{
  "schemaVersion": "artifactExample.v2",
  "artifactId": "SI",
  "title": "Software Inventory",
  "definitionRef": {
    "artifactId": "SI",
    "definitionSchemaVersion": "artifactDefinition.v2",
    "definitionId": "SI.artifactDefinition.v2",
    "title": "Software Inventory"
  },
  "organization": "Arcfield",
  "sections": [
    {
      "id": "title_page",
      "title": "Title Page",
      "values": {
        "Register Title": "Software Inventory",
        "Register ID": "SI-REG-001",
        "Version": "1.1",
        "Status": "Approved",
        "Organization": "Arcfield",
        "Owner": "IT Operations Manager",
        "Approver": "ISMS Manager",
        "Classification": "Internal",
        "Effective Date": "2026-09-11",
        "Next Review Date": "2027-09-11"
      },
      "items": [
        "Register Title: Software Inventory",
        "Register ID: SI-REG-001",
        "Version: 1.1",
        "Status: Approved",
        "Organization: Arcfield",
        "Owner: IT Operations Manager",
        "Approver: ISMS Manager",
        "Classification: Internal",
        "Effective Date: 2026-09-11",
        "Next Review Date: 2027-09-11"
      ],
      "contentType": "metadata"
    },
    {
      "id": "abstract",
      "title": "Abstract",
      "text": "This example records Arcfield software assets with business purpose, owner, supplier or maintainer, deployment model, data classification, criticality, license status, update status, related process and evidence. This inventory is the in-scope Arcfield Platform set on the 11 September 2026 freeze in the surveillance cycle after certificate ARC-ISMS-2025-001.",
      "contentType": "narrative"
    },
    {
      "id": "document_control",
      "title": "Document Control",
      "rows": [
        {
          "Property": "Purpose",
          "Value": "Maintain an audit-ready software inventory."
        },
        {
          "Property": "Used by",
          "Value": "IT Operations Manager, Security Lead, Engineering Lead, Supplier Manager, Internal Auditor"
        },
        {
          "Property": "Maintained by",
          "Value": "IT Operations Manager"
        },
        {
          "Property": "Evidence role",
          "Value": "Software asset, licensing, patching and supplier evidence"
        },
        {
          "Property": "ISO reference",
          "Value": "ISO/IEC 27001:2022 A.5.9, A.5.32, A.8.8 and A.8.19"
        },
        {
          "Property": "Review cadence",
          "Value": "Quarterly and after major software, supplier or scope changes"
        }
      ],
      "contentType": "control_table"
    },
    {
      "id": "instructions",
      "title": "Instructions",
      "items": [
        "Record software that is business-critical, security-relevant or used to process in-scope information.",
        "Assign an accountable owner.",
        "Record supplier, deployment model, data classification and criticality.",
        "Track license status, version or release and patch/update status.",
        "Link supplier, access, vulnerability or license evidence.",
        "Review unsupported, unlicensed or unpatched software before management review.",
        "Use sheets ending in “Ex” as read-only examples. Enter live data only on the matching “Wk” (Working) sheets.",
        "Every operative list is an Excel Table with frozen headers and filters. Add new rows on the next empty worksheet row beneath the table so Excel expands it — do not leave blank rows inside the table.",
        "Where a column offers a dropdown, choose a value from the list (Status, Owner role, Priority, Severity, Likelihood, Impact, Applicability, Evidence Status, Review Result). Do not invent free-text variants.",
        "Enter dates as YYYY-MM-DD. Date columns are validated and formatted accordingly.",
        "Review the Flag columns (Overdue, Review Due, Missing Owner, Missing Evidence). They calculate automatically and highlight gaps for follow-up.",
        "Keep Cover, Legal, Book, Lists and Metadata unchanged. System sheets are protected on purpose."
      ],
      "contentType": "ordered_list"
    },
    {
      "id": "software_inventory",
      "title": "Software inventory",
      "schemaRef": {
        "definitionId": "SI.artifactDefinition.v2",
        "sectionId": "software_inventory",
        "columnsRef": "sections.software_inventory.columns"
      },
      "rows": [
        {
          "Software ID": "SI-001",
          "Software Name": "CloudDesk Support Platform",
          "Business Purpose": "Customer support case handling",
          "Owner": "Support Operations Manager",
          "Supplier or Maintainer": "CloudDesk Inc.",
          "Deployment Model": "SaaS",
          "Data Classification": "Confidential customer support data",
          "Criticality": "High",
          "License Status": "Active subscription",
          "Version or Release": "SaaS current",
          "Patch or Update Status": "Supplier-managed",
          "Related Asset or Process": "Customer support operations",
          "Evidence Reference": "SINV-CLOUDDESK-2026-Q3",
          "Status": "Active",
          "Notes": "In ISMS scope after support scope extension."
        },
        {
          "Software ID": "SI-002",
          "Software Name": "Arcfield Identity Provider",
          "Business Purpose": "Authentication and access management",
          "Owner": "IT Operations Manager",
          "Supplier or Maintainer": "Internal IT / SaaS provider",
          "Deployment Model": "SaaS",
          "Data Classification": "Identity and access data",
          "Criticality": "High",
          "License Status": "Active subscription",
          "Version or Release": "SaaS current",
          "Patch or Update Status": "Supplier-managed; configuration reviewed monthly",
          "Related Asset or Process": "Access control",
          "Evidence Reference": "ARR-2026-08",
          "Status": "Active",
          "Notes": "Privileged access review pending for one cloud admin group."
        },
        {
          "Software ID": "SI-003",
          "Software Name": "SecureBuild CI/CD",
          "Business Purpose": "Software build and deployment pipeline",
          "Owner": "Engineering Lead",
          "Supplier or Maintainer": "Engineering Platform Team",
          "Deployment Model": "SaaS with managed runners",
          "Data Classification": "Source code and deployment metadata",
          "Criticality": "High",
          "License Status": "Active subscription",
          "Version or Release": "2026.08",
          "Patch or Update Status": "Current",
          "Related Asset or Process": "Secure development",
          "Evidence Reference": "CIL-2026-Q3",
          "Status": "Active",
          "Notes": "Privacy checkpoint added for production-like data workflows."
        },
        {
          "Software ID": "SI-004",
          "Software Name": "Endpoint Protection Suite",
          "Business Purpose": "Endpoint malware detection and response",
          "Owner": "Security Lead",
          "Supplier or Maintainer": "Security vendor",
          "Deployment Model": "Endpoint agent and SaaS console",
          "Data Classification": "Endpoint telemetry",
          "Criticality": "High",
          "License Status": "Active subscription",
          "Version or Release": "Agent 8.12",
          "Patch or Update Status": "Current except one finance laptop reimaged",
          "Related Asset or Process": "Malware protection and monitoring",
          "Evidence Reference": "EDR-CASE-4481",
          "Status": "Active",
          "Notes": "Linked to IL-002."
        },
        {
          "Software ID": "SI-005",
          "Software Name": "EvidenceHub",
          "Business Purpose": "Audit evidence collection and indexing",
          "Owner": "Internal Auditor",
          "Supplier or Maintainer": "Compliance tooling provider",
          "Deployment Model": "SaaS",
          "Data Classification": "Internal audit evidence",
          "Criticality": "Medium",
          "License Status": "Pilot approved",
          "Version or Release": "Pilot tenant",
          "Patch or Update Status": "Supplier-managed",
          "Related Asset or Process": "Evidence log and audit pack",
          "Evidence Reference": "ELAI-AUTO-2026-PILOT",
          "Status": "Pilot",
          "Notes": "Effectiveness review after first access-review cycle."
        },
        {
          "Software ID": "SI-006",
          "Software Name": "Open Source Analytics Library",
          "Business Purpose": "Internal service usage analytics",
          "Owner": "Engineering Lead",
          "Supplier or Maintainer": "Open-source community",
          "Deployment Model": "Embedded library",
          "Data Classification": "Aggregated usage metrics",
          "Criticality": "Medium",
          "License Status": "Permissive license reviewed",
          "Version or Release": "4.8.1",
          "Patch or Update Status": "Update scheduled to 4.9.0",
          "Related Asset or Process": "Analytics service",
          "Evidence Reference": "SI-OSS-2026-Q3",
          "Status": "Update planned",
          "Notes": "License evidence retained in LRR-004."
        }
      ],
      "contentType": "register_table"
    },
    {
      "id": "software_inventory_review",
      "title": "Software inventory review",
      "values": {
        "Review result": "Software inventory reviewed; one library update and one privileged access follow-up remain open.",
        "Software items reviewed": 6,
        "Critical items": 4,
        "Items needing update": 1,
        "License issues": 0,
        "Reviewed by": "IT Operations Manager",
        "Decision date": "2026-08-29",
        "Evidence reference": "SI-REVIEW-2026-Q3"
      },
      "rows": [
        {
          "Field": "Review result",
          "Value": "Software inventory reviewed; one library update and one privileged access follow-up remain open."
        },
        {
          "Field": "Software items reviewed",
          "Value": "6"
        },
        {
          "Field": "Critical items",
          "Value": "4"
        },
        {
          "Field": "Items needing update",
          "Value": "1"
        },
        {
          "Field": "License issues",
          "Value": "0"
        },
        {
          "Field": "Reviewed by",
          "Value": "IT Operations Manager"
        },
        {
          "Field": "Decision date",
          "Value": "2026-08-29"
        },
        {
          "Field": "Evidence reference",
          "Value": "SI-REVIEW-2026-Q3"
        }
      ],
      "contentType": "decision_table"
    },
    {
      "id": "external_references",
      "title": "References",
      "groups": [
        {
          "text": "Cite these sources from workshops and audits. This list names ISO clauses, book chapters and companion artifacts used by this file."
        },
        {
          "rows": [
            {
              "Kind": "ISO",
              "Reference": "ISO/IEC 27001:2022",
              "How this document uses it": "Normative source this artifact implements or cites.",
              "href": "https://www.iso.org/standard/82875.html"
            },
            {
              "Kind": "Book",
              "Reference": "Secure Engineering, Data Lifecycle & Classification",
              "How this document uses it": "Primary operating chapter for this companion artifact.",
              "href": "https://www.amazon.com/dp/9789908983455"
            },
            {
              "Kind": "Artifact",
              "Reference": "ISO Information Security Objectives (Building the ISMS, Information Security Policies & Risk Management)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/dp/9789908983448"
            },
            {
              "Kind": "Artifact",
              "Reference": "ARR Access Rights Register (Secure Engineering, Access Control & Identity Management)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/dp/9789908983455"
            },
            {
              "Kind": "Artifact",
              "Reference": "CIL Continual Improvement Log (Building the ISMS, Continual Improvement (Clause 10))",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/dp/9789908983448"
            },
            {
              "Kind": "Artifact",
              "Reference": "ELAI Evidence Log / Audit Pack Index (Implementation & Certification, Audit Process)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/s?k=ISO+27001+for+Software+Companies+Implementation+and+Certification"
            }
          ]
        }
      ],
      "contentType": "reference_table"
    }
  ],
  "enrichment": {
    "source": "Example.json",
    "method": "curated-json",
    "note": "Completes Example JSON with renderer-native sections and generalized groups; no mdSource helper fields."
  },
  "snapshotRef": {
    "snapshotId": "arcfield.platform.surv.2026-09-11",
    "schemaVersion": "evidenceSnapshot.v1"
  },
  "scenarioRef": {
    "githubIssue": 64,
    "crId": "CR-TYPE-ARCFIELD-001",
    "family": "Inventory",
    "role": "In-scope Arcfield Platform inventory on the freeze"
  }
}
