R — Responsibility
Define the fictional mission, tasks, questions, evidence, outputs, dependencies, and lifecycle responsibilities of each role.
Learn how fictional incident response teams establish command, technical analysis, identity, service, infrastructure, evidence, communication, privacy, continuity, recovery, supplier, and leadership responsibilities before time pressure begins.
Lesson Progress
High School Advanced • A7: Incident Response Lifecycle • Lesson 1 of 10
Readiness Check
0/6 ready
Professional Hook
A fictional alert affects a critical student-support service. The technical lead tells infrastructure to isolate the service. The service owner tells staff to keep it online. The identity owner revokes an account without telling the incident lead. A communications coordinator tells users that the issue is resolved before recovery validation finishes. Every person is trying to help, yet the response becomes less safe because authority, coordination, evidence, continuity, and communication were never clearly assigned.
Weak structure
“Everyone respond quickly and do what seems necessary.”
Strong structure
“One incident lead coordinates. Specialists answer bounded questions. Authorized owners approve actions. Independent roles validate outcomes. Communications use the current decision record.”
Exactly Five Learning Objectives
Objective 1
Distinguish fictional incident command, technical analysis, identity, service, infrastructure, evidence, communications, privacy, continuity, recovery, supplier, and leadership responsibilities.
Objective 2
Create fictional role charters with mission, authority, decision rights, boundaries, required evidence, alternates, availability, escalation paths, and handoff acceptance.
Objective 3
Evaluate fictional role conflicts, unavailable owners, duplicate command, missing authority, responsibility gaps, overloaded specialists, and abandoned coordination.
Objective 4
Use fictional separation of duties so that incident declaration, containment approval, evidence handling, communication approval, recovery acceptance, residual-risk acceptance, closure, and reopening remain properly governed.
Objective 5
Create a portfolio-ready fictional Incident Response Role and Authority Package containing a role matrix, decision-rights model, alternate-owner map, handoff checklist, conflict-resolution process, escalation map, readiness metrics, and reflection.
Why This Matters
Fictional incident response includes decisions about activation, scope, containment, evidence, communication, continuity, recovery, privacy, suppliers, risk, closure, and reopening. Each decision requires the right evidence and authority. Without role design, responders may duplicate work, exceed authority, abandon questions, issue conflicting messages, damage continuity, weaken evidence, or close before validation.
One fictional incident lead preserves the complete response while specialists own bounded questions.
Each fictional decision goes to the role authorized to make it under documented conditions and limits.
High-impact fictional actions separate recommendation, approval, execution, validation, and acceptance.
Core Framework
Define the fictional mission, tasks, questions, evidence, outputs, dependencies, and lifecycle responsibilities of each role.
Assign one primary owner, an authorized alternate, availability expectations, handoff acceptance, and a coordinating incident owner.
Document fictional decision rights, authority boundaries, required independent review, privacy limits, continuity limits, and escalation triggers.
Require fictional source, provenance, timing, source health, scope, uncertainty, decisions, actions, validation, and residual risk for role decisions.
Separate high-impact duties, declare conflicts, activate alternates, preserve shift handoffs, and maintain continuity when roles change.
Decision-ready role statement
The fictional identity owner may approve a scoped role revocation after reviewing authorization, active sessions, service continuity, validation, and rollback. The incident lead coordinates the decision, and an independent owner validates the resulting identity and session state.
Advanced Vocabulary
The fictional coordinating role responsible for activation, scope, state, priorities, owner assignments, decision records, conflicts, deadlines, and overall response continuity.
The fictional role coordinating evidence review, technical questions, hypotheses, source health, containment options, validation, and technical risk communication.
The fictional role accountable for service purpose, users, dependencies, impact, continuity, recovery priorities, and business acceptance.
The fictional role accountable for accounts, roles, groups, sessions, approvals, extensions, revocations, effective access, and identity validation.
The fictional role accountable for shared compute, network, platform, hosting, storage, configuration, availability, and recovery dependencies.
The fictional role maintaining evidence identity, purpose, provenance, timing, integrity, access, custody, retention, transfer, limitations, and reporting records.
The fictional role coordinating audience, facts, uncertainty, approvals, timing, distribution, corrections, guidance, and next-update commitments.
The fictional role evaluating purpose limitation, data minimization, access, sharing, retention, user effect, and residual privacy risk.
The fictional role responsible for keeping critical mission functions operating safely through workarounds, alternate services, prioritization, and user guidance.
The fictional role coordinating clean-state criteria, staged restoration, validation, rollback, monitoring, dependencies, and recovery acceptance.
The fictional role coordinating an external provider relationship, bounded questions, contracts, service dependencies, response expectations, evidence, and escalation.
The fictional role authorized to resolve resource conflict, accept residual risk, approve major service disruption, or make decisions beyond routine operational authority.
A fictional documented authority to make a specific response decision under defined conditions and limits.
A fictional limit describing which decisions a role may make and which decisions require another owner or escalation.
A fictional document defining a role's mission, responsibilities, authority, inputs, outputs, alternates, dependencies, availability, escalation, and review.
The fictional first accountable role for a defined responsibility or decision.
The fictional approved replacement who assumes responsibility when the primary owner is unavailable or conflicted.
A fictional confirmation that the receiving role understands the question, authority, evidence, deadline, current state, dependencies, and next action.
A fictional control that prevents one role from making, executing, validating, and approving every high-impact decision without independent review.
The fictional role preserving the whole response while specialists answer bounded questions.
A fictional required task or decision with no accountable owner.
A fictional condition in which several roles issue conflicting instructions or believe they control the same decision.
A fictional situation in which one person's responsibilities, incentives, authority, evidence access, or decision interests may interfere with independent judgment.
A fictional documented response time, alternate path, and escalation trigger for a role during different urgency levels.
Fictional unresolved work caused by unclear authority, missing owners, stale contacts, unaccepted handoffs, delayed approvals, or undocumented decisions.
Instructional Section 1
Maintain one coordinated fictional response from activation through closure or reopening.
Core responsibilities
Confirm activation, preserve scope, set case state, assign owners, manage deadlines, record major decisions, resolve coordination conflicts, approve transitions within authority, and communicate current response status.
Decision rights
May activate routine incident coordination, assign work, set operational priorities, request bounded evidence, schedule updates, and escalate decisions beyond authority.
Authority boundary
Does not independently approve every technical action, privacy decision, major service interruption, public message, legal conclusion, or residual-risk acceptance.
Required inputs
Initial report, evidence summary, source health, service context, owner availability, priority, active impact, continuity needs, and playbook.
Professional outputs
Activation decision, role assignments, response state, decision log, owner deadlines, escalation path, update cadence, and closure recommendation.
Alternate requirement
Named deputy incident lead with identical documentation access and a formal transfer checklist.
Coordinate fictional technical evidence, hypotheses, source-health interpretation, and validation.
Core responsibilities
Review evidence provenance, compare alternatives, identify evidence gaps, assess technical scope, propose containment options, define validation, and explain technical uncertainty.
Decision rights
May organize technical review, assign technical questions, recommend actions, define technical tests, and mark evidence conclusions within the documented scope.
Authority boundary
Does not independently declare the incident, approve business interruption, communicate externally, accept residual risk, or close the response.
Required inputs
Logs, alerts, case notes, source-health records, system context, service dependencies, identity evidence, and owner statements.
Professional outputs
Technical assessment, hypotheses, evidence matrix, scope inputs, containment options, validation criteria, source-health limits, and recovery evidence needs.
Alternate requirement
Secondary analyst lead with access to the evidence register, current hypotheses, question log, and decision history.
Answer fictional questions about accounts, roles, groups, sessions, approvals, effective access, and identity recovery.
Core responsibilities
Validate identity state, approval scope, role assignment, group membership, session status, sponsor, owner, revocation, recovery, and post-action state.
Decision rights
May approve authorized identity actions within policy, confirm identity evidence, assign identity specialists, and validate identity recovery.
Authority boundary
Does not determine complete incident scope, service impact, communications, evidence custody, or overall closure.
Required inputs
Identity ID, role, group, session, approval, extension, sponsor, owner, source health, timing, service relationship, and response question.
Professional outputs
Identity evidence, authorization conclusion, approved action, validation result, remaining limitations, and identity residual risk.
Alternate requirement
Named access-governance alternate with equivalent authority for emergency review.
Protect fictional service purpose, users, dependencies, continuity, impact assessment, and recovery acceptance.
Core responsibilities
Explain service function, critical users, dependencies, acceptable interruption, current impact, continuity options, recovery sequence, business validation, and owner decisions.
Decision rights
May approve service-specific continuity steps, validate service impact, accept service restoration, and recommend service containment within authority.
Authority boundary
Does not independently alter identity policy, preserve evidence, issue public communication, or accept organization-wide residual risk.
Required inputs
Service status, user reports, dependency map, identity relationships, current changes, supplier state, containment options, recovery evidence, and continuity plan.
Professional outputs
Impact statement, criticality, continuity decision, dependency list, recovery acceptance criteria, and service residual risk.
Alternate requirement
Deputy service owner or continuity owner with documented service decision authority.
Coordinate fictional shared platform, network, compute, storage, hosting, and infrastructure dependencies.
Core responsibilities
Provide platform state, configuration context, dependency evidence, infrastructure containment options, restoration support, capacity, source health, and infrastructure validation.
Decision rights
May perform approved infrastructure actions within the documented plan and validate platform restoration.
Authority boundary
Does not independently decide business continuity, identity authorization, public communication, or final incident closure.
Required inputs
Affected service, network zone, platform, configuration, hosting relationship, source health, dependencies, action request, and rollback criteria.
Professional outputs
Infrastructure evidence, approved action result, platform validation, dependency status, rollback readiness, and remaining infrastructure risk.
Alternate requirement
Secondary platform or network owner selected according to the affected infrastructure domain.
Preserve fictional evidence identity, purpose, provenance, timing, integrity, access, custody, retention, and transfer.
Core responsibilities
Assign evidence IDs, document source and handler, record purpose and scope, preserve original records conceptually, track controlled copies, maintain access history, document limitations, and support reporting.
Decision rights
May enforce evidence-register requirements, reject unscoped evidence requests, and require custody or integrity documentation.
Authority boundary
Does not independently determine technical meaning, legal outcome, incident severity, business impact, or containment.
Required inputs
Evidence request, authority, scope, source, event time, collection time, handler, integrity record, access need, retention rule, and privacy requirement.
Professional outputs
Evidence register, custody history, integrity record, access log, transfer record, limitation statement, retention decision, and public-safe summary.
Alternate requirement
Named evidence-record alternate with access to the register and custody process.
Deliver fictional audience-specific, evidence-bounded, approved, timely, and correctable messages.
Core responsibilities
Map audiences, draft updates, preserve confirmed facts and uncertainty, manage approvals, coordinate timing, track distribution, correct errors, and record next-update commitments.
Decision rights
May coordinate internal update timing and approved templates; may not publish beyond assigned authority.
Authority boundary
Does not invent technical conclusions, assign blame, disclose unnecessary details, or independently approve legal, privacy, or public statements.
Required inputs
Confirmed facts, supported conclusions, uncertainty, current impact, owner decisions, approved actions, audience needs, privacy constraints, and next milestone.
Professional outputs
Analyst update, service-owner update, user guidance, supplier message, leadership brief, correction notice, distribution log, and next-update schedule.
Alternate requirement
Deputy communications coordinator with template and approval-chain access.
Ensure fictional response evidence, actions, communications, sharing, and retention remain purpose-limited and appropriately governed.
Core responsibilities
Review minimization, access, sharing, retention, user effect, evidence purpose, communication content, supplier exchange, correction, and residual privacy risk.
Decision rights
May require privacy review, restrict unnecessary fields, request narrower sharing, and escalate decisions beyond routine authority.
Authority boundary
Does not replace technical analysis, incident command, service recovery, or leadership risk acceptance.
Required inputs
Data categories, purpose, affected users, evidence request, audience, sharing plan, access model, retention, supplier relationship, and legal or policy trigger.
Professional outputs
Privacy decision, minimization requirement, sharing boundary, retention instruction, approval condition, user-impact guidance, and residual privacy risk.
Alternate requirement
Named governance alternate with equivalent review authority.
Maintain fictional critical mission functions while incident response and recovery work continue.
Core responsibilities
Identify essential workflows, acceptable interruption, alternate processes, user priorities, dependency constraints, temporary guidance, capacity, and continuity risks.
Decision rights
May activate approved continuity options and prioritize critical workflows within documented authority.
Authority boundary
Does not independently approve technical containment, evidence handling, identity actions, or organization-wide risk acceptance.
Required inputs
Service impact, user needs, dependency status, containment options, expected duration, capacity, supplier state, and recovery plan.
Professional outputs
Continuity decision, alternate workflow, user priority, operational limitation, service expectation, and transition-back criteria.
Alternate requirement
Service deputy or operations continuity alternate.
Coordinate fictional eradication, clean-state criteria, staged restoration, validation, rollback, monitoring, and acceptance.
Core responsibilities
Translate root-cause evidence into approved recovery tasks, sequence dependencies, define clean state, manage staged restoration, monitor validation, maintain rollback, and coordinate owner acceptance.
Decision rights
May direct approved recovery sequence and pause restoration when quality gates fail.
Authority boundary
Does not independently accept business impact, close the response, approve public messaging, or override evidence and privacy requirements.
Required inputs
Root-cause evidence, containment state, service dependencies, identity state, configuration, data integrity, backup status, supplier readiness, validation criteria, and rollback.
Professional outputs
Recovery plan, clean-state checklist, staged rollout, validation results, rollback decision, monitoring period, acceptance record, and residual risk.
Alternate requirement
Deputy recovery coordinator with authority to pause or roll back within the approved plan.
Coordinate fictional external-provider dependencies, bounded requests, response expectations, evidence exchange, service commitments, and escalation.
Core responsibilities
Confirm supplier contact, contract expectations, affected service, evidence needs, update cadence, dependency state, confidentiality, action ownership, and escalation.
Decision rights
May communicate approved bounded requests and activate documented supplier escalation paths.
Authority boundary
Does not disclose unrestricted internal details, accept supplier conclusions without review, or transfer incident command.
Required inputs
Supplier relationship, service dependency, contract expectation, evidence question, source health, timing, confidentiality boundary, and owner deadline.
Professional outputs
Supplier request, response record, dependency assessment, commitment, escalation, limitation, and supplier residual risk.
Alternate requirement
Named contract or service relationship alternate.
Resolve fictional high-impact resource, continuity, policy, risk, or authority decisions beyond operational roles.
Core responsibilities
Review bounded decision options, mission impact, evidence, uncertainty, continuity, privacy, resources, recovery, residual risk, and owner recommendations.
Decision rights
May approve major service interruption, resource redirection, exceptional continuity choices, organization-level risk acceptance, and decisions defined by governance.
Authority boundary
Does not replace technical evidence review, evidence custody, service validation, or detailed incident coordination.
Required inputs
Decision statement, options, evidence, limitations, active impact, urgency, mission tradeoffs, owner recommendations, privacy, cost, and residual risk.
Professional outputs
Leadership decision, authority record, selected option, conditions, owner assignments, review trigger, and risk acceptance or rejection.
Alternate requirement
Named executive or governance alternate with equivalent delegated authority.
Instructional Section 2
Primary decision owner
Incident lead
Required fictional input
Neutral observation, initial evidence, source health, mission relevance, urgency, owner availability, and activation criteria.
Independent review
Technical analysis lead or appropriate service owner may challenge the activation basis.
Escalation condition
Leadership only when activation creates major policy, resource, or service consequences beyond routine authority.
Primary decision owner
Incident lead with technical analysis lead
Required fictional input
Potential consequence, evidence certainty, active effect, scope, source health, timing, recoverability, and mission context.
Independent review
Service, identity, privacy, or source owners review their affected dimensions.
Escalation condition
Escalate when ratings drive exceptional service interruption, policy exception, or leadership decision.
Primary decision owner
Identity and access owner
Required fictional input
Identity state, role, group, session, authorization, active effect, scope, continuity impact, validation, and rollback.
Independent review
Incident lead confirms coordination; service owner reviews continuity effect.
Escalation condition
Leadership or governance review for broad, high-impact, or policy-exception actions.
Primary decision owner
Service owner within authority
Required fictional input
Current risk, user impact, dependencies, continuity, evidence preservation, reversibility, validation, and rollback.
Independent review
Technical lead reviews effectiveness; continuity owner reviews mission effect.
Escalation condition
Leadership approval for major or prolonged service interruption.
Primary decision owner
Evidence coordinator with privacy reviewer
Required fictional input
Purpose, authority, scope, source, provenance, access need, recipient, retention, integrity, and privacy.
Independent review
Technical lead confirms relevance; incident lead confirms decision use.
Escalation condition
Governance, privacy, or legal authority when sharing or retention exceeds routine boundaries.
Primary decision owner
Communications lead within assigned audience
Required fictional input
Confirmed facts, supported conclusions, uncertainty, impact, guidance, approval chain, privacy, timing, and next update.
Independent review
Incident lead, technical lead, service owner, privacy reviewer, and leadership as required by audience.
Escalation condition
Public, legal, policy, or high-impact messages require the documented authority.
Primary decision owner
Recovery owner with service owner
Required fictional input
Root-cause evidence, clean-state criteria, dependencies, identity, configuration, data integrity, source health, validation, monitoring, and rollback.
Independent review
Technical lead validates evidence; continuity owner validates transition effect.
Escalation condition
Leadership when recovery risk, resource need, service interruption, or residual risk exceeds operational authority.
Primary decision owner
Risk or leadership decision owner
Required fictional input
Known gap, mission impact, likelihood, duration, compensating controls, owner, review date, and alternatives.
Independent review
Incident, service, technical, privacy, continuity, and recovery owners provide bounded recommendations.
Escalation condition
Escalate according to the documented risk threshold and authority level.
Primary decision owner
Incident lead within closure authority
Required fictional input
Questions resolved, source health reviewed, scope and impact documented, actions validated, recovery accepted, residual risk assigned, review obligations, and reopen triggers.
Independent review
Service, technical, identity, evidence, privacy, recovery, and risk owners confirm their criteria.
Escalation condition
Leadership or governance when unresolved risk requires exceptional acceptance.
Primary decision owner
Incident lead or documented review authority
Required fictional input
New evidence, failed validation, changed scope, repeated behavior, source recovery, or residual-risk trigger.
Independent review
Relevant technical and service owners verify the trigger and impact on the prior decision.
Escalation condition
Escalate when the reopened condition requires higher authority or broader coordination.
Instructional Section 3
Requirement
Name the fictional state, activation basis, severity, confidence, priority, active impact, and current response phase.
Failure if missing
The receiving role may act from an outdated or unsupported understanding.
Requirement
State exactly what the fictional receiving role must answer, approve, validate, communicate, or own.
Failure if missing
The recipient may review too broadly or return an unusable answer.
Requirement
Document which fictional decision rights the receiving role has and which require escalation.
Failure if missing
The role may act without authority or wait unnecessarily.
Requirement
Provide fictional evidence IDs, observations, provenance, timing, source states, limitations, and non-proof statements.
Failure if missing
The recipient may treat missing or degraded evidence as fact.
Requirement
List fictional affected, possibly affected, unknown, excluded, and out-of-scope entities, services, data, suppliers, and periods.
Failure if missing
The handoff may unintentionally broaden or narrow the response.
Requirement
Summarize fictional decisions, alternatives, owners, rationale, conditions, expirations, and review triggers.
Failure if missing
The receiving role may repeat or contradict earlier decisions.
Requirement
Separate fictional actions proposed, approved, initiated, completed, validated, failed, rolled back, and still pending.
Failure if missing
Action completion may be mistaken for successful outcome.
Requirement
Document fictional service, identity, infrastructure, evidence, supplier, user, communication, and recovery dependencies.
Failure if missing
The receiving role may cause unexpected mission or recovery effects.
Requirement
Provide fictional response deadline, time sensitivity, missed-deadline path, update cadence, and escalation trigger.
Failure if missing
Time-sensitive decisions may age without visibility.
Requirement
The fictional receiving role confirms the question, authority, evidence, deadline, dependencies, next step, and ownership.
Failure if missing
Work may be assigned but not actually owned.
Instructional Section 4
| Activity | Initiates | Validates | Approves | Why separation matters |
|---|---|---|---|---|
| Incident declaration | Incident lead | Technical or service evidence owner | Incident lead within authority or leadership for exceptional activation | Prevents one unsupported alert interpretation from becoming an unquestioned declaration. |
| High-impact containment | Technical, identity, service, or infrastructure owner | Independent technical and continuity reviewers | Authorized owner and leadership when the action exceeds routine authority | Separates recommendation, business effect, execution authority, and outcome validation. |
| Evidence preservation and access | Technical analyst or incident lead | Evidence coordinator and privacy reviewer | Evidence and governance authority according to purpose and scope | Prevents unnecessary access, uncontrolled copies, or unsupported evidence use. |
| External communication | Communications lead | Technical, service, privacy, legal, and incident owners as appropriate | Documented communication authority | Prevents speculation, conflicting facts, unnecessary disclosure, and unsupported promises. |
| Recovery acceptance | Recovery owner | Technical, identity, infrastructure, data, source, and service owners | Service owner and incident lead within authority | Prevents connectivity or availability from being mistaken for trustworthy recovery. |
| Residual-risk acceptance | Incident, service, technical, or recovery owner | Risk, privacy, continuity, and affected owners | Documented leadership or risk authority | Prevents operational teams from silently accepting risk beyond their authority. |
| Incident closure | Incident lead | Technical, service, identity, evidence, privacy, recovery, and risk owners | Incident lead or higher closure authority | Prevents closure based on alert silence, action completion, or one owner's view. |
| Post-incident action closure | Corrective-action owner | Independent quality or control owner | Program or incident improvement owner | Prevents corrective actions from closing without evidence that the intended improvement occurred. |
Instructional Section 5
Condition
Fictional review with no confirmed active impact, broad scope, urgent continuity issue, or executive decision need.
Availability expectation
Primary owner acknowledges within the documented routine window; alternate activates if missed.
Escalation
Escalate through the operational owner chain when the deadline is missed.
Documentation
Role assignment, question, deadline, acknowledgement, and next update.
Condition
Fictional active session, privileged authority, increasing impact, short response opportunity, or important source degradation.
Availability expectation
Primary owner responds within the shortened urgent window; alternate and incident lead are notified immediately.
Escalation
Activate alternate owner and specialist escalation when acknowledgement or decision is late.
Documentation
Urgency basis, missed-deadline trigger, alternate activation, and decision deadline.
Condition
Fictional critical service, broad user effect, major continuity need, privacy concern, supplier dependency, or high-impact containment decision.
Availability expectation
Incident lead, service owner, continuity owner, technical lead, and required authorities are continuously coordinated.
Escalation
Leadership and governance paths activate according to decision rights.
Documentation
Command structure, update cadence, authority, impact, options, decisions, and leadership needs.
Condition
Fictional response continues across shifts, teams, suppliers, recovery stages, or observation periods.
Availability expectation
Formal shift handoffs, deputy coverage, role rotation, fatigue controls, and current decision records are required.
Escalation
Resource, staffing, and continuity gaps go to program and leadership owners.
Documentation
Shift transfer, open questions, current state, pending actions, next milestones, and acceptance.
Instructional Section 6
Risk
The fictional coordinator may feel pressure to minimize service impact or avoid independent review.
Professional response
Use a deputy incident lead or independent service-impact reviewer while preserving the service owner's expertise.
Evidence to preserve
Conflict declaration, delegated decision rights, independent validation, and review record.
Risk
The fictional action may be approved without independent outcome review.
Professional response
Assign another qualified owner to validate expected state, side effects, rollback readiness, and residual risk.
Evidence to preserve
Proposal record, approval, independent validation, result, and exception if no alternate exists.
Risk
Different fictional audiences may receive conflicting or overstated updates.
Professional response
Incident lead identifies the current supported statement, records uncertainty, and assigns a technical decision deadline.
Evidence to preserve
Source conclusions, limitation statement, approved wording, version, and correction path.
Risk
The fictional response may accept one party's statement without reconciling evidence scope and timing.
Professional response
Record both statements, compare source authority, timing, scope, and limitations, and assign a bounded reconciliation question.
Evidence to preserve
Supplier response, local source health, affected period, service evidence, and owner decision.
Risk
A fictional decision may remain unowned while active impact or evidence loss continues.
Professional response
Use the documented authority chain, incident lead interim coordination, and leadership escalation if no authorized alternate exists.
Evidence to preserve
Availability record, contact attempts, authority map, interim owner, and escalation decision.
Risk
Fictional actions may interfere, duplicate, expand scope, damage continuity, or weaken evidence.
Professional response
Pause unapproved action, return to the incident lead, compare evidence and authority, select one coordinated plan, and document rejected alternatives.
Evidence to preserve
Proposals, owners, authority, dependencies, impact, selected option, validation, and rollback.
Risk
The fictional case may close while source recovery, validation, residual risk, or reopen criteria remain incomplete.
Professional response
Present the closure gaps, available options, risk acceptance requirement, owner recommendations, and documented review trigger.
Evidence to preserve
Closure checklist, unresolved obligations, decision authority, accepted risk, and review date.
Risk
Fictional unnecessary personal, supplier, operational, or internal response information may be exposed.
Professional response
Require purpose, recipient, minimum fields, authority, privacy review, retention, and transfer records.
Evidence to preserve
Purpose-limited request, approved subset, recipient, access, transfer, retention, and limitations.
Instructional Section 7
| Case | Type | Fictional input | Expected result | Quality protected |
|---|---|---|---|---|
| ROLE-T01 | Primary unavailable | Fictional incident lead is unavailable during a time-sensitive activation. | Named alternate accepts the role using the documented transfer checklist. | Command continuity. |
| ROLE-T02 | No alternate | Fictional service owner is unavailable and no authorized alternate exists. | Incident lead records the gap and activates the authority escalation path rather than inventing authority. | Decision legitimacy. |
| ROLE-T03 | Duplicate command | Fictional technical lead and service owner issue conflicting containment instructions. | Uncoordinated action pauses and the incident lead resolves the decision through evidence, authority, continuity, and rollback review. | Coordinated response. |
| ROLE-T04 | Unaccepted handoff | A fictional identity question is sent but the receiving owner never acknowledges it. | Ownership remains with the coordinator, aging activates, and alternate escalation begins. | No abandoned work. |
| ROLE-T05 | Authority exceeded | Fictional analyst proposes a major service interruption without approval authority. | The proposal is documented and routed to service, continuity, incident, and leadership decision owners. | Authorized action. |
| ROLE-T06 | Self-validation | The same fictional owner proposes, executes, and validates a high-impact action. | Independent validation is assigned unless an approved emergency exception is documented. | Separation of duties. |
| ROLE-T07 | Role conflict | Fictional incident lead also owns the affected service. | Conflict is declared and independent coordination or service-impact review is assigned. | Decision objectivity. |
| ROLE-T08 | Shift change | A fictional extended response moves to a new shift with open decisions and pending recovery. | Formal handoff includes state, evidence, scope, decisions, actions, deadlines, dependencies, and acceptance. | Response continuity. |
| ROLE-T09 | Broad evidence request | A fictional owner asks for the entire case to answer one service question. | Evidence coordinator supplies only purpose-limited fields after authority and privacy review. | Privacy and evidence governance. |
| ROLE-T10 | Closure pressure | Fictional leadership asks to close while source reconciliation remains incomplete. | Incident lead presents closure gaps and requires appropriate risk acceptance or continued Conditional state. | Evidence-based closure. |
| ROLE-T11 | Supplier dependency | Fictional supplier owner has no current contact or escalation path. | Dependency is marked as readiness debt and leadership receives the resulting response limitation. | External coordination. |
| ROLE-T12 | Public portfolio | Student plans to use sanitized real role charts and response contacts. | Portfolio validation fails; every organization, role, contact, authority, event, and decision must be invented. | Confidentiality and safety. |
Instructional Section 8
Review question
Do all fictional required command, technical, service, identity, evidence, communications, privacy, continuity, recovery, supplier, and leadership responsibilities have owners?
Fictional evidence
Role matrix, incident types, critical services, dependency map, and responsibility-gap register.
Limitation
Named ownership does not prove availability or decision quality.
Review question
Does each fictional critical role have an authorized alternate with current access and training?
Fictional evidence
Alternate map, authority delegation, contact test, access review, and exercise results.
Limitation
An alternate may still be unavailable during a real schedule conflict.
Review question
Can fictional responders identify who may activate, contain, communicate, recover, accept risk, close, and reopen?
Fictional evidence
Decision-rights matrix, playbook tests, tabletop answers, exceptions, and escalation records.
Limitation
Authority may change across jurisdictions, services, suppliers, or policy conditions.
Review question
What percentage of fictional assignments receive documented acknowledgement and complete handoff fields?
Fictional evidence
Assignment log, response time, missing fields, acceptance, rejected handoffs, and aging.
Limitation
Acknowledgement does not prove the owner can complete the work.
Review question
How long do fictional owners take to acknowledge, answer, approve, execute, and validate?
Fictional evidence
Time-stamped requests, urgency tier, owner role, alternate use, complexity, and response quality.
Limitation
Fast response does not prove a correct decision.
Review question
How often are fictional conflicts declared, independently reviewed, reassigned, or escalated?
Fictional evidence
Conflict register, delegated authority, independent review, decision outcome, and lessons.
Limitation
Low conflict count may mean conflicts are not being recognized.
Review question
Do fictional high-impact decisions separate proposal, approval, execution, validation, and acceptance where required?
Fictional evidence
Decision records, action logs, validation records, emergency exceptions, and quality review.
Limitation
Separation can be limited by staffing and may require documented exceptions.
Review question
Which fictional roles, alternates, authority statements, contact paths, training, access, supplier paths, or review dates are stale or incomplete?
Fictional evidence
Debt register, owner, age, mission effect, due date, escalation, and validation.
Limitation
Counting debt does not show which gap has the greatest mission impact.
Fictional Response Architecture
This conceptual structure is completely invented and intentionally non-operational. It teaches role design without real personnel, services, contacts, authority chains, suppliers, incidents, or response procedures.
Mission inputs
Critical services, users, continuity, privacy, suppliers
Evidence inputs
Alerts, records, source health, scope, uncertainty
Authority inputs
Policies, decision rights, alternates, escalation
Lifecycle inputs
Activation, containment, recovery, closure, reopening
Fictional Response Core
Command
One coordinator, state, scope, decisions, conflicts
Technical
Evidence, hypotheses, source health, options, validation
Owners
Identity, service, infrastructure, supplier decisions
Governance
Evidence, privacy, communications, authority, risk
Continuity
Critical workflows, alternatives, user priorities
Recovery
Clean state, staged restoration, rollback, monitoring
Handoffs
Question, authority, evidence, deadline, acceptance
Lifecycle
Readiness, activation, closure, reopening, improvement
Operational output
Assigned owners, deadlines, decisions, actions
Governance output
Authority, evidence, privacy, risk, approval
Leadership output
Impact, options, decisions, resources, residual risk
Portfolio boundary
Fully fictional, privacy-safe, non-operational
Fake Dashboard
Fictional role coverage, alternate readiness, authority clarity, handoff acceptance, owner delay, conflict review, separation of duties, and role debt for training only.
Critical fictional roles with validated alternates
9 / 12
Continuity, supplier, and privacy alternates still require access, authority, contact, and exercise validation.
Open handoffs without acceptance
3
Identity, service-impact, and supplier questions remain with the coordinating incident owner until acknowledgement.
Open fictional role and authority debt
11
Alternates, supplier escalation, authority statements, shift handoff, conflicts, evidence access, communication approval, recovery acceptance, risk authority, training, and review dates remain open.
Fake SOC Alert
Source: Fake Northbridge Response Governance Console • Time: 9:36 AM
Fake Log Panel
09:00 RESPONSE state='activated' 09:01 INCIDENT-LEAD primary='assigned' 09:02 TECH-LEAD primary='assigned' 09:03 SERVICE-OWNER role='same-as-incident-lead' 09:04 CONFLICT status='undeclared' 09:10 HANDOFF identity-question='sent' 09:11 HANDOFF service-impact='sent' 09:12 HANDOFF supplier-state='sent' 09:25 ACCEPT identity='missing' 09:26 ACCEPT service='received' 09:27 ACCEPT supplier='missing' 09:30 CLOSURE request='immediate' 09:31 SOURCE group='recovering' 09:32 VALIDATION service='incomplete' 09:33 RISK owner='missing' 09:34 REVIEW independent='missing' 09:36 ALERT issue='role-conflict'
Training note: this is fake data for defensive analysis practice only.
Fictional Evidence Matrix
Observation
Incident lead, technical lead, and evidence coordinator are assigned, but no continuity owner is named.
Supports
A continuity responsibility gap exists.
Does not prove
The roster does not prove continuity decisions will be needed in every incident.
Response use
Assign a primary and alternate continuity owner before activation.
Observation
Technical lead may recommend service containment but cannot approve prolonged interruption.
Supports
Containment approval requires service and possibly leadership authority.
Does not prove
The matrix does not determine which option is technically strongest.
Response use
Route the proposal through coordinated technical, service, continuity, and leadership review.
Observation
Identity question was assigned at 09:10 but not acknowledged by 09:30.
Supports
The work is not yet accepted and the deadline is aging.
Does not prove
Nonresponse does not prove the identity owner is unavailable or the activity unauthorized.
Response use
Activate alternate contact and preserve the incident lead as coordinating owner.
Observation
Incident lead also owns the affected service and requested immediate closure.
Supports
Independent closure review is appropriate.
Does not prove
The dual role does not prove the closure recommendation is wrong.
Response use
Assign independent service or incident review and document decision authority.
Observation
Infrastructure owner proposed, executed, and validated a major isolation action.
Supports
Separation-of-duties review is required.
Does not prove
The record does not prove the action failed.
Response use
Assign independent validation and review whether an emergency exception was authorized.
Observation
Two audiences received different impact statements from separate owners.
Supports
Message coordination and correction are required.
Does not prove
The log does not establish which statement is correct.
Response use
Incident lead and communications lead reconcile evidence and issue a versioned correction.
Observation
The critical supplier relationship has no tested alternate contact or escalation path.
Supports
Supplier coordination is a readiness gap and decision debt.
Does not prove
The gap does not prove supplier response would fail.
Response use
Assign owner, test contact, document escalation, and report residual limitation.
Observation
The receiving incident lead acknowledged the case but did not receive the open decision and rollback trigger.
Supports
The handoff is incomplete despite acknowledgement.
Does not prove
The review does not prove the new lead made an incorrect decision.
Response use
Complete the handoff fields and confirm acceptance again.
Analyze the Evidence
Common Mistakes
Fictional observation
A fictional incident lead collects evidence, approves containment, sends messages, validates recovery, accepts risk, and closes the case alone.
Decision impact
Authority, expertise, independence, privacy, continuity, and validation become weak.
Professional correction
Separate coordination, technical analysis, owner decisions, evidence, communication, validation, and risk acceptance.
Fictional observation
A fictional roster lists owners but does not explain what each may approve or when to escalate.
Decision impact
Teams may delay, exceed authority, or issue conflicting decisions.
Professional correction
Create a decision-rights matrix with conditions, limits, inputs, independent review, and escalation.
Fictional observation
A fictional critical role has a backup name but the alternate lacks access, training, or delegated authority.
Decision impact
The response may still stop when the primary is unavailable.
Professional correction
Validate alternate authority, access, contact, training, documentation, and tabletop performance.
Fictional observation
A fictional question is sent to a role and removed from the coordinator's queue.
Decision impact
Work can become unowned or silently delayed.
Professional correction
Require handoff acknowledgement and retain coordinating ownership until acceptance.
Fictional observation
Fictional identity, network, and service owners act without one coordinated containment plan.
Decision impact
Actions may conflict, damage continuity, hide evidence, or create unclear outcomes.
Professional correction
Use incident command, explicit authority, dependency review, one plan, validation, and rollback.
Fictional observation
A fictional service owner serving as incident lead recommends rapid closure without independent review.
Decision impact
Bias or perceived bias can weaken trust and decision quality.
Professional correction
Declare the conflict, delegate the affected decision, and preserve independent validation.
Fictional observation
A fictional analyst sends raw evidence without a bounded decision request.
Decision impact
Leadership may make a resource or risk decision without clear options, uncertainty, or owner recommendations.
Professional correction
Provide mission impact, options, evidence, limitations, urgency, recommendation, authority need, and residual risk.
Fictional observation
A fictional evidence coordinator is asked to decide technical cause and severity.
Decision impact
Provenance responsibilities and technical interpretation become mixed.
Professional correction
Keep evidence governance separate from technical conclusions while supporting traceability.
Fictional observation
Fictional contact lists, alternates, authority, service ownership, and supplier paths are not reviewed.
Decision impact
The documented response structure may fail under time pressure.
Professional correction
Use review dates, tests, exercises, debt tracking, owner confirmation, and expiration.
Fictional observation
A student uses sanitized real staff names, phone trees, role charts, service ownership, or authority records.
Decision impact
Sensitive people, structures, priorities, and response capabilities may be exposed.
Professional correction
Invent every organization, role, contact, authority, service, event, decision, and outcome.
Safe Fictional Practice Lab
Document Northbridge's critical services, users, data, identity model, supplier dependencies, continuity priorities, privacy boundary, and response purpose.
Required output
Incident response mission and safety charter.
Quality check
Every organization, service, identity, role, contact, and decision is invented.
Define fictional incident lead, technical lead, identity, service, infrastructure, evidence, communications, privacy, continuity, recovery, supplier, and leadership roles.
Required output
Role catalog with missions and boundaries.
Quality check
Each role has a distinct purpose and does not silently replace other expertise.
Map fictional activation, severity, containment, evidence, communication, recovery, risk, closure, and reopening decisions to authorized owners.
Required output
Decision-rights matrix.
Quality check
Every decision includes required inputs, independent review, authority limit, and escalation.
Assign fictional primary owners, alternates, availability tiers, delegated authority, access needs, and escalation paths.
Required output
Primary and alternate owner register.
Quality check
A named alternate is not counted as ready until authority, access, training, and contact are validated.
Document fictional state, bounded question, authority, evidence, source health, scope, prior decisions, actions, dependencies, deadline, and acceptance.
Required output
Ten-field handoff checklist.
Quality check
Assignment remains with the coordinating owner until the receiver accepts.
Separate fictional initiation, validation, approval, execution, business acceptance, residual-risk acceptance, and closure for high-impact decisions.
Required output
Separation-of-duties matrix.
Quality check
Emergency exceptions are documented, time-bounded, reviewed, and independently validated later.
Evaluate fictional unavailable owners, duplicate command, dual roles, supplier disagreement, inconsistent messages, self-validation, and closure pressure.
Required output
Conflict and exception register.
Quality check
Every conflict has delegated authority, independent review, or escalation.
Test fictional routine, time-sensitive, mission-impacting, and extended-response conditions.
Required output
Availability and escalation test record.
Quality check
Acknowledgement, alternate activation, leadership path, and shift handoff are measurable.
Track fictional role coverage, alternate coverage, authority clarity, handoff acceptance, response time, conflict resolution, separation of duties, and role debt.
Required output
Role-readiness dashboard and debt register.
Quality check
Metrics balance speed with authority, quality, completeness, privacy, and continuity.
Combine the fictional mission, roles, authority, alternates, handoffs, separation, conflicts, availability, metrics, debt, residual risk, and reflection.
Required output
Public-safe Incident Response Role and Authority Package.
Quality check
No real role chart, contact, service owner, supplier path, authority, or response structure is used.
Scenario Decision Lab
A fictional time-sensitive response begins while the primary incident lead is unavailable. A trained alternate exists, but the service owner suggests waiting for the primary because the alternate has never led a real event.
Scenario Decision Lab
The fictional incident lead is also the service owner and recommends immediate closure. Source recovery, independent service validation, and residual-risk acceptance remain incomplete.
Advanced Challenge
Fictional Northbridge has twelve response responsibilities, three missing alternates, one unaccepted identity handoff, one conflicted incident lead, an untested supplier escalation path, a self-validated containment action, and no current residual-risk authority for extended recovery.
Defend command
Explain fictional incident lead mission, authority, limits, alternate, state, scope, decisions, conflicts, handoffs, and closure role.
Defend specialist ownership
Explain fictional technical, identity, service, infrastructure, evidence, privacy, communications, continuity, recovery, and supplier questions.
Defend decision rights
Explain fictional activation, containment, evidence, communication, recovery, risk, closure, and reopening authority.
Defend handoffs
Explain fictional state, question, authority, evidence, source health, scope, decisions, actions, dependencies, deadline, and acceptance.
Defend independence
Explain fictional separation of duties, conflicts, delegated decisions, emergency exceptions, independent validation, and review.
Defend readiness
Explain fictional alternates, availability tiers, contact tests, exercises, debt, metrics, residual risk, and review dates.
Challenge output
Produce a fictional mission charter, twelve-role catalog, responsibility matrix, decision-rights matrix, primary and alternate owner map, availability model, ten-field handoff, separation-of-duties matrix, conflict register, escalation map, role-readiness dashboard, debt register, residual-risk statement, leadership summary, and public portfolio boundary.
Defender Habits
Check Your Understanding
Choose your answers first. Explanations appear only after submission.
Portfolio Prompt
Create a fully fictional Incident Response Role and Authority Package for the Northbridge Student-Support Cooperative. Include mission, critical services, users, data categories, identity model, supplier dependencies, continuity priorities, privacy boundary, incident lead, deputy incident lead, technical analysis lead, alternate technical lead, identity owner, alternate identity owner, service owner, alternate service owner, infrastructure owner, alternate infrastructure owner, evidence coordinator, alternate evidence coordinator, communications lead, alternate communications lead, privacy reviewer, alternate privacy reviewer, continuity owner, alternate continuity owner, recovery owner, alternate recovery owner, supplier owner, alternate supplier owner, leadership decision owner, alternate leadership owner, role mission, responsibilities, decision rights, authority boundaries, inputs, outputs, required evidence, availability expectations, escalation paths, training requirements, access requirements, review dates, activation authority, severity authority, confidence authority, priority authority, identity-containment authority, service-containment authority, infrastructure-action authority, evidence-preservation authority, evidence-sharing authority, communication authority, recovery authority, residual-risk authority, closure authority, reopening authority, decision inputs, independent review, escalation conditions, current incident state, bounded handoff questions, handoff authority, handoff evidence, source health, handoff scope, prior decisions, actions, validation, dependencies, continuity, deadlines, urgency, acceptance, incident declaration separation, high-impact containment separation, evidence-access separation, communication separation, recovery-acceptance separation, residual-risk separation, closure separation, corrective-action separation, routine availability, time-sensitive availability, mission-impacting availability, extended-response availability, conflict declaration, dual-role conflict, unavailable-owner conflict, duplicate-command conflict, supplier-evidence conflict, inconsistent-communication conflict, self-validation conflict, closure-pressure conflict, broad-evidence-request conflict, validation cases, expected results, role-coverage metrics, alternate-coverage metrics, authority-clarity metrics, handoff-acceptance metrics, owner-response metrics, role-conflict metrics, separation-of-duties metrics, role debt, owner matrix, residual risk, leadership summary, reflection, and a statement that every organization, role, contact, authority, service, supplier, incident, event, decision, action, and outcome is invented.
Confidence / Readiness Reflection
Before moving to A7.2, rate your readiness from 1 to 5 for role mission, command, technical ownership, service and identity authority, evidence, communication, privacy, continuity, recovery, supplier coordination, leadership, alternates, handoffs, separation, conflicts, availability, metrics, and complete fictionalization.
Key Takeaways
Navigation
Next, learn how fictional incident response teams transform mission, authority, roles, evidence, source health, containment, continuity, communication, recovery, validation, rollback, closure, and reopening into usable plans and scenario-specific playbooks.