Use the synthetic Northbridge packet and your prior A18 artifacts. Your goal is to create a coherent professional portfolio, not reproduce every sentence from earlier lessons. Preserve detailed evidence where it supports traceability, summarize repeated material intelligently, and keep unresolved questions visible.
1Write a one-paragraph case scope that names the fictional services, identity, detection, change, time window, business boundary, and safety boundary.
2Create an evidence inventory that identifies source, freshness, provenance, time characteristics, owner, and whether each source is direct, derived, delayed, contradictory, or incomplete.
3Summarize the A18.1 multi-source investigation with the strongest current hypotheses, contradictions, confidence, and bounded conclusion.
4Add the A18.2 architecture review and identify trust boundaries, monitoring dependencies, degraded modes, resilience concerns, owners, and validation needs.
5Add the A18.3 cloud review while separating configuration state, governance evidence, classification freshness, logging, backup, recovery validation, and exceptions.
6Add the A18.4 identity decision pack with current justification, ownership, permission scope, review freshness, exceptions, service-identity lifecycle, and final access decisions.
7Preserve the A18.5 tabletop decision chronology, including what was known at each decision point, authority, reassessment triggers, impact statements, and recovery criteria.
8Add the A18.6 detection recommendation with baseline metrics, noise sources, analyst usefulness, reopen rate, safer tuning categories, monitoring window, and rollback criteria.
9Add the A18.7 risk register and ensure each material risk has a complete statement, control-effectiveness analysis, residual risk, treatment, owner, due date, review trigger, and validation evidence.
10Add the A18.8 normalized timeline, anchor events, contradictions, delayed records, clock uncertainty, evidence gaps, confidence labels, hypotheses, and bounded narrative.
11Add the A18.9 Executive Security Summary as the leadership-facing entry point while keeping the detailed evidence available in the supporting sections.
12Create a cross-case findings section that combines evidence only where multiple artifacts genuinely converge.
13Create a priority-decision section that records recommendation, evidence, authority or owner, decision, rationale, and reassessment trigger.
14Create a phased improvement roadmap that establishes baselines first, improves defensive controls and governance second, then measures outcomes and residual risk.
15Write a leadership decision summary that clearly states what requires sponsorship now, what remains owned operational work, and what conditions would trigger escalation.
16Finish with a lessons-learned section explaining how the case changed from initial alert interpretation to the final bounded conclusion without rewriting earlier evidence.
17Run a final terminology check for facts, hypotheses, assumptions, findings, issues, risks, incidents, exceptions, recommendations, decisions, and unresolved questions.
18Run a final safety check confirming the casebook contains no real access instructions, credentials, scanning, exploitation, bypass, evasion, containment execution, or private data.
Lab safety boundary
This capstone is analysis and documentation practice using synthetic evidence only. Do not acquire evidence from real devices, access real accounts, use credentials, inspect real cloud consoles, scan or probe systems, extract private information, bypass controls, modify endpoints, change network or cloud settings, disable detections, or execute real containment. Incident-response actions remain tabletop and conceptual.