By the end of A7, you will have one connected fictional package showing how a professional response moves from preparation and activation to evidence, scope, containment, communication, preservation, recovery, closure, review, metrics, and continuous improvement.
Artifact 1
Fictional incident response mission, scope, safety, authority, privacy, continuity, supplier, communication, evidence, recovery, and lifecycle charter
Artifact 2
Incident lead, technical lead, identity, service, evidence, communications, privacy, legal, continuity, recovery, supplier, and leadership role matrix
Artifact 3
Primary and alternate owner register with availability, authority, response expectations, decision rights, escalation, and handoff acceptance
Artifact 4
Versioned incident response plan, scenario playbooks, activation criteria, source-health requirements, containment options, communication approvals, recovery gates, and closure standards
Artifact 5
Fictional incident activation record, initial facts, primary questions, severity, confidence, priority, owner assignments, deadlines, and non-proof statements
Artifact 6
Evidence-based scope workbook with affected, possibly affected, unaffected, unknown, excluded, out-of-scope, and source-limited categories
Artifact 7
Chronology showing event time, collection time, processing time, report time, decision time, action time, validation time, communication time, recovery time, and closure time
Artifact 8
Containment decision matrix covering risk reduction, continuity, evidence, privacy, authority, operational cost, dependencies, validation, rollback, and residual risk
Artifact 9
Eradication and recovery plan with root-cause requirements, clean-state criteria, identity, configuration, data, dependencies, backups, staged restoration, monitoring, and owner acceptance
Artifact 10
Stakeholder communication matrix and template library for analysts, owners, users, suppliers, privacy, legal, leadership, recovery, and public-safe summaries
Artifact 11
Evidence preservation register with identity, source, provenance, purpose, timing, handler, integrity, access, custody, storage, retention, transfer, limitations, and disposal
Artifact 12
Case-management package containing notes, evidence references, hypotheses, decisions, actions, validation, state transitions, residual uncertainty, residual risk, closure, and reopening
Artifact 13
Post-incident review with facts, chronology, decisions, contributing conditions, strengths, gaps, root causes, lessons, corrective actions, owners, dependencies, and validation
Artifact 14
Incident response dashboard and metric dictionary covering readiness, activation, detection, scoping, owner delay, containment, continuity, communication, evidence, recovery, closure, reopening, privacy, and debt
Artifact 15
Corrective-action register with priority, mission effect, owner, due date, evidence, dependency, validation, aging, escalation, residual risk, and closure criteria
Artifact 16
Complete fictional Incident Response Simulation Package, leadership brief, technical appendix, tabletop record, public-safe portfolio summary, and reflection