level"
      },
      {
        "abbr": "JSON",
        "longForm": "JavaScript Object Notation"
      }
    ],
    "must": [
      "Keep one live row per record on Working sheets. Do not merge several cases into one row.",
      "Example sheets must contain realistic Arcfield rows for every required sheet. Empty required cells are not an example."
    ],
    "mustNot": [
      "Do not invent live rows in the renderer. Example data lives in the Example JSON.",
      "Do not treat Ex example tabs as working sheets. Do not put live data on system sheets."
    ],
    "softwareCompanyAdaptations": [
      "Use Arcfield as the worked example (cover variant A).",
      "Name SaaS, CI/CD, privileged access or supplier interfaces in example rows where they affect this register."
    ],
    "exampleWorkbook": {
      "workedExampleOrg": "Arcfield",
      "requiredSheets": [
        "software_inventory",
        "software_inventory_review"
      ],
      "minExampleRows": 6,
      "coverFromExample": true
    }
  },
  "editorialContractId": "editorial.xlsx.register.v1",
  "contentContractId": "content.register.inventory.v1"
}
