High School AdvancedModule A7Lesson 10 of 10Full-Lifecycle Defensive Simulation

A7.10 Incident Response Simulation Lab

Integrate preparation, activation, roles, evidence, source health, scoping, priority, containment, continuity, communication, preservation, cause, recovery, validation, review, metrics, corrective actions, closure, and reopening in one fully fictional defensive capstone.

Lesson Progress

Incident Response Simulation Lab

High School AdvancedA7: Incident Response Lifecycle • Lesson 10 of 10

100% complete

Readiness Check

Before You Start

0/6 ready

Professional Hook

The Hardest Incident-Response Problems Are Coordination Problems

Fictional Northbridge begins with one stale role and one privileged session. Within two hours, the team must handle a Degraded identity source, a Blind data source, one user report, a delayed supplier, a leadership decision, a narrow containment action, an inaccurate message, a broad preservation request, failed recovery gates, late conflicting evidence, corrective actions, and a green metric that hides poor quality. No single technical answer can solve the whole scenario.

Weak simulation behavior

“Find the cause, shut everything down, and call the service recovered when it responds.”

Strong simulation behavior

“Coordinate bounded evidence, roles, decisions, mission, privacy, communication, recovery gates, validation, learning, and improvement.”

The simulation is successful when participants can defend the lifecycle of their decisions—not when they guess a hidden answer.

Exactly Five Learning Objectives

What You Will Be Able to Do

Objective 1

Integrate fictional preparation, activation, role coordination, source-health reasoning, scoping, prioritization, containment, continuity, communication, evidence preservation, eradication, recovery, validation, review, metrics, and reopening into one coherent response.

Objective 2

Build and maintain a fictional incident record that separates confirmed, possible, Unknown, unaffected, excluded, and out-of-scope entities while preserving chronology, source health, evidence quality, decision rights, and version history.

Objective 3

Defend fictional containment and recovery decisions using bounded questions, options, authority, expected state, validation, rollback, continuity, privacy, user impact, supplier dependencies, and residual risk.

Objective 4

Create fictional audience-specific communications, evidence-preservation records, post-incident lessons, corrective actions, and metrics without exposing real systems, identities, incidents, suppliers, or operational procedures.

Objective 5

Produce a portfolio-ready fictional Incident Response Simulation Package containing the complete lifecycle record, decision log, scope register, communication set, evidence package, recovery plan, review findings, improvement dashboard, leadership brief, and reflection.

Why This Matters

A Complete Response Must Remain Coherent as Evidence Changes

Fictional response decisions are connected. A source-health change may alter scope, communication, containment confidence, recovery, privacy, leadership, metrics, and closure. A corrected message may require decision-owner acknowledgement. A failed canary may trigger rollback. A recovered source may reopen the case. The lab teaches students to maintain that connected record under pressure.

Integrate the lifecycle

Fictional preparation, decisions, communications, evidence, recovery, review, and metrics remain connected.

Protect mission and people

Fictional continuity, accessibility, privacy, suppliers, users, and leadership needs shape response choices.

Create durable learning

Fictional exercise evidence becomes owned, testable, measurable, and validated program improvement.

Core Framework

The I-N-C-I-D-E-N-T Method

I — Initiate safely

Confirm fictional charter, roles, alternates, authority, evidence owners, boundaries, and pause conditions.

N — Name the question

Define fictional activation, scope, containment, communication, preservation, recovery, or leadership decision.

C — Classify evidence and scope

Separate fictional facts, conclusions, Unknowns, relationships, source health, confidence, and non-proof.

I — Identify options and owners

Compare fictional choices, authority, mission effect, privacy, dependencies, validation, and rollback.

D — Decide and document

Record fictional evidence, rationale, expected state, action, communication, owner, deadline, and residual risk.

E — Evaluate outcomes

Validate fictional source-side state, continuity, user effect, data, supplier, monitoring, and side effects.

N — Navigate change

Correct fictional messages, update scope, respond to late evidence, freeze recovery, and reopen decisions.

T — Transform learning

Convert fictional hotwash and review evidence into actions, tests, metrics, debt, governance, and closure.

Simulation command statement

Fictional Northbridge will coordinate a bounded response to one confirmed identity-session-service relationship, preserve uncertainty around group, device, supplier, user, and protected data, select narrow authorized containment, maintain mission continuity, correct unsupported communication, and recover only through mandatory clean-state gates.

Advanced Vocabulary

Terms for Incident Response Simulation

Simulation inject

A fictional timed event, evidence item, source change, decision request, user report, supplier update, or recovery condition introduced into the exercise.

Master scenario events list

A fictional ordered list controlling inject timing, expected decisions, evidence availability, source health, and observer prompts.

Controller

The fictional role that introduces approved exercise injects and keeps the scenario on its intended path.

Facilitator

The fictional role that explains rules, keeps participants focused on decisions, and protects the exercise boundary.

Observer

The fictional role that records decisions, evidence use, source-health reasoning, communication quality, ownership, and outcomes without secretly changing the scenario.

Participant

A fictional responder role expected to interpret evidence and make decisions within its documented authority.

White cell

A fictional exercise coordination group controlling scenario flow, clarifications, timing, safety, and observer consistency.

Exercise boundary

The fictional rule that all systems, evidence, identities, suppliers, communications, actions, and outcomes are invented and non-operational.

Decision point

A fictional moment requiring a bounded choice, owner, authority, evidence, rationale, validation, and next review.

Decision clock

A fictional time window showing when a decision or acknowledgement is needed for mission, risk, communication, or recovery reasons.

Scope register

A fictional versioned list of confirmed, possible, Unknown, unaffected, excluded, and out-of-scope entities and relationships.

Evidence pack

A fictional set of decision-relevant records with purpose, provenance, timing, source health, limitations, access, and retention.

Source-health inject

A fictional change to a source such as Healthy, Conditional, Degraded, Blind, Conflicting, or Recovering.

Control objective

A fictional desired defensive condition such as reduced risk, protected continuity, trusted recovery, accurate communication, or validated improvement.

Containment objective

The fictional current risk or unsafe condition that an authorized action should reduce.

Clean-state gate

A fictional identity, session, configuration, service, data, supplier, source, dependency, monitoring, privacy, continuity, or user condition required for recovery.

Recovery wave

A fictional bounded group of users, identities, functions, integrations, or services restored under shared entry, validation, rollback, and exit criteria.

Break condition

A fictional event that freezes, reverses, escalates, or reopens containment, communication, recovery, or closure.

Exercise success condition

A fictional evidence-supported outcome demonstrating the intended decision or program capability.

Exercise failure condition

A fictional missed gate, unsupported conclusion, unowned action, privacy problem, source-health error, or harmful decision requiring correction.

Hotwash

A fictional immediate structured reflection capturing strengths, gaps, unanswered questions, and urgent actions after the exercise.

After-action review

A fictional evidence-based review converting exercise observations into lessons, corrective actions, owners, tests, and improvement decisions.

Exercise metric

A fictional defined measure of role activation, evidence use, scope quality, containment, communication, recovery, review, or improvement performance.

Exercise debt

Fictional unresolved playbook, source, ownership, communication, recovery, evidence, supplier, validation, or governance work revealed by the simulation.

Reopen trigger

A fictional late evidence, recurring condition, source recovery, failed validation, scope expansion, user effect, supplier problem, or overdue action that returns the scenario to active review.

Instructional Section 1

Assign Ten Simulation Roles

Incident lead

Mission

Coordinate fictional activation, priorities, decisions, scope, containment, communications, recovery, risk, and closure.

Authority

Approve response coordination within the exercise plan and escalate beyond delegated authority.

Evidence needed

Current chronology, scope, source health, impacts, owners, decisions, and deadlines.

Required deliverable

Incident command record and leadership decision brief.

Failure pattern

Becoming the only decision-maker or skipping domain owners.

Technical lead

Mission

Translate fictional evidence into bounded technical questions, options, expected states, validation, and rollback.

Authority

Recommend technical actions and coordinate authorized technical owners.

Evidence needed

Identity, session, service, configuration, source, dependency, and validation records.

Required deliverable

Technical decision and containment option matrix.

Failure pattern

Treating technical possibility as authority or confirmed scope.

Identity owner

Mission

Evaluate fictional roles, groups, approvals, sponsors, lifecycle state, effective access, and sessions.

Authority

Approve identity actions within delegated policy.

Evidence needed

Role, group, approval, sponsor, session, source-health, and owner records.

Required deliverable

Identity scope, validation, and clean-state record.

Failure pattern

Assuming role removal proves active-session closure.

Service and continuity owner

Mission

Protect fictional critical workflows, users, accessibility, alternate processes, capacity, and service recovery.

Authority

Approve service and continuity decisions within the exercise.

Evidence needed

Service health, dependencies, users, backlog, support reports, recovery gates, and supplier state.

Required deliverable

Continuity impact and user-acceptance record.

Failure pattern

Treating service availability as full recovery.

Evidence coordinator

Mission

Maintain fictional evidence purpose, provenance, chronology, source health, access, custody, retention, corrections, and derived links.

Authority

Govern exercise evidence metadata and preservation records.

Evidence needed

Every material source, decision, communication, transfer, correction, and review record.

Required deliverable

Evidence register, chronology, custody log, and source-health matrix.

Failure pattern

Preserving everything without purpose or minimum-necessary limits.

Privacy and data reviewer

Mission

Evaluate fictional data categories, access, source health, sharing, retention, user communication, and acceptance.

Authority

Approve privacy conclusions and data-related communication within delegated policy.

Evidence needed

Data scope, source health, alternate evidence, transfers, suppliers, communications, and recovery state.

Required deliverable

Privacy decision and data-state record.

Failure pattern

Calling a Blind period unaffected.

Communications lead

Mission

Create fictional audience-specific facts, uncertainty, impact, guidance, decisions, corrections, and next updates.

Authority

Coordinate approved internal, user, supplier, leadership, and recovery communications.

Evidence needed

Approved facts, uncertainty, impact categories, decisions, privacy boundaries, and owner commitments.

Required deliverable

Versioned communication package and acknowledgement tracker.

Failure pattern

Sending one technical message to every audience.

Supplier relationship owner

Mission

Coordinate fictional provider evidence, status, commitments, confidentiality, escalation, and recovery dependencies.

Authority

Send bounded supplier requests and activate approved escalation paths.

Evidence needed

Dependency map, relevant period, local evidence, supplier statements, queue state, and privacy limits.

Required deliverable

Supplier request, commitment log, and reconciliation record.

Failure pattern

Assigning causation before evidence or lacking an alternate.

Recovery lead

Mission

Design fictional clean-state criteria, canary waves, validation, rollback, observation, acceptance, and reopen triggers.

Authority

Recommend or approve recovery waves within documented decision rights.

Evidence needed

Identity, session, configuration, service, data, supplier, source, dependency, monitoring, and user gates.

Required deliverable

Recovery-wave plan and validation dashboard.

Failure pattern

Restoring broadly because the service responds.

Observer and facilitator

Mission

Protect fictional exercise safety, timing, scoring consistency, and learning.

Authority

Pause the exercise for safety, clarification, or controller alignment.

Evidence needed

Scenario events, expected decisions, scoring criteria, participant records, and inject history.

Required deliverable

Observer scorecard, hotwash record, and after-action evidence.

Failure pattern

Coaching participants toward answers or changing scores inconsistently.

Instructional Section 2

Run Ten Full-Lifecycle Phases

Phase 0 — Preparation

Objective

Confirm fictional roles, alternates, playbooks, evidence sources, communication templates, continuity options, recovery gates, and simulation rules.

Participant tasks

Acknowledge roles, review authority, identify Blind-source branches, verify user and supplier contacts, and record exercise boundaries.

Controller inject

One alternate identity owner is unavailable and one supplier contact is stale.

Required decision

Activate alternates and determine whether readiness debt blocks the exercise.

Success condition

Critical roles, authority, alternates, evidence ownership, and safety boundaries are explicit.

Break condition

Participants use real systems, real contacts, real evidence, or unsupported operational actions.

Phase 1 — Detection and activation

Objective

Interpret a fictional alert without assuming intent, impact, or complete scope.

Participant tasks

Review the alert, source health, identity, service, destination, change context, and decision clock.

Controller inject

A temporary recovery role remains Active near approval expiration, and one session reaches an administrative destination.

Required decision

Routine triage, source-recovery issue, service issue, or incident coordination?

Success condition

Activation is bounded, evidence-based, owned, and time-stamped.

Break condition

The team declares breach, data access, or malicious intent from the alert alone.

Phase 2 — Initial scoping

Objective

Create the first fictional scope version using confirmed, possible, Unknown, unaffected, excluded, and out-of-scope categories.

Participant tasks

Register identity, role, group, session, service, destination, device, supplier, data, and user relationships.

Controller inject

Group evidence is Degraded, the device relationship is possible, and one user reports delay.

Required decision

Which entities enter confirmed, possible, and Unknown scope?

Success condition

Every entity has evidence, source health, confidence, owner, limitation, and next evidence.

Break condition

Every related entity is called affected.

Phase 3 — Priority and containment

Objective

Select the narrowest fictional authorized action that reduces supported current risk.

Participant tasks

Compare monitor, close session, restrict role, disable identity, limit service function, pause integration, and broad interruption options.

Controller inject

The identity supports urgent student-assistance work and the service remains available.

Required decision

Which action best balances risk, continuity, evidence, authority, validation, and rollback?

Success condition

The decision includes question, options, authority, expected state, validation, side effects, rollback, and residual risk.

Break condition

The broadest action is selected automatically without comparison.

Phase 4 — Communication and privacy

Objective

Create fictional analyst, user, supplier, privacy, recovery, and leadership updates.

Participant tasks

Separate facts, conclusions, uncertainty, non-proof, impact, guidance, privacy, decisions, and next updates.

Controller inject

The protected-data source becomes Blind, and a draft message says no data was affected.

Required decision

How should the data status and correction process be handled?

Success condition

Data becomes Unknown, the unsupported statement is corrected, and affected owners acknowledge the change.

Break condition

The Blind source is treated as proof of no access.

Phase 5 — Evidence preservation

Objective

Preserve only fictional evidence needed for bounded response questions.

Participant tasks

Build purpose, authority, scope, provenance, multi-time chronology, source health, access, custody, retention, transfer, and correction records.

Controller inject

A broad request asks to preserve every user and supplier record indefinitely.

Required decision

What minimum-necessary evidence should be preserved, by whom, for how long, and for which decision?

Success condition

Every item has purpose, source, owner, timing, health, supports, limitations, access, retention, and decision use.

Break condition

Preserve everything forever becomes the plan.

Phase 6 — Eradication and recovery

Objective

Separate containment, cause correction, clean state, staged recovery, validation, rollback, observation, and closure readiness.

Participant tasks

Build trigger, immediate cause, root cause, contributing conditions, control gaps, clean-state gates, and recovery waves.

Controller inject

The service is reachable, but group evidence is Degraded, supplier backlog is unreconciled, and critical-user validation is incomplete.

Required decision

Can recovery expand beyond the identity canary?

Success condition

Mandatory failed gates block or narrow expansion; rollback and owner acceptance remain ready.

Break condition

Service availability is called trusted recovery.

Phase 7 — Late evidence and reopening

Objective

Reassess fictional decisions when sources recover or evidence conflicts.

Participant tasks

Preserve prior versions, register recovered evidence, correct scope and communications, and identify affected recovery and risk decisions.

Controller inject

Recovered group records conflict with the prior effective-access interpretation.

Required decision

Does the case, recovery plan, communication set, or closure review reopen?

Success condition

Prior history remains visible and affected decisions are corrected with acknowledgement.

Break condition

Late evidence is ignored or silently overwrites the prior record.

Phase 8 — Post-incident review

Objective

Convert fictional response experience into strengths, gaps, lessons, corrective actions, and validation.

Participant tasks

Review chronology, decisions, source health, continuity, communication, preservation, recovery, metrics, and residual risk.

Controller inject

Leadership asks who caused the incident and wants all actions closed after the review meeting.

Required decision

How will the review preserve accountability without unsupported blame?

Success condition

Lessons become specific owned actions with alternates, due dates, validation, risk, and escalation.

Break condition

The review becomes personal blame or vague recommendations.

Phase 9 — Metrics and continuous improvement

Objective

Measure fictional exercise and program outcomes without rewarding shortcuts.

Participant tasks

Define populations, quality gates, source health, distributions, action validation, recurrence, gaming risk, and metric retirement.

Controller inject

Closure speed is green, but three sampled cases lack owner validation.

Required decision

Can the program claim improvement, and what metric redesign is required?

Success condition

The valid speed result is preserved while the overall quality claim remains Conditional.

Break condition

A green number is treated as proof of complete improvement.

Instructional Section 3

Control a Twenty-Inject Scenario Timeline

08:00

Exercise start and role acknowledgement.

Source state

All fictional baseline sources Healthy.

Evidence

Role chart, authority matrix, playbook version, contact list, and exercise charter.

Expected action

Confirm primary and alternate owners, boundaries, communication channels, and pause authority.

Observer focus

Role acceptance, alternate coverage, safety, and readiness debt.

08:12

Temporary recovery role remains Active near approval expiration.

Source state

Role source Healthy; group source Conditional.

Evidence

Role NB-ROLE-17, identity NB-ID-042, approval end, sponsor, and owner.

Expected action

Open bounded triage and request session plus group evidence.

Observer focus

Fact versus conclusion, owner assignment, and source-health awareness.

08:18

One privileged session reaches coordination-admin.

Source state

Session source Healthy.

Evidence

Session NB-SES-881, service NB-SVC-07, destination, start time, and identity relationship.

Expected action

Consider incident activation and create initial confirmed scope.

Observer focus

Activation rationale and avoidance of intent assumptions.

08:25

Group evidence becomes Degraded because synchronization is delayed.

Source state

Group source Degraded.

Evidence

Source-health notice, delayed processing, and incomplete effective-access view.

Expected action

Qualify identity conclusions and assign alternate evidence.

Observer focus

Whether missing evidence becomes proof of safe or unsafe state.

08:31

One staff user reports a delayed support submission.

Source state

User-support source Conditional.

Evidence

One report, workflow, service state, alternate process, and support owner.

Expected action

Add possible limited user impact without broad disruption claim.

Observer focus

Impact categorization and continuity ownership.

08:37

Supplier integration reports delayed responses.

Source state

Supplier statement Conditional; local service source Healthy.

Evidence

Supplier NB-SUP-03 notice, dependency map, queue summary, and local health.

Expected action

Create a bounded supplier request and preserve alternative explanations.

Observer focus

Fairness, confidentiality, deadline, acknowledgement, and escalation.

08:43

Protected-data evidence source becomes Blind for the relevant period.

Source state

Data source Blind.

Evidence

Blind-period notice, data categories, owner, alternate evidence, and privacy questions.

Expected action

Classify protected-data access as Unknown and review message language.

Observer focus

Source-health honesty and privacy decision quality.

08:50

Leadership asks whether the service should be paused.

Source state

Service source Healthy; broader scope still Conditional.

Evidence

Current scope, service health, continuity, user report, supplier delay, and data Unknown.

Expected action

Present options, recommendation, mission effect, authority, validation, and next review.

Observer focus

Decision framing and avoidance of broad default action.

08:57

Scoped session containment is approved.

Source state

Identity and session evidence Healthy enough for session-level action.

Evidence

Decision record, authority, expected Closed state, continuity, rollback, and residual risk.

Expected action

Close the confirmed session conceptually and validate source-side state.

Observer focus

Target precision, separation of duties, and expected-state validation.

09:05

Service remains available after containment.

Source state

Service source Healthy; identity and data questions remain.

Evidence

Service health, critical workflow, user-support status, and session validation.

Expected action

Report successful session containment without declaring full eradication or recovery.

Observer focus

Outcome precision and non-proof statements.

09:12

Draft Update 2.1 states protected data was unaffected.

Source state

Data source still Blind.

Evidence

Draft message, source-health record, audience map, and privacy review.

Expected action

Reject the unsupported statement and prepare an accurate approved update.

Observer focus

Communication approval and uncertainty language.

09:20

Update 2.1 is discovered after distribution to leadership and recovery owners.

Source state

Communication record Healthy; data source Blind.

Evidence

Prior version, distribution, recipients, acknowledgement, and decision dependencies.

Expected action

Issue explicit correction, redistribute, obtain acknowledgement, and update connected records.

Observer focus

Correction completeness and decision impact.

09:30

A request asks to preserve every available record indefinitely.

Source state

Multiple sources mixed.

Evidence

Broad preservation request with no question, owner, fields, period, access, or retention.

Expected action

Pause and replace with purpose-based minimum-necessary preservation.

Observer focus

Authority, privacy, proportionality, and lifecycle governance.

09:42

Cause analysis identifies a lifecycle ownership gap.

Source state

Role, approval, session, and process evidence mostly Healthy.

Evidence

Trigger, immediate cause, root-cause hypothesis, contributing factors, and alternatives.

Expected action

Approve a bounded correction target with validation and rollback.

Observer focus

Cause confidence, alternatives, and non-blaming analysis.

10:00

Identity canary preparation is complete.

Source state

Role and session sources Healthy; group source Degraded.

Evidence

Known-good role, approval, sponsor, session plan, and rollback.

Expected action

Keep the canary Conditional until group-state limitations are resolved or accepted.

Observer focus

Clean-state discipline and source-health gates.

10:12

Supplier queue may contain duplicate submissions.

Source state

Supplier and queue evidence Conditional.

Evidence

Supplier statement, local queue count, data-integrity question, and recovery dependency.

Expected action

Freeze integration expansion and assign reconciliation.

Observer focus

Data integrity, supplier fairness, ownership, and rollback.

10:25

Critical-user canary sign-in succeeds, but submission workflow fails.

Source state

Identity Healthy; user workflow and data state Conditional.

Evidence

Canary result, user report, service response, queue state, and monitoring.

Expected action

Freeze expansion, preserve evidence, investigate dependency, and roll back or revise.

Observer focus

Availability versus trusted recovery.

10:40

Recovered group records conflict with the prior interpretation.

Source state

Group source Recovering then Conflicting.

Evidence

Historical records, prior scope, correction log, recovery decision, and communications.

Expected action

Preserve history, correct affected records, and reopen relevant decisions.

Observer focus

Late evidence, correction propagation, and reopening.

11:00

Leadership requests formal closure.

Source state

Several sources Healthy; supplier and data obligations remain Conditional.

Evidence

Observation, recovery gates, residual risk, action register, debt, and source reconciliation.

Expected action

Provide a closure-readiness recommendation and preserve open obligations.

Observer focus

Closure conditions, risk acceptance, and reopen triggers.

11:20

Exercise hotwash begins.

Source state

Exercise evidence pack complete enough for review.

Evidence

Observer notes, decision log, communications, scorecard, strengths, gaps, and actions.

Expected action

Capture immediate strengths, gaps, urgent corrections, and unanswered questions.

Observer focus

Blameless accountability, specificity, and action ownership.

Instructional Section 4

Maintain a Ten-Entity Scope Register

NB-ID-042

Fictional identity

Confirmed

Evidence

Role and session records connect the identity to the relevant session.

Source health

Healthy

Limitation

Does not prove harmful intent or every action.

Owner

Identity owner

Next evidence

Role, group, approval, session, and owner validation.

NB-SES-881

Fictional privileged session

Confirmed

Evidence

Session source records service, destination, identity, and time.

Source health

Healthy

Limitation

Does not prove protected-data access.

Owner

Identity and service owners

Next evidence

Containment validation and session-end confirmation.

NB-SVC-07

Fictional service

Confirmed relationship

Evidence

The confirmed session reached one administrative destination within the service.

Source health

Healthy

Limitation

Relationship does not prove service-wide impact.

Owner

Service owner

Next evidence

Administrative state, user workflows, errors, and recovery validation.

coordination-admin

Fictional destination

Confirmed

Evidence

Session source identifies the destination.

Source health

Healthy

Limitation

Destination does not prove a specific action occurred.

Owner

Service owner

Next evidence

Function-level and change-context review.

recovery-admin

Fictional group

Unknown / Conditional

Evidence

Group relationship may affect effective access.

Source health

Degraded then Recovering

Limitation

Exact state during the key period is not initially reliable.

Owner

Identity platform owner

Next evidence

Recovered historical group records and alternate identity evidence.

NB-DEV-14

Fictional device

Possible

Evidence

One session relationship may connect the device.

Source health

Conditional

Limitation

The relationship is not independently confirmed.

Owner

Technical owner

Next evidence

Qualified device-session ownership record.

NB-SUP-03

Fictional supplier integration

Possible dependency

Evidence

Supplier reports delayed responses and the service depends on the integration.

Source health

Conditional

Limitation

Does not prove supplier causation.

Owner

Supplier relationship owner

Next evidence

Bounded supplier evidence and local queue reconciliation.

Protected student-support records

Fictional data category

Unknown

Evidence

The decision-critical data source is Blind for part of the relevant period.

Source health

Blind

Limitation

Supports neither access nor no-access conclusions.

Owner

Data and privacy owners

Next evidence

Alternate evidence, source recovery, and historical reconciliation.

One staff support user

Fictional user

Possible limited impact

Evidence

One report describes a delayed submission.

Source health

Conditional

Limitation

Does not represent all users or prove incident causation.

Owner

Service and continuity owners

Next evidence

Canary testing, support reports, and workflow validation.

Broader user population

Fictional users

Not confirmed affected

Evidence

No broad error increase or widespread reports exist.

Source health

Healthy enough for broad service-health question

Limitation

Does not prove every user was unaffected.

Owner

Service owner

Next evidence

Segmented user acceptance and observation.

Instructional Section 5

Defend Ten Material Decisions

DEC-01

Activate fictional incident coordination

Decision question

Does the evidence justify structured response beyond routine triage?

Options

Continue routine triage, treat as source issue, treat as service issue, or activate incident coordination.

Evidence

Role remains Active, one privileged session reaches an administrative destination, source health is mixed, and mission impact is not yet confirmed.

Authority

Incident lead within the exercise charter.

Selected choice

Activate bounded incident coordination.

Expected state

Named owners, current scope, decision clocks, evidence questions, communication plan, and next review.

Validation

Role acknowledgements, scope version, decision log, and owner deadlines exist.

Rollback

Return to routine ownership if later evidence shows no incident-response coordination need.

Residual risk

Intent, data access, complete scope, and supplier relationship remain unresolved.

DEC-02

Classify protected-data status

Decision question

Can protected-data access be called affected or unaffected?

Options

Affected, possible, unaffected, or Unknown.

Evidence

The decision-critical source is Blind for part of the relevant period.

Authority

Privacy and data owner with incident coordination.

Selected choice

Classify as Unknown.

Expected state

Messages, scope, recovery, leadership, and evidence records preserve the uncertainty.

Validation

No approved message says unaffected without alternate qualified evidence.

Rollback

Revise classification when recovered or alternate evidence supports a bounded conclusion.

Residual risk

Historical data access remains unresolved until source recovery or accepted limitation.

DEC-03

Select fictional containment

Decision question

Which authorized action reduces the strongest supported current risk with the smallest mission blast radius?

Options

Monitor, close the confirmed session, restrict role, disable identity, limit service function, pause integration, or pause service.

Evidence

One session is confirmed; the identity supports urgent work; broad service impact is not confirmed.

Authority

Identity owner and incident lead under the exercise matrix.

Selected choice

Close the confirmed session and preserve broader identity availability.

Expected state

The session reaches Closed while critical service continuity remains stable.

Validation

Source-side session state, identity state, service health, user impact, and monitoring agree.

Rollback

Restore only an approved replacement session when business and technical gates pass.

Residual risk

Role, group, data, device, supplier, and recurrence questions remain.

DEC-04

Issue fictional user guidance

Decision question

Do users need an advisory before broad impact is confirmed?

Options

No message, broad outage notice, or limited plain-language guidance.

Evidence

One user reports delay, the service remains available, and an alternate process exists.

Authority

Service and communications owners with privacy review.

Selected choice

Issue limited guidance for delayed submissions and the alternate process.

Expected state

Users know what they may notice, what to do, what not to do, where to get help, and when the next update arrives.

Validation

Support owner and accessibility reviewer acknowledge the approved message.

Rollback

Correct or retract guidance if service conditions or evidence materially change.

Residual risk

The complete affected user population remains unknown.

DEC-05

Correct fictional Update 2.1

Decision question

How should an unsupported unaffected statement be handled?

Options

Quiet edit, delay correction, or issue explicit versioned correction.

Evidence

Update 2.1 reached decision owners while the data source was Blind.

Authority

Incident, privacy, and communications leads.

Selected choice

Issue explicit correction changing the status to Unknown.

Expected state

Every affected recipient receives the current version and understands decision impact.

Validation

Distribution, acknowledgement, connected-record updates, and version history are complete.

Rollback

Not applicable to history; a later evidence-based update may supersede the correction.

Residual risk

Some recipients may continue using the prior statement until acknowledgement completes.

DEC-06

Approve fictional evidence preservation scope

Decision question

Which evidence is necessary for the response questions?

Options

Preserve everything, preserve nothing until certainty, or preserve bounded decision-relevant records.

Evidence

Role, session, group, service, data-source limitation, supplier, user, communication, and recovery records support material decisions.

Authority

Evidence coordinator with domain, privacy, and incident owners.

Selected choice

Preserve the minimum necessary bounded evidence package.

Expected state

Every item has purpose, provenance, timing, source health, access, retention, limitations, and decision use.

Validation

Evidence register, custody, access, and retention records pass review.

Rollback

Correct scope or disposition when purpose, authority, or evidence needs change.

Residual risk

Source recovery may add historical records requiring correction or reopening.

DEC-07

Approve fictional recovery expansion

Decision question

Can recovery move beyond the identity canary?

Options

Full expansion, bounded exception, remain at current wave, or rollback.

Evidence

Service availability passes, but group, supplier queue, protected-data, and critical-user gates remain incomplete.

Authority

Recovery lead with technical, service, privacy, supplier, and business acceptance owners.

Selected choice

Remain at Wave 1 Conditional.

Expected state

No broader users or integrations restore until mandatory gates pass or an explicit exception is approved.

Validation

Recovery dashboard, owner acknowledgements, rollback readiness, and failed-gate records are current.

Rollback

Close the canary session and return to scoped containment if a break condition occurs.

Residual risk

Mission delay and recovery debt continue while gates remain open.

DEC-08

Respond to fictional canary failure

Decision question

What happens when sign-in succeeds but the critical submission workflow fails?

Options

Expand anyway, freeze and investigate, remove the gate, or close the incident.

Evidence

Canary identity passes; service workflow and queue integrity do not.

Authority

Recovery, service, data, and incident leads.

Selected choice

Freeze expansion and investigate the workflow plus queue state.

Expected state

Evidence is preserved, users remain on the alternate workflow, and rollback remains available.

Validation

The failed workflow, queue, monitoring, user effect, and owner decisions are recorded.

Rollback

Return to the prior accepted wave.

Residual risk

Recovery time increases, but a broader inconsistent state is avoided.

DEC-09

Reopen after fictional late evidence

Decision question

Which prior conclusions and decisions are affected by recovered group records?

Options

Ignore, overwrite history, correct selected records, or reopen all relevant decisions.

Evidence

Recovered records conflict with the prior effective-access interpretation.

Authority

Incident lead with identity, evidence, recovery, privacy, and communications owners.

Selected choice

Preserve history, correct affected artifacts, and reopen relevant decisions.

Expected state

Scope, communication, recovery, risk, and closure records reflect the new evidence.

Validation

Correction propagation and owner acknowledgement are complete.

Rollback

Prior versions remain preserved; no silent replacement occurs.

Residual risk

Further historical records may still change the conclusion.

DEC-10

Declare fictional closure readiness

Decision question

Are response, recovery, evidence, communication, improvement, and risk obligations complete enough for closure?

Options

Close, close conditionally, remain active, or reopen.

Evidence

Containment is stable, but source reconciliation, supplier work, several actions, and observation remain open.

Authority

Closure authority defined by the exercise charter.

Selected choice

Maintain Conditional closure readiness.

Expected state

Open obligations transfer into owned records with due dates, risk, escalation, and reopen triggers.

Validation

Closure checklist, debt, risk, archive, action owners, and observation are complete.

Rollback

Return to active response when a reopen trigger occurs.

Residual risk

Late evidence, recurrence, supplier delay, or failed corrective action may change the case.

Instructional Section 6

Preserve a Ten-Item Fictional Evidence Pack

SIM-E01

Fictional role and approval record

Healthy

Purpose

Support activation, identity scope, cause, containment, and recovery decisions.

Provenance

Identity-role source supplied by the identity owner.

Timing

Event 08:12; collected 08:13; processed 08:14.

Supports

Temporary recovery role remained Active near approval expiration.

Does not prove

Does not prove exercised privilege, group state, or intent.

Access

Incident, identity, evidence, and recovery owners.

Retention

Through corrective-action validation and closure review.

SIM-E02

Fictional privileged-session record

Healthy

Purpose

Support activation, scope, containment, validation, and recovery.

Provenance

Session source supplied by identity and service owners.

Timing

Event 08:18; collected 08:19; processed 08:20.

Supports

One session connected the identity, service, destination, and period.

Does not prove

Does not prove data access or every action within the session.

Access

Incident, identity, service, evidence, and recovery owners.

Retention

Through observation, review, and corrective-action validation.

SIM-E03

Fictional group-source health record

Degraded then Recovering and Conflicting

Purpose

Support effective-access, recovery, source-quality, and reopening decisions.

Provenance

Identity platform owner and source-health monitor.

Timing

Degraded at 08:25; Recovering at 10:40.

Supports

Initial group conclusions require qualification and later reassessment.

Does not prove

Does not prove exact effective state until reconciliation.

Access

Identity, incident, evidence, recovery, and review owners.

Retention

Through historical reconciliation and review closure.

SIM-E04

Fictional service and user-impact record

Service Healthy; user sample Conditional

Purpose

Support continuity, communication, containment side effects, and recovery acceptance.

Provenance

Service-health and user-support sources.

Timing

Service checks 08:31-10:25; user report 08:31.

Supports

No broad outage is confirmed, but limited workflow impact is possible.

Does not prove

Does not represent every user or prove incident causation.

Access

Service, continuity, communications, recovery, and incident owners.

Retention

Through user acceptance and post-incident review.

SIM-E05

Fictional protected-data source limitation

Blind

Purpose

Support privacy, scope, communication, recovery, evidence, and leadership decisions.

Provenance

Data owner and source-health record.

Timing

Blind period begins 08:43.

Supports

Protected-data access remains Unknown for the period.

Does not prove

Supports neither access nor no-access conclusions.

Access

Data, privacy, incident, evidence, communications, and leadership owners.

Retention

Through source recovery, privacy acceptance, and closure review.

SIM-E06

Fictional supplier and queue record

Conditional

Purpose

Support dependency, alternative explanation, communication, data integrity, and recovery.

Provenance

Supplier statement and local integration owner.

Timing

Supplier notice 08:37; queue concern 10:12.

Supports

The integration is delayed and queue reconciliation is required.

Does not prove

Does not prove supplier causation or duplicate records.

Access

Supplier, service, data, privacy, recovery, and incident owners.

Retention

Through reconciliation and supplier corrective action.

SIM-E07

Fictional communication correction record

Healthy

Purpose

Support message accountability, decision correction, and acknowledgement.

Provenance

Approved communications versions 2.1 and 3.2.

Timing

Draft 09:12; distributed then corrected at 09:20.

Supports

The prior unaffected statement was unsupported and explicitly corrected.

Does not prove

Does not prove every recipient changed its decision.

Access

Affected owners, communications, privacy, incident, recovery, and archive reviewers.

Retention

Through acknowledgement, review, and communication corrective action.

SIM-E08

Fictional containment validation record

Healthy for session-level question

Purpose

Support session-level outcome, continuity, recovery preparation, and review.

Provenance

Session, identity, service, monitoring, and decision records.

Timing

Approved 08:57; validated 09:05.

Supports

The confirmed session reached Closed and service continuity remained stable.

Does not prove

Does not prove eradication, complete identity cleanup, or trusted recovery.

Access

Incident, identity, service, recovery, evidence, and review owners.

Retention

Through review and corrective-action validation.

SIM-E09

Fictional recovery gate and canary record

Conditional

Purpose

Support recovery expansion, rollback, user acceptance, and closure readiness.

Provenance

Recovery lead and domain-owner gate records.

Timing

Canary preparation 10:00; workflow failure 10:25.

Supports

Identity sign-in passes while workflow and data-integrity gates fail.

Does not prove

Does not prove all recovery domains failed.

Access

Recovery, service, identity, data, supplier, incident, and leadership owners.

Retention

Through observation and recovery-debt review.

SIM-E10

Fictional exercise observer scorecard

Conditional until observer reconciliation

Purpose

Support hotwash, after-action review, corrective actions, metrics, and exercise redesign.

Provenance

Calibrated observers using versioned criteria.

Timing

Recorded throughout the simulation and finalized after hotwash.

Supports

Shows decision quality, strengths, gaps, missed gates, and action needs.

Does not prove

Does not prove participant capability in every future condition.

Access

Facilitator, program owner, participants, and approved leadership reviewers.

Retention

Through action validation and exercise redesign.

Instructional Section 7

Create Nine Audience-Specific Communications

Initial analyst situation report

Fictional message

Fictional Northbridge confirms identity NB-ID-042, temporary role NB-ROLE-17, session NB-SES-881, service NB-SVC-07, and destination coordination-admin within the current review scope. Intent, protected-data access, broader user impact, device relationship, supplier causation, and complete effective access are not confirmed. Group evidence is Degraded. Owners and next evidence are assigned.

Audience

Incident, technical, identity, service, evidence, privacy, and continuity roles.

Approval

Incident lead with technical and evidence review.

Next update

At the next material scope change or 08:35.

Quality gate

Facts, Unknowns, source health, owners, and next decisions are visible.

Technical owner request

Fictional message

Determine whether recovery-admin provided effective access to NB-ID-042 from 08:00 to 08:30. The group source is Degraded, so identify alternate evidence and state what the result supports and does not prove. A decision-ready response is needed by 09:00 because containment and recovery depend on this question.

Audience

Identity platform owner.

Approval

Technical lead and incident lead.

Next update

Owner acknowledgement within ten fictional minutes.

Quality gate

The question, period, source limitation, deadline, purpose, and decision consequence are bounded.

User advisory

Fictional message

Some users may experience delays when submitting requests. Continue using the service for urgent work and use the published alternate support process if a submission does not complete. Do not submit the same request repeatedly. No broad service interruption is currently confirmed. The next update will be provided at 10:00 or sooner if guidance changes.

Audience

Fictional student-support service users and support staff.

Approval

Service, continuity, accessibility, communications, incident, and privacy reviewers.

Next update

10:00 or meaningful guidance change.

Quality gate

Plain language, safe action, accessibility, support, limitations, and timing pass.

Supplier evidence request

Fictional message

Northbridge requests a bounded status and evidence update for integration NB-SUP-03 from 08:00 to 10:30. Please confirm delay periods, queue behavior, replay or duplication concerns, current service state, and expected recovery timing. This request is limited to the Student Assistance Coordination dependency. Acknowledgement is requested by 09:00.

Audience

Approved fictional supplier role.

Approval

Supplier owner with service, privacy, data, and incident review.

Next update

Escalate if acknowledgement is missed.

Quality gate

Purpose, period, fields, confidentiality, deadline, owner, and escalation are explicit.

Leadership decision brief

Fictional message

One privileged session is confirmed and contained. No broad service interruption is confirmed. Protected-data access is Unknown because the required source is Blind. Group evidence is Degraded, one user delay is possible, and supplier backlog remains unresolved. The recommended decision is to continue narrow containment and hold recovery at Wave 1 until required gates pass.

Audience

Fictional leadership and risk authority.

Approval

Incident lead with service, privacy, recovery, supplier, and communications review.

Next update

At the 10:30 recovery decision or earlier if user guidance changes.

Quality gate

Decision, evidence, uncertainty, mission effect, recommendation, consequence, and next review are clear.

Correction notice

Fictional message

Correction to Update 2.1: the prior message stated that protected-data access was unaffected. That statement was not supported because the required source is Blind for part of the relevant period. The correct current status is Unknown. User guidance is unchanged. Privacy and evidence owners are reviewing alternate records. Decision-owner acknowledgement is required.

Audience

Every fictional recipient of Update 2.1.

Approval

Incident, privacy, communications, and policy owners.

Next update

Acknowledgement review at 09:40.

Quality gate

Prior error, corrected statement, evidence reason, decision effect, unchanged guidance, owner, and next update are explicit.

Recovery wave update

Fictional message

Recovery remains at Wave 1 Conditional. Identity and session canary preparation passes. Group, protected-data, supplier-queue, and critical-user workflow gates remain incomplete. No expansion is authorized. Rollback remains available and the next recovery decision occurs at 10:40.

Audience

Recovery, identity, service, data, supplier, monitoring, continuity, privacy, and leadership roles.

Approval

Recovery and incident leads with required domain owners.

Next update

10:40 or upon a failed break condition.

Quality gate

Passing and failing gates, authority, rollback, and next decision are visible.

Late-evidence reopening notice

Fictional message

Recovered group records conflict with the prior effective-access interpretation. Prior versions remain preserved. Scope, identity recovery, communication, residual-risk, and closure records are reopening for bounded review. No conclusion should be silently replaced. The next approved update follows owner reconciliation.

Audience

Incident, identity, privacy, communications, recovery, evidence, leadership, and closure owners.

Approval

Incident lead with identity and evidence owners.

Next update

At the reconciliation decision or within thirty fictional minutes.

Quality gate

New evidence, affected artifacts, preserved history, owner, and reopening boundary are explicit.

Closure-readiness brief

Fictional message

Session containment and service continuity are validated. Formal closure is not yet recommended because source reconciliation, supplier queue review, corrective-action validation, observation, and one acknowledgement remain open. These obligations have named owners, dates, residual risk, escalation, and reopen triggers.

Audience

Fictional closure authority and leadership.

Approval

Incident lead with recovery, evidence, privacy, service, supplier, and risk review.

Next update

At the next closure-gate review.

Quality gate

Completed and incomplete obligations, owners, risks, and reopen triggers are explicit.

Instructional Section 8

Control Ten Recovery Gates

Identity

Conditional

Entry criteria

Fictional role, group, approval, sponsor, owner, effective access, emergency access, and lifecycle state are current.

Evidence

Role, group, approval, sponsor, owner, session, source-health, and exception records.

Validation

Independent review confirms only approved access remains.

Break condition

Unexpected role, group, approval, owner, or effective-access conflict.

Rollback

Close canary sessions and return to scoped containment.

Sessions

Pass

Entry criteria

Prior fictional sessions are Closed or explicitly accepted.

Evidence

Session identities, services, destinations, start/end times, and containment validation.

Validation

No unexpected active session remains; new canary session matches current authorization.

Break condition

Stale or unexplained session reappears.

Rollback

Close the canary session.

Configuration

Pass

Entry criteria

Fictional identity and service configuration match an approved known-good state.

Evidence

Baseline, change history, owner approval, dependencies, and exceptions.

Validation

Independent comparison shows expected scoped values.

Break condition

Unexpected drift or dependency failure.

Rollback

Return to the prior accepted configuration.

Service

Conditional

Entry criteria

Critical fictional functions, administrative paths, errors, capacity, and dependencies are understood.

Evidence

Service health, function tests, monitoring, continuity, and owner acceptance.

Validation

Critical-user canary completes the required workflow.

Break condition

Critical workflow, capacity, or administrative-state failure.

Rollback

Return users to the alternate process.

Data and privacy

Fail / Unknown

Entry criteria

Fictional data categories, access, integrity, queues, transfers, source limitations, and privacy acceptance are documented.

Evidence

Data source, alternate evidence, queue state, privacy review, and integrity checks.

Validation

Data state supports the required mission and privacy conclusion.

Break condition

Blind evidence, integrity mismatch, unexplained access, or exposure concern.

Rollback

Freeze the data-dependent recovery wave.

Supplier

Fail / Conditional

Entry criteria

Fictional provider status, local dependency, queue, commitment, fallback, and owner are current.

Evidence

Supplier notice, local integration state, queue, commitment, and validation.

Validation

Integration and queue operate within accepted limits.

Break condition

Queue duplication, missed commitment, privacy issue, or service degradation.

Rollback

Pause the integration and use the local fallback.

Evidence sources

Conditional

Entry criteria

Decision-critical fictional sources are Healthy or their limitations are explicitly accepted.

Evidence

Freshness, completeness, timing, schema, coverage, conflicts, Blind periods, and recovery.

Validation

Required sources support identity, data, supplier, service, and monitoring decisions.

Break condition

A mandatory source becomes Blind, Conflicting, or unable to support a gate.

Rollback

Freeze or narrow the wave.

Dependencies

Pass

Entry criteria

Fictional identity, service, supplier, data, continuity, communication, monitoring, and owner dependencies are available or have fallbacks.

Evidence

Architecture, owner statements, capacity, supplier state, source health, and fallback tests.

Validation

Dependencies remain stable during the canary.

Break condition

Dependency or fallback failure.

Rollback

Return to the last accepted wave.

Monitoring

Pass

Entry criteria

Fictional monitoring can observe expected state, break conditions, source health, user impact, and recovery milestones.

Evidence

Detection logic, dashboards, source health, routing, owners, and test signals.

Validation

Expected canary signals and break conditions remain visible.

Break condition

Blind monitoring, missed signal, or unowned alert.

Rollback

Freeze expansion until visibility returns.

Business and user acceptance

Fail

Entry criteria

Fictional critical users, accessibility, alternate workflows, capacity, deadlines, and limitations are understood.

Evidence

Canary tests, support reports, backlog, accessibility review, and owner acceptance.

Validation

Critical users complete essential tasks within accepted quality and timing.

Break condition

Critical workflow, accessibility, queue, or guidance failure.

Rollback

Return users to the alternate workflow.

Instructional Section 9

Score Eight Exercise Dimensions

Preparation and roles

Excellent

Fictional primary and alternate owners acknowledge authority, limits, decision clocks, evidence needs, and handoffs.

Developing

Roles exist but alternates, authority, or handoffs are incomplete.

Unsafe or ineffective

Participants act outside role authority or use real systems.

Evidence

Role chart, acknowledgements, alternate activation, and observer notes.

Evidence and source health

Excellent

Fictional evidence is purposeful, traceable, time-aware, source-qualified, and linked to supports plus limitations.

Developing

Evidence is present but timing, provenance, source health, or non-proof statements are incomplete.

Unsafe or ineffective

Missing evidence becomes proof or real evidence is introduced.

Evidence

Evidence register, chronology, source-health matrix, custody, and corrections.

Scoping

Excellent

Fictional confirmed, possible, Unknown, unaffected, excluded, and out-of-scope categories are versioned and evidence-supported.

Developing

Categories exist but relationships, confidence, owners, or next evidence are weak.

Unsafe or ineffective

All related entities are labeled affected.

Evidence

Scope register, relationship map, versions, owners, and change log.

Prioritization and containment

Excellent

Fictional options are compared and the narrowest effective authorized action is validated with continuity and rollback.

Developing

A reasonable action is selected but options, side effects, or validation are incomplete.

Unsafe or ineffective

The broadest action is automatic or authority is invented.

Evidence

Decision matrix, approval, expected state, validation, continuity, and residual risk.

Communication and privacy

Excellent

Fictional messages are accurate, audience-specific, approved, versioned, corrected, acknowledged, privacy-aware, and actionable.

Developing

Messages are mostly accurate but audience, approval, accessibility, acknowledgement, or next update is weak.

Unsafe or ineffective

Blind data is called unaffected or sensitive detail is shared unnecessarily.

Evidence

Message set, approvals, distribution, acknowledgements, corrections, and privacy review.

Evidence preservation

Excellent

Fictional preservation is purpose-based, minimum necessary, authorized, access-controlled, retained, and correction-ready.

Developing

Evidence is registered but access, transfer, retention, or disposition is incomplete.

Unsafe or ineffective

Preserve everything forever or operational collection is attempted.

Evidence

Preservation charter, register, custody, access, retention, and transfer records.

Recovery

Excellent

Fictional clean-state gates, canary waves, validation, rollback, user acceptance, supplier reconciliation, and observation control restoration.

Developing

Recovery is staged but one domain owner, gate, or rollback detail is weak.

Unsafe or ineffective

Service availability is called full recovery or failed mandatory gates are ignored.

Evidence

Recovery plan, gate matrix, canary results, rollback, observation, and acceptance.

Review and improvement

Excellent

Fictional strengths and gaps become owned, testable, validated, measurable actions with residual risk and reopening.

Developing

Lessons exist but actions, alternates, validation, or escalation are incomplete.

Unsafe or ineffective

The review assigns unsupported blame or closes actions at implementation.

Evidence

Hotwash, after-action review, action register, tests, metrics, debt, and risk.

Instructional Section 10

Validate Sixteen Simulation Scenarios

CaseTypeFictional inputExpected resultQuality protected
SIM-T01Role unavailableA fictional primary identity owner is unavailable at exercise start.Activate the documented alternate, record acknowledgement, authority, and any readiness debt.Role continuity
SIM-T02Alert uncertaintyA fictional alert shows stale authority and one administrative session.Activate bounded coordination without claiming intent, data access, or complete impact.Activation quality
SIM-T03Degraded group sourceFictional effective-access evidence is delayed and incomplete.Keep identity conclusions Conditional and assign alternate evidence plus source recovery.Source-health honesty
SIM-T04One user reportOne fictional staff user reports a delayed submission.Classify possible limited impact and activate continuity review without broad outage language.Impact accuracy
SIM-T05Blind data sourceA fictional draft says no protected data was affected.Reject the statement, classify status as Unknown, and prepare an accurate approved update.Privacy and evidence
SIM-T06Broad containment requestLeadership asks whether the entire fictional service should pause.Compare narrower options, mission effect, authority, validation, rollback, and residual risk.Proportional containment
SIM-T07Preserve everything requestA fictional responder wants every user and supplier record indefinitely.Replace the request with purpose-based minimum-necessary preservation and retention.Evidence governance
SIM-T08Supplier delayA fictional provider reports slow integration responses but causation is unconfirmed.Send a bounded request, preserve local evidence, assign deadlines, and avoid blame.Supplier coordination
SIM-T09Service reachableThe fictional service responds while data, supplier, group, and user gates remain incomplete.Keep recovery Conditional and block or narrow expansion.Recovery integrity
SIM-T10Canary workflow failureA fictional canary signs in but cannot complete the critical workflow.Freeze expansion, preserve evidence, investigate, and roll back or revise.Staged recovery
SIM-T11Late conflicting evidenceRecovered fictional group records challenge an earlier conclusion.Preserve history, issue corrections, update affected decisions, and reopen bounded review.Historical continuity
SIM-T12Blame requestLeadership asks which fictional person caused the incident.Redirect to evidence, decision-time context, system conditions, accountability, and actions.Blameless review
SIM-T13Green closure metricFictional closure speed improves while quality samples lack owner validation.Preserve the speed result but reject the complete improvement claim and revise gates.Balanced measurement
SIM-T14Action implementedA fictional corrective action updates a playbook but has not been tested.Keep it In validation until outcome evidence and owner acceptance exist.Improvement quality
SIM-T15Closure pressureFictional containment is stable but source, supplier, action, and observation obligations remain open.Maintain Conditional closure readiness with owners, dates, risk, escalation, and reopen triggers.Closure governance
SIM-T16Public portfolioA student plans to adapt a real incident exercise package.Fail portfolio validation and invent every organization, role, system, record, action, metric, date, and outcome.Confidentiality and safety

Fictional Simulation Architecture

Northbridge Full-Lifecycle Exercise Model

This architecture is entirely fictional and non-operational. It teaches incident-response coordination without real identities, systems, suppliers, communications, evidence, contacts, architecture, procedures, or incidents.

Readiness inputs

Charter, roles, alternates, authority, playbooks

Evidence inputs

Records, provenance, chronology, health, limitations

Mission inputs

Services, users, privacy, suppliers, continuity

Decision inputs

Scope, options, validation, rollback, risk

Fictional Simulation Core

Activate

Evidence, urgency, ownership, decision clock

Scope

Confirmed, possible, Unknown, unaffected, excluded

Contain

Options, authority, continuity, validation, rollback

Communicate

Audience, facts, uncertainty, guidance, correction

Preserve

Purpose, provenance, access, custody, retention

Recover

Clean state, canary, gates, rollback, observation

Review

Strengths, gaps, lessons, actions, risk

Improve

Metrics, validation, recurrence, debt, retirement

Responder output

Scope, decisions, actions, communications

Recovery output

Gates, canary, acceptance, observation

Program output

Review, actions, metrics, debt, risk

Portfolio boundary

Fully fictional, safe, non-operational

Fake Dashboard

Fake Northbridge Incident Response Simulation Dashboard

Fictional role activation, source health, scope quality, containment, communication, preservation, recovery, review, action validation, and exercise debt.

Material fictional decisions completed

10 / 10

Every decision includes evidence, authority, rationale, expected state, validation, rollback, and residual risk.

Mandatory fictional recovery gates passing

5 / 10

Identity, service, data, supplier, and user gates remain Conditional or failed, so expansion is blocked.

Open fictional exercise debt

8

Alternate ownership, source recovery, correction acknowledgement, supplier reconciliation, accessibility, recovery validation, action testing, and metric redesign remain open.

Fake SOC Alert

Recovery Expansion and Closure Are Blocked

Source: Fake Northbridge Simulation Control Console • Time: 10:25 AM

High Severity
The fictional identity canary can sign in, but the critical submission workflow fails. Protected-data evidence is Blind, supplier queue state is Conditional, group evidence is Recovering and Conflicting, and one decision-changing correction lacks complete acknowledgement.
Defensive recommendation: Freeze fictional recovery expansion, preserve evidence, maintain the alternate workflow, reconcile group and supplier records, complete correction acknowledgement, and keep closure readiness Conditional.

Fake Log Panel

Fake Incident Response Simulation Timeline

training-log-viewer.log
08:00 EXERCISE status='started'
08:12 ROLE state='active-near-expiration'
08:18 SESSION destination='coordination-admin'
08:25 SOURCE group='degraded'
08:31 USER impact='possible-limited'
08:37 SUPPLIER state='conditional'
08:43 SOURCE data='blind'
08:57 CONTAINMENT action='session-close'
09:05 VALIDATION session='closed'
09:20 CORRECTION version='3.2'
09:30 PRESERVATION request='overbroad'
10:12 SUPPLIER queue='unreconciled'
10:25 RECOVERY canary='failed-workflow'
10:40 SOURCE group='recovering-conflicting'
11:00 CLOSURE status='conditional'
11:20 HOTWASH status='started'

Training note: this is fake data for defensive analysis practice only.

Fictional Evidence Matrix

What the Simulation Evidence Supports—and What It Does Not Prove

SIM-E01

Fictional role and approval record

Supports

Temporary recovery role remained Active near approval expiration.

Does not prove

Does not prove exercised privilege, group state, or intent.

Provenance and timing

Identity-role source supplied by the identity owner. Event 08:12; collected 08:13; processed 08:14.

Governance

Access: Incident, identity, evidence, and recovery owners. Retention: Through corrective-action validation and closure review.

SIM-E02

Fictional privileged-session record

Supports

One session connected the identity, service, destination, and period.

Does not prove

Does not prove data access or every action within the session.

Provenance and timing

Session source supplied by identity and service owners. Event 08:18; collected 08:19; processed 08:20.

Governance

Access: Incident, identity, service, evidence, and recovery owners. Retention: Through observation, review, and corrective-action validation.

SIM-E03

Fictional group-source health record

Supports

Initial group conclusions require qualification and later reassessment.

Does not prove

Does not prove exact effective state until reconciliation.

Provenance and timing

Identity platform owner and source-health monitor. Degraded at 08:25; Recovering at 10:40.

Governance

Access: Identity, incident, evidence, recovery, and review owners. Retention: Through historical reconciliation and review closure.

SIM-E04

Fictional service and user-impact record

Supports

No broad outage is confirmed, but limited workflow impact is possible.

Does not prove

Does not represent every user or prove incident causation.

Provenance and timing

Service-health and user-support sources. Service checks 08:31-10:25; user report 08:31.

Governance

Access: Service, continuity, communications, recovery, and incident owners. Retention: Through user acceptance and post-incident review.

SIM-E05

Fictional protected-data source limitation

Supports

Protected-data access remains Unknown for the period.

Does not prove

Supports neither access nor no-access conclusions.

Provenance and timing

Data owner and source-health record. Blind period begins 08:43.

Governance

Access: Data, privacy, incident, evidence, communications, and leadership owners. Retention: Through source recovery, privacy acceptance, and closure review.

SIM-E06

Fictional supplier and queue record

Supports

The integration is delayed and queue reconciliation is required.

Does not prove

Does not prove supplier causation or duplicate records.

Provenance and timing

Supplier statement and local integration owner. Supplier notice 08:37; queue concern 10:12.

Governance

Access: Supplier, service, data, privacy, recovery, and incident owners. Retention: Through reconciliation and supplier corrective action.

SIM-E07

Fictional communication correction record

Supports

The prior unaffected statement was unsupported and explicitly corrected.

Does not prove

Does not prove every recipient changed its decision.

Provenance and timing

Approved communications versions 2.1 and 3.2. Draft 09:12; distributed then corrected at 09:20.

Governance

Access: Affected owners, communications, privacy, incident, recovery, and archive reviewers. Retention: Through acknowledgement, review, and communication corrective action.

SIM-E08

Fictional containment validation record

Supports

The confirmed session reached Closed and service continuity remained stable.

Does not prove

Does not prove eradication, complete identity cleanup, or trusted recovery.

Provenance and timing

Session, identity, service, monitoring, and decision records. Approved 08:57; validated 09:05.

Governance

Access: Incident, identity, service, recovery, evidence, and review owners. Retention: Through review and corrective-action validation.

SIM-E09

Fictional recovery gate and canary record

Supports

Identity sign-in passes while workflow and data-integrity gates fail.

Does not prove

Does not prove all recovery domains failed.

Provenance and timing

Recovery lead and domain-owner gate records. Canary preparation 10:00; workflow failure 10:25.

Governance

Access: Recovery, service, identity, data, supplier, incident, and leadership owners. Retention: Through observation and recovery-debt review.

SIM-E10

Fictional exercise observer scorecard

Supports

Shows decision quality, strengths, gaps, missed gates, and action needs.

Does not prove

Does not prove participant capability in every future condition.

Provenance and timing

Calibrated observers using versioned criteria. Recorded throughout the simulation and finalized after hotwash.

Governance

Access: Facilitator, program owner, participants, and approved leadership reviewers. Retention: Through action validation and exercise redesign.

Analyze the Evidence

Which Full-Lifecycle Decision Is Best Supported?

The confirmed privileged session is Closed.
The service remains reachable.
The group source is Recovering and Conflicting.
Protected-data evidence remains Blind.
The supplier queue remains unreconciled.
The critical-user canary workflow failed.
One decision-changing correction lacks complete acknowledgement.
Several corrective actions remain unvalidated.

Which fictional response decision best fits the current Northbridge simulation evidence?

Common Mistakes

Avoid Twelve Simulation Errors

The simulation becomes a technical puzzle

Fictional observation

Participants focus only on identifying the fictional system condition.

Impact

Roles, authority, continuity, privacy, communication, evidence, recovery, leadership, and improvement disappear.

Professional correction

Score the complete incident-response lifecycle, not one technical answer.

Controllers coach the answer

Fictional observation

The fictional controller explains which containment or recovery decision participants should choose.

Impact

The exercise no longer measures participant reasoning or playbook quality.

Professional correction

Controllers provide approved injects and clarifications, not hidden solutions.

Every inject becomes confirmed scope

Fictional observation

A fictional supplier mention, user report, device relationship, and Blind source are all labeled affected.

Impact

Scope becomes inflated and decisions lose evidence discipline.

Professional correction

Use confirmed, possible, Unknown, unaffected, excluded, and out-of-scope categories.

The broadest action looks strongest

Fictional observation

Participants pause the fictional service before comparing session, role, function, supplier, and continuity options.

Impact

Mission disruption and evidence loss may exceed the supported risk.

Professional correction

Require an option matrix, authority, expected state, validation, rollback, and residual risk.

One message goes to everyone

Fictional observation

Fictional users receive raw identifiers while leadership receives unstructured technical detail.

Impact

Recipients lack the guidance or decision information they need and sensitive details spread.

Professional correction

Tailor audience, purpose, facts, uncertainty, guidance, approval, and next update.

Preservation means unlimited collection

Fictional observation

Participants preserve every fictional record with no question, owner, access, or retention.

Impact

Privacy, review burden, custody, and evidence debt grow.

Professional correction

Use bounded purpose, minimum necessary scope, provenance, access, retention, and disposition.

Service availability becomes recovery

Fictional observation

The fictional page loads, so recovery is marked Complete.

Impact

Identity, data, supplier, source, user, monitoring, and privacy gates are ignored.

Professional correction

Require multi-domain clean state, canary validation, rollback, observation, and acceptance.

Late evidence silently replaces history

Fictional observation

Recovered fictional records overwrite the prior scope and decision.

Impact

Reviewers cannot reconstruct what was known or why earlier decisions occurred.

Professional correction

Preserve prior versions, issue corrections, update affected decisions, and reopen when required.

The hotwash ends the improvement lifecycle

Fictional observation

Fictional lessons are written but no owners, due dates, tests, or escalation exist.

Impact

Exercise insight does not become program change.

Professional correction

Create governed corrective actions and track them through validation and acceptance.

Scores become personal rankings

Fictional observation

Fictional participant scores are used to compare individuals without role, case, collaboration, or source context.

Impact

People may hide uncertainty, avoid difficult decisions, and game the exercise.

Professional correction

Use scoring to improve systems, training, playbooks, sources, and team capability.

Green metrics replace observer evidence

Fictional observation

A fictional time target passes even though observers record missing validation and privacy errors.

Impact

The exercise rewards speed over trustworthy outcomes.

Professional correction

Pair every metric with quality gates and evidence review.

Real information enters the simulation

Fictional observation

A student adapts a real alert, architecture, contact list, incident email, recovery plan, or dashboard.

Impact

Sensitive systems, identities, incidents, suppliers, and response capability may remain identifiable.

Professional correction

Invent every organization, role, service, source, record, action, message, metric, date, and outcome.

Safe Fictional Capstone Lab

Run the Complete Northbridge Incident Response Simulation

Use only invented Northbridge information. Do not access, test, scan, monitor, investigate, alter, contain, preserve, recover, or communicate about any real identity, system, service, device, data set, supplier, organization, incident, or person.
1

Approve the fictional simulation charter

Define purpose, audience, scope, roles, controllers, observers, authority, confidentiality, safety, scoring, pause conditions, outputs, and timeline.

Required output

Simulation charter and role matrix.

Quality check

The exercise is fully fictional, defensive, non-operational, and bounded.

2

Prepare the fictional master scenario events list

Sequence role, alert, source-health, user, supplier, privacy, containment, recovery, late-evidence, review, and metrics injects.

Required output

Twenty-event scenario timeline.

Quality check

Each inject has purpose, evidence, expected decisions, observer focus, and break conditions.

3

Build the fictional evidence pack

Create role, session, group, service, data, supplier, communication, containment, recovery, and observer records.

Required output

Ten-item evidence register.

Quality check

Every item has purpose, provenance, timing, source health, supports, limitations, access, and retention.

4

Run activation and scoping

Assign fictional owners and create the first versioned confirmed, possible, Unknown, unaffected, excluded, and out-of-scope register.

Required output

Activation record and scope register.

Quality check

No alert, relationship, report, or missing record becomes an unsupported conclusion.

5

Run priority and containment decisions

Compare fictional monitoring, session, role, identity, function, supplier, and service options.

Required output

Containment decision package.

Quality check

The selected action is authorized, precise, validated, continuity-aware, reversible, and risk-owned.

6

Run communication and preservation

Create fictional analyst, user, supplier, privacy, leadership, correction, recovery, and closure updates while preserving minimum-necessary evidence.

Required output

Communication and evidence package.

Quality check

Versions, approvals, acknowledgements, corrections, custody, access, and retention remain visible.

7

Run eradication and recovery

Build fictional cause, clean-state gates, canary waves, validation, rollback, user acceptance, supplier reconciliation, observation, and reopen triggers.

Required output

Recovery decision package.

Quality check

Service availability cannot override failed mandatory gates.

8

Run late-evidence and reopening

Introduce fictional recovered group records and trace every affected scope, message, recovery, risk, evidence, and closure decision.

Required output

Correction-propagation and reopening record.

Quality check

Prior versions remain preserved and affected owners acknowledge the change.

9

Run hotwash and after-action review

Capture fictional strengths, gaps, decision-time context, lessons, actions, validation, debt, residual risk, and leadership needs.

Required output

After-action and corrective-action package.

Quality check

Blameless learning remains accountable, specific, owned, and testable.

10

Build the improvement dashboard

Measure fictional role activation, evidence quality, scope, containment, communication, preservation, recovery, review, action validation, recurrence, and gaming risk.

Required output

Balanced exercise dashboard.

Quality check

Speed and completion values cannot pass without quality gates.

11

Prepare the leadership readout

Summarize fictional mission effect, strengths, gaps, source limitations, decisions, actions, resources, residual risk, closure, and reopening.

Required output

Leadership simulation brief.

Quality check

Every leadership ask is bounded, evidence-supported, owned, and time-sensitive.

12

Prepare the portfolio package

Combine charter, roles, timeline, evidence, scope, decisions, communications, preservation, recovery, review, metrics, debt, reflection, and public-safe boundary.

Required output

Incident Response Simulation Package.

Quality check

No real incident, system, identity, supplier, contact, architecture, evidence, or response procedure appears.

Scenario Decision Lab

The Service Is Reachable but the Recovery Story Is Not Trustworthy

Fictional Northbridge has closed the confirmed session and restored service availability. The group source is Recovering and Conflicting, protected-data evidence is Blind, the supplier queue is unreconciled, the critical-user canary failed, and one correction acknowledgement remains incomplete.

Scenario Decision Lab

Late Evidence Challenges the Nearly Closed Case

Recovered fictional group records conflict with the prior effective-access interpretation after leadership has requested closure and the final dashboard is already green.

Advanced Challenge

Defend the Entire Simulation before an Incident Governance Board

The fictional board asks whether Northbridge activated correctly, scoped accurately, contained proportionately, protected users and privacy, preserved evidence responsibly, recovered safely, corrected communication, responded to late evidence, learned without blame, measured improvement honestly, and can now close.

Defend activation and scope

Explain fictional alert facts, source health, relationships, categories, confidence, owners, next evidence, and decision clocks.

Defend containment

Explain fictional options, authority, mission effect, expected state, validation, rollback, side effects, and residual risk.

Defend communication and privacy

Explain fictional audiences, facts, Unknowns, guidance, approvals, versions, correction, acknowledgement, and minimum necessary detail.

Defend preservation and recovery

Explain fictional purpose, provenance, access, retention, clean-state gates, canary failure, rollback, observation, and acceptance.

Defend review and improvement

Explain fictional strengths, gaps, decision-time context, lessons, actions, validation, metrics, debt, and recurrence.

Defend closure or reopening

Explain fictional source reconciliation, supplier obligations, action status, residual risk, observation, correction, archive, and reopen triggers.

Challenge output

Produce a fictional simulation charter, ten-role matrix, twenty-inject timeline, ten-entity scope register, ten-decision log, ten-item evidence pack, nine-message communication set, preservation plan, ten-gate recovery matrix, observer scorecard, sixteen validation cases, hotwash, after-action review, corrective-action register, metrics dashboard, debt register, leadership recommendation, closure decision, reopen triggers, and public portfolio boundary.

Defender Habits

Incident Response Simulation Checklist

Check Your Understanding

A7.10 Mini Quiz: Incident Response Simulation Lab

Choose your answers first. Explanations appear only after submission.

1. What is the strongest purpose of the fictional A7.10 simulation?

2. A fictional group source is Degraded. What should happen?

3. Which fictional containment decision is strongest when one session is confirmed and broad service impact is not?

4. The protected-data source is Blind. Which communication is strongest?

5. A fictional service responds, but mandatory data and user gates fail. What should recovery do?

6. Recovered fictional evidence conflicts with a prior decision. What is strongest?

7. Which public portfolio approach is safest?

Portfolio Prompt

Portfolio Prompt

Create a fully fictional Incident Response Simulation Package for the Northbridge Student-Support Cooperative. Include simulation purpose, audience, charter, exercise boundary, confidentiality, pause authority, controller, facilitator, observers, participants, primary roles, alternate roles, authority, evidence needs, deliverables, failure patterns, master scenario events list, inject IDs, inject times, source-health changes, decision clocks, observer prompts, preparation, activation, detection, initial scope, confirmed entities, possible entities, Unknown entities, unaffected entities, excluded entities, out-of-scope entities, relationship classes, source health, confidence, limitations, owners, next evidence, priority, containment options, selected action, authority, expected state, validation, rollback, continuity, user impact, accessibility, privacy, supplier coordination, communication audiences, analyst update, technical request, user advisory, supplier request, leadership brief, correction notice, recovery update, reopening notice, closure brief, evidence purpose, provenance, event time, collection time, processing time, decision time, access, custody, transfer, retention, disposition, supports, non-proof statements, trigger, immediate cause, root cause, contributing conditions, control gaps, recovery complications, known-good state, identity gates, session gates, configuration gates, service gates, data gates, supplier gates, source gates, dependency gates, monitoring gates, business gates, canary waves, failed gates, rollback, observation, acceptance, break conditions, late evidence, correction propagation, reopening, hotwash, post-incident review, strengths, gaps, lessons, corrective actions, primary owners, alternate owners, due dates, dependencies, validation tests, residual risk, exercise scorecard, role metrics, evidence metrics, scope metrics, containment metrics, communication metrics, preservation metrics, recovery metrics, review metrics, action-validation metrics, recurrence, gaming review, exercise debt, leadership readout, closure recommendation, archive, reopen triggers, reflection, and a statement that every organization, role, identity, service, source, supplier, record, action, message, metric, date, and outcome is invented.

Keep the fictional simulation focused on decision quality, ownership, evidence, mission protection, validation, and learning rather than guessing one hidden answer.
Make fictional source health visible in every scope, communication, containment, recovery, metric, and closure decision.
Preserve fictional prior versions and correction history when late evidence changes the response.
Keep fictional implementation, validation, acceptance, completion, closure, and reopening separate.
Keep the package completely fictional, defensive, non-operational, privacy-safe, evidence-aware, maintainable, and suitable for a public learning portfolio.

Confidence / Readiness Reflection

Are You Ready for the A7 Module Test?

Rate your readiness from 1 to 5 for preparation, roles, activation, evidence, source health, scoping, priority, containment, continuity, communication, privacy, preservation, cause, recovery, validation, late evidence, review, corrective actions, metrics, closure, reopening, and complete fictionalization.

I can coordinate the fictional incident lifecycle without reducing it to one technical answer.
I can keep fictional facts, conclusions, Unknowns, source health, and non-proof statements separate.
I can defend fictional containment and recovery decisions with authority, validation, rollback, continuity, and risk.
I can create fictional audience-specific communications and explicit corrections.
I can preserve fictional evidence responsibly without teaching invasive collection.
I can respond to fictional failed recovery gates and late conflicting evidence.
I can convert fictional exercise observations into validated improvement actions and balanced metrics.
I can produce a safe fictional capstone package without adapting any real incident material.
Record one fictional activation decision, one scope uncertainty, one containment option, one user or privacy need, one preservation boundary, one failed recovery gate, one late-evidence correction, one corrective action, one quality-gated metric, and one area to review before the module test.

Key Takeaways

What You Should Remember

1.A fictional incident-response simulation should evaluate the full lifecycle, not one technical answer.
2.Roles, alternates, authority, evidence needs, deliverables, handoffs, and pause conditions belong before the first inject.
3.Confirmed, possible, Unknown, unaffected, excluded, and out-of-scope entities require separate fictional evidence and ownership.
4.Healthy, Conditional, Degraded, Blind, Conflicting, and Recovering source states should change fictional decisions and confidence.
5.The strongest fictional containment is the narrowest authorized action that reduces supported risk and passes validation, continuity, rollback, and residual-risk review.
6.Fictional communications should be audience-specific, privacy-aware, approved, versioned, actionable, corrected, acknowledged, and tied to the next update.
7.Fictional evidence preservation requires purpose, authority, minimum necessary scope, provenance, timing, access, custody, retention, limitations, and decision use.
8.Service availability is not fictional trusted recovery; clean-state gates, canary validation, rollback, user acceptance, observation, and source health remain essential.
9.Late fictional evidence should preserve history, correct connected records, obtain acknowledgement, and reopen affected decisions when required.
10.Hotwash findings become improvement only when fictional actions are owned, validated, measured, monitored, and connected to risk and reopening.
11.Speed, volume, closure, and completion metrics require fictional quality gates and gaming review.
12.Every CyberShield simulation artifact must remain fully fictional, authorized, defensive, non-operational, privacy-safe, and incapable of exposing real incidents, systems, people, suppliers, evidence, or response capabilities.

Navigation

Complete Module A7

You have completed all ten Incident Response Lifecycle lessons. Continue to the module test to assess preparation, roles, playbooks, activation, evidence, source health, scoping, priority, containment, recovery, communication, preservation, review, metrics, closure, and reopening.