P — Purpose
Define the fictional scenario, mission question, supported decisions, users, exclusions, and safety boundary.
Learn how fictional response teams transform mission, authority, evidence, source health, containment, continuity, communication, recovery, validation, rollback, closure, reopening, ownership, and exercises into usable plans and playbooks.
Lesson Progress
High School Advanced • A7: Incident Response Lifecycle • Lesson 2 of 10
Readiness Check
0/6 ready
Professional Hook
A fictional playbook says: “If a critical alert appears, isolate the service, notify everyone, restore from backup, and close when the service responds.” During a tabletop, the source is Blind, the service supports urgent student assistance, the supplier contact is stale, recovery has not been validated, and the incident lead is unavailable. The document contains steps but not the decisions needed for safe response.
Weak playbook
“Follow the same steps quickly whenever the alert appears.”
Strong playbook
“Use activation criteria, bounded questions, source-health branches, authorized options, continuity tradeoffs, validation, rollback, and lifecycle gates.”
Exactly Five Learning Objectives
Objective 1
Distinguish fictional incident response policy, plan, playbook, checklist, reference, contact list, decision record, and evidence register by purpose and level of detail.
Objective 2
Design fictional playbooks with activation criteria, roles, bounded questions, evidence, source-health behavior, branches, containment, continuity, communication, recovery, validation, rollback, closure, and reopening.
Objective 3
Evaluate fictional playbooks for rigid scripting, missing authority, stale assumptions, untested branches, absent privacy boundaries, weak recovery gates, and unclear ownership.
Objective 4
Create fictional tabletop exercises that test decisions, handoffs, owner unavailability, source degradation, scope change, containment tradeoffs, supplier delays, communication, recovery, and improvement.
Objective 5
Create a portfolio-ready fictional Preparation and Playbook Design Package containing a response plan, scenario playbooks, activation matrix, evidence map, exercise record, validation cases, version history, debt register, and reflection.
Why This Matters
Fictional response becomes safer when teams decide in advance who has authority, which evidence is needed, how source health changes conclusions, which continuity options exist, how containment is validated, who approves communication, what proves recovery, and when closure or reopening is justified.
Activation, containment, communication, recovery, and closure criteria are defined before urgency distorts judgment.
Roles, contacts, sources, suppliers, branches, recovery gates, and fallbacks are exercised rather than trusted on paper.
Owners, versions, approvals, expiration, debt, corrective actions, and retest prevent silent decay.
Core Framework
Define the fictional scenario, mission question, supported decisions, users, exclusions, and safety boundary.
Document entry conditions, activation levels, roles, authority, alternates, and escalation.
List observation, authorization, service, impact, source-health, scope, supplier, privacy, continuity, and recovery questions.
Map sources, fields, provenance, timing, health, alternate evidence, privacy, retention, and limitations.
Create Expected, Source-Degraded, Containment, Continuity, Supplier, Leadership, Recovery, Closure, and Reopen paths.
Compare choices using authority, benefit, cost, dependencies, evidence effect, continuity, validation, rollback, and risk.
Define expected state, validation evidence, monitoring, owner acceptance, failure triggers, and rollback.
Assign owner, version, approval, exercises, corrective actions, expiration, debt, archive, and replacement.
Advanced Vocabulary
A fictional high-level statement of purpose, authority, scope, responsibilities, governance, and minimum program expectations.
A fictional organization-wide framework describing preparation, activation, coordination, evidence, containment, communication, recovery, closure, and improvement.
A fictional scenario-focused decision guide containing triggers, questions, roles, evidence, branches, options, validation, rollback, communication, continuity, and lifecycle steps.
A fictional concise list used to confirm required evidence, actions, approvals, or validation without replacing judgment.
A fictional supporting document containing definitions, maps, source details, decision criteria, role information, or communication templates.
A fictional readiness record containing primary owners, alternates, authority, availability, escalation, and review dates.
A fictional log of the question, options, evidence, uncertainty, owner, authority, selected action, rationale, validation, and review trigger.
A fictional record of evidence identity, source, purpose, provenance, timing, health, integrity, access, custody, retention, and case use.
A fictional condition that triggers routine review, incident coordination, specialist escalation, leadership review, source recovery, or another workflow.
A fictional moment at which evidence, source health, scope, authority, continuity, privacy, impact, or recovery requires an explicit choice.
A fictional condition that moves a playbook into a different path based on evidence or mission context.
A fictional requirement that must be true before a playbook or phase begins.
A fictional requirement that must be satisfied before a response phase ends.
A fictional required evidence, approval, validation, source-health, privacy, continuity, or lifecycle check.
A fictional planning belief that must be documented, tested, reviewed, and changed when evidence or conditions change.
A fictional identity, service, platform, source, supplier, data, communication, continuity, or authority condition needed for a response step.
A fictional alternate path used when a primary role, source, service, supplier, communication channel, or recovery method is unavailable.
A fictional discussion-based simulation used to test roles, decisions, evidence, authority, continuity, communication, recovery, and improvement.
A fictional new fact, source failure, owner response, scope change, impact update, or constraint introduced during a simulation.
A fictional documented response that should occur when a specific exercise condition appears.
The fictional decision or response actually produced during an exercise.
Fictional unresolved work involving stale roles, missing evidence, untested branches, weak recovery, unclear authority, or outdated assumptions.
A fictional record of playbook changes, owner, reason, date, evidence, test result, approval, and rollback reference.
A fictional date or condition requiring review because mission, services, identities, suppliers, sources, ownership, policy, or architecture may have changed.
Instructional Section 1
Define fictional program authority, scope, governance, responsibilities, required outcomes, and exception rules.
Contains
Purpose, scope, authority, responsibilities, minimum controls, exceptions, review, and accountability.
Boundary
Does not contain live case decisions or detailed scenario steps.
Owner
Program governance or leadership authority.
Describe the fictional organization-wide incident response lifecycle and coordination model.
Contains
Activation, command, roles, evidence, communication, containment, continuity, recovery, closure, reopening, review, and metrics.
Boundary
Does not attempt to contain every scenario branch.
Owner
Incident response program owner.
Guide fictional scenario-specific evidence and decision workflows.
Contains
Triggers, questions, sources, health rules, roles, branches, options, validation, rollback, communication, recovery, and exit criteria.
Boundary
Does not authorize one rigid response for every case.
Owner
Scenario owner with program approval.
Confirm fictional required evidence, actions, approvals, validation, and lifecycle steps.
Contains
Short verification items, status, owner, and completion evidence.
Boundary
Does not replace complex decision reasoning.
Owner
Operational or quality owner.
Provide fictional definitions, service maps, source details, role information, criteria, and templates.
Contains
Definitions, maps, sources, criteria, templates, role details, and review dates.
Boundary
Does not contain unsupported case conclusions.
Owner
Domain owner.
Provide fictional primary owners, alternates, availability, decision rights, and escalation.
Contains
Role, primary, alternate, authority, response expectation, access readiness, escalation, and review date.
Boundary
Public learning versions contain no real contacts.
Owner
Program owner and role owners.
Preserve fictional case-specific reasoning and authority.
Contains
Question, evidence, source health, options, owner, authority, decision, rationale, conditions, validation, and review trigger.
Boundary
Excludes unnecessary personal details and unsupported certainty.
Owner
Incident lead or decision owner.
Preserve fictional evidence traceability and governance.
Contains
Evidence ID, source, purpose, provenance, timing, health, integrity, access, custody, retention, transfer, limitations, and use.
Boundary
Technical interpretation stays in the analysis record.
Owner
Evidence coordinator.
Instructional Section 2
Core question
What fictional condition does the playbook address, and which mission decision does it support?
Required content
Scenario, mission relevance, users, supported decisions, exclusions, and safety boundary.
Weak pattern
A vague title such as suspicious activity with no bounded question.
Core question
Which fictional observations, evidence, health states, reports, impacts, or owner concerns justify activation?
Required content
Routine, incident, specialist, leadership, source-recovery, privacy, continuity, and supplier triggers.
Weak pattern
Every alert automatically becomes a confirmed incident.
Core question
Who coordinates, analyzes, owns decisions, preserves evidence, communicates, maintains continuity, recovers, and accepts risk?
Required content
Primary roles, alternates, decision rights, availability, handoff acceptance, conflicts, and escalation.
Weak pattern
Roles are named without authority or backups.
Core question
Which fictional observation, authorization, identity, service, impact, source-health, supplier, privacy, continuity, and recovery questions matter?
Required content
Bounded questions, evidence, owners, deadlines, affected/possible/unknown categories, and scope-change history.
Weak pattern
Investigate everything related to the alert.
Core question
Which fictional sources, fields, provenance, times, health states, alternatives, and limitations support each decision?
Required content
Source inventory, evidence IDs, event/collection/processing time, health behavior, privacy, retention, and missing-data rules.
Weak pattern
No visible evidence is treated as absence.
Core question
How do consequence, certainty, active impact, scope, time sensitivity, source health, and recoverability affect urgency?
Required content
Separate severity, confidence, priority, rationale, owner, and reassessment triggers.
Weak pattern
Severity alone determines the full response.
Core question
Which fictional containment, continuity, communication, evidence, supplier, privacy, and leadership options exist under different conditions?
Required content
Options, entry conditions, authority, dependencies, benefits, costs, evidence effects, validation, rollback, and break conditions.
Weak pattern
One irreversible action for every case.
Core question
Which fictional audiences need which facts, uncertainty, guidance, approvals, timing, correction, and next update?
Required content
Audience, owner, review, approval, privacy, version, distribution, correction, and next-update commitment.
Weak pattern
One generic message goes to every audience.
Core question
How will fictional critical functions continue, and what proves trustworthy restoration?
Required content
Continuity options, clean-state criteria, dependencies, identity, configuration, data, source recovery, monitoring, rollback, and acceptance.
Weak pattern
Service reachable equals recovered.
Core question
Which fictional evidence and approvals end phases, close the response, reopen it, and keep the playbook current?
Required content
Exit criteria, residual uncertainty, residual risk, corrective actions, reopen triggers, owner, version, expiration, debt, archive, and replacement.
Weak pattern
Alerts stop, so the case and playbook are complete.
Instructional Section 3
Fictional evidence
One fictional alert, Healthy sources, no confirmed impact, narrow scope, and plausible expected alternatives.
Workflow
Routine triage with bounded questions and source-health review.
Authority
Analyst or incident lead within routine authority.
Escalation
Escalate if confidence, scope, impact, source health, or owner deadlines change.
Fictional evidence
Fictional SIEM alert, user reports, service symptoms, or supplier notice align around one mission service.
Workflow
Incident coordination readiness review.
Authority
Incident lead or authorized alternate.
Escalation
Activate when evidence crosses documented mission or coordination criteria.
Fictional evidence
Fictional Healthy service evidence confirms broad user effect or loss of critical function.
Workflow
Incident coordination plus service and continuity activation.
Authority
Incident lead, service owner, and continuity owner.
Escalation
Leadership when containment, resources, continuity, or risk exceed routine authority.
Fictional evidence
Fictional role or session remains active after expiration while authorization evidence is incomplete.
Workflow
Time-sensitive identity and incident coordination.
Authority
Incident lead with identity owner.
Escalation
Alternate owner or leadership if the identity decision deadline is missed.
Fictional evidence
Fictional evidence source is Blind during the key period and affects mission-relevant conclusions.
Workflow
Source-recovery and evidence-limited response path.
Authority
Incident lead with source and affected decision owners.
Escalation
Leadership if evidence loss blocks critical decisions.
Fictional evidence
Fictional evidence suggests unnecessary access, sharing, or exposure of protected information.
Workflow
Incident coordination with privacy and governance review.
Authority
Incident lead and privacy authority.
Escalation
Legal, policy, or leadership authority according to documented triggers.
Fictional evidence
Fictional critical service depends on an external provider and local evidence cannot answer the bounded question.
Workflow
Incident coordination plus supplier escalation.
Authority
Supplier owner with incident lead.
Escalation
Leadership when service continuity, data sharing, contract, or delay creates mission risk.
Fictional evidence
Fictional service is reachable but clean-state, identity, configuration, data, source, or dependency validation fails.
Workflow
Recovery remains Conditional; rollback or continued containment is evaluated.
Authority
Recovery owner with service and incident owners.
Escalation
Leadership if restoration delay or rollback has major mission consequences.
Instructional Section 4
Behavior
Fictional freshness, completeness, schema, parser, queue, timing, and coverage support normal-confidence use.
Playbook rule
Use evidence normally while preserving provenance, scope, and limitations.
Prohibited conclusion
Healthy evidence still does not prove intent or complete scope.
Behavior
Fictional evidence is usable for some questions but limited by delay, partial coverage, stale context, or assumptions.
Playbook rule
Label affected conclusions, request alternate evidence, assign owner, and define reassessment.
Prohibited conclusion
Do not present Conditional evidence as complete.
Behavior
Fictional evidence is materially weakened by delay, missing fields, parser defects, conflicts, or incomplete coverage.
Playbook rule
Reduce confidence, narrow decisions, use alternate evidence, and escalate source repair.
Prohibited conclusion
Do not treat missing records as no activity.
Behavior
Fictional required evidence is unavailable for the relevant population or period.
Playbook rule
Use Source-Degraded or Unknown, activate alternate evidence and recovery, and require historical reassessment.
Prohibited conclusion
Do not claim confirmation, absence, success, or full scope.
Behavior
Fictional sources disagree beyond timing or semantic tolerance.
Playbook rule
Preserve both observations, compare authority, timing, mapping, scope, and ownership, and assign reconciliation.
Prohibited conclusion
Do not choose the preferred source without documented reason.
Behavior
Fictional connectivity is returning but backlog, replay, duplicates, schema, timing, or historical gaps remain.
Playbook rule
Keep recovery obligations open, reconcile affected cases, and delay final closure conclusions.
Prohibited conclusion
Connected does not equal trustworthy recovery.
Instructional Section 5
Entry condition
Fictional identity, service, destination, purpose, owner, approval, timing, and source health match current approved activity.
Fictional action
Document Expected state, preserve visibility, set expiration, monitor break conditions, and record owner confirmation.
Break condition
New identity, session, destination, service, scope, result, time, owner, impact, or source-health change.
Exit criterion
Expected context remains valid through observation or returns to active triage.
Entry condition
A fictional required source is Conditional, Degraded, Blind, Conflicting, or Recovering.
Fictional action
Lower confidence, preserve affected periods, use alternate evidence, assign source owner, and define reassessment.
Break condition
Source recovery, conflicting evidence, wider scope, active impact, or deadline failure.
Exit criterion
Source obligations and historical reassessment support the needed decision.
Entry condition
Fictional privileged authority or active session creates time-sensitive risk under authorization uncertainty.
Fictional action
Compare scoped restriction, session closure, monitoring, continuity, validation, and rollback with identity-owner approval.
Break condition
New identity, service, session, active impact, health change, or broader scope.
Exit criterion
Authorized action is validated and remaining authorization, scope, continuity, and risk work is assigned.
Entry condition
Fictional containment or recovery may interrupt critical users or workflows.
Fictional action
Activate approved alternate workflows, prioritize critical users, communicate limits, monitor capacity, and define transition-back criteria.
Break condition
Worsening impact, capacity failure, dependency loss, privacy issue, supplier failure, or recovery milestone.
Exit criterion
Trusted restoration is accepted and temporary workflows retire safely.
Entry condition
Fictional evidence, service, recovery, or source questions depend on an external provider.
Fictional action
Send purpose-limited request, track commitment, preserve confidentiality, compare evidence, and escalate mission issues.
Break condition
Missed deadline, conflicting evidence, broader impact, data-sharing concern, or continuity risk.
Exit criterion
Dependency resolves, becomes accepted residual risk, or transfers to a long-term owner.
Entry condition
Fictional resource conflict, major interruption, policy exception, public communication, or risk decision exceeds operational authority.
Fictional action
Provide bounded decision, options, evidence, uncertainty, mission impact, recommendations, urgency, and residual risk.
Break condition
Evidence changes, deadline expires, an option disappears, or impact increases.
Exit criterion
Authorized decision is recorded with conditions, owners, review trigger, and communication.
Instructional Section 6
Tests
Alternate authority, activation, handoff, contact readiness, and command continuity.
Expected response
Named alternate accepts the role using the documented transfer checklist.
Tests
Source-health behavior, alternate evidence, confidence, ownership, and reassessment.
Expected response
Authorization becomes Conditional rather than forced into yes or no.
Tests
Scope change, service ownership, severity, priority, communication, and continuity.
Expected response
Scope version updates without assuming the second service is fully affected.
Tests
Containment tradeoff, continuity, authority, alternatives, validation, rollback, and leadership escalation.
Expected response
Team compares narrow and broad options and selects only an authorized evidence-supported path.
Tests
Evidence reconciliation, message approval, uncertainty, correction, and versioning.
Expected response
Incident lead establishes supported wording and assigns a technical decision deadline.
Tests
Supplier escalation, local fallback, continuity, evidence limits, and leadership decision need.
Expected response
Supplier owner activates alternate escalation and the incident lead records decision impact.
Tests
Recovery gates, source reconciliation, data integrity, business acceptance, rollback, and closure.
Expected response
Recovery remains Conditional and closure is blocked.
Tests
Closure authority, risk acceptance, evidence, owner recommendations, and communication.
Expected response
Incident lead presents closure gaps and requires the documented risk authority or continued Conditional state.
Instructional Section 7
Strong behavior
Fictional activation uses evidence, source health, mission relevance, authority, scope, and non-proof statements.
Weak behavior
The alert title alone declares the incident.
Evidence record
Activation record and decision rationale.
Strong behavior
Fictional primary and alternate owners accept bounded responsibilities under documented authority.
Weak behavior
Roles are assigned without acknowledgement, authority, or alternate.
Evidence record
Role roster, handoff log, and decision-rights matrix.
Strong behavior
Fictional evidence includes provenance, timing, source health, supports, limitations, privacy, and purpose.
Weak behavior
Missing evidence becomes absence or raw records are shared broadly.
Evidence record
Evidence register and source-health map.
Strong behavior
Fictional affected, possible, unknown, excluded, and out-of-scope categories are versioned.
Weak behavior
Scope is permanently defined by the first alert.
Evidence record
Scope register and change log.
Strong behavior
Fictional options compare risk reduction, continuity, evidence, authority, reversibility, validation, rollback, and risk.
Weak behavior
The fastest or broadest action is selected automatically.
Evidence record
Containment decision matrix.
Strong behavior
Fictional messages preserve facts, uncertainty, audience need, approvals, privacy, versions, and corrections.
Weak behavior
One message goes to everyone or conflicting statements remain unresolved.
Evidence record
Communication log and approvals.
Strong behavior
Fictional clean-state, identity, configuration, data, source, dependency, monitoring, rollback, and acceptance gates pass.
Weak behavior
Availability alone is treated as recovery.
Evidence record
Recovery and validation checklist.
Strong behavior
Fictional closure, reopening, corrective actions, debt, owners, review, and versioning are complete.
Weak behavior
The exercise ends without improvement or retest.
Evidence record
Closure review, after-action report, and updated playbook.
Instructional Section 8
| Case | Type | Fictional input | Expected result | Quality protected |
|---|---|---|---|---|
| PLAY-T01 | Routine alert | One fictional low-confidence alert, Healthy sources, no impact, and narrow scope. | Use routine triage rather than automatic incident activation. | Proportionate response |
| PLAY-T02 | Multiple evidence categories | Fictional alert, user reports, and service symptoms align around one mission service. | Trigger coordinated response review. | Mission-aware activation |
| PLAY-T03 | Primary unavailable | Fictional incident lead is unavailable. | Authorized alternate accepts command through the handoff process. | Command continuity |
| PLAY-T04 | Blind source | Fictional required source is Blind during the key period. | Follow Source-Degraded branch, alternate evidence, and reassessment. | Evidence honesty |
| PLAY-T05 | Scope expansion | Fictional second service appears after initial scope. | Update scope version, owners, and priority. | Dynamic scoping |
| PLAY-T06 | Containment tradeoff | Fictional broad shutdown interrupts critical support. | Compare narrow, broad, continuity, validation, and rollback options. | Mission continuity |
| PLAY-T07 | Privacy-sensitive evidence | Fictional request includes fields unnecessary for the decision. | Apply minimization and privacy review. | Purpose limitation |
| PLAY-T08 | Supplier delay | Fictional critical supplier misses a response commitment. | Activate supplier escalation and local fallback. | External readiness |
| PLAY-T09 | Recovery incomplete | Fictional service is reachable while data and source validation remain incomplete. | Keep recovery Conditional and block closure. | Trustworthy restoration |
| PLAY-T10 | Stale playbook | Fictional ownership, contacts, and supplier paths changed after review. | Fail readiness validation and update plus retest. | Lifecycle accuracy |
| PLAY-T11 | Closure pressure | Fictional leadership requests closure before residual-risk ownership exists. | Route risk decision to documented authority. | Evidence-based closure |
| PLAY-T12 | Public portfolio | Student plans to adapt a real playbook and contact tree. | Fail portfolio validation and invent every detail. | Confidentiality and safety |
Instructional Section 9
| Field | Purpose | Fictional example |
|---|---|---|
| Playbook identifier | Trace across versions, exercises, cases, approvals, and archive. | IR-PB-NB-004 |
| Version | Identify the fictional approved state. | Version 2.3 |
| Owner | Assign content, testing, review, debt, and retirement accountability. | Incident response program owner |
| Approvers | Record required incident, technical, service, privacy, continuity, evidence, recovery, supplier, and leadership approvals. | Incident lead, service owner, privacy reviewer, recovery owner |
| Change reason | Explain which exercise, incident, source, role, supplier, policy, or architecture change required revision. | Tabletop found missing supplier fallback |
| Affected sections | Identify activation, roles, evidence, branches, communication, recovery, closure, or other sections changed. | Sections 3, 8, 9, and 10 |
| Supporting evidence | Link exercise observations, validation cases, source changes, owner review, or corrective actions. | EX-NB-07 and PLAY-T08 to PLAY-T11 |
| Test result | Document expected and observed behavior after revision. | Supplier delay, recovery gate, and closure cases passed |
| Approval date | Record fictional authorization for use. | Invented date: 2026-08-01 |
| Review and expiration | Prevent use after assumptions or dependencies change. | Review in ninety days or after service, role, source, supplier, policy, or architecture change |
| Rollback reference | Identify the prior validated version if the new version causes defects. | Return to 2.2 if recovery branch validation fails |
| Archive and replacement | Document retirement, replacement coverage, history, and access. | Archive 2.2 read-only after 2.3 approval |
Instructional Section 10
Review question
Do fictional mission-critical scenarios, services, identities, suppliers, privacy concerns, source failures, and recovery conditions have playbooks?
Evidence
Scenario inventory, mission map, service criticality, source map, supplier map, and residual-risk register.
Limitation
A written playbook does not prove readiness.
Review question
Can fictional responders distinguish routine triage, incident coordination, specialist, leadership, source-recovery, and privacy paths?
Evidence
Activation matrix, exercise decisions, false activations, delayed activations, and owner review.
Limitation
Real conditions may not match exercise categories exactly.
Review question
Have fictional Expected, Source-Degraded, Containment, Continuity, Supplier, Leadership, Recovery, Closure, and Reopen paths been tested?
Evidence
Validation cases, injects, observed actions, defects, corrections, and retest.
Limitation
Passing known branches does not cover unknown future conditions.
Review question
Do fictional playbook roles have current authority, alternates, access, training, contacts, and handoff acceptance?
Evidence
Role roster, alternate map, contact test, access review, and tabletop performance.
Limitation
A tested role may still be unavailable later.
Review question
Are fictional sources, fields, health rules, alternate evidence, privacy, retention, and owners current?
Evidence
Source inventory, schema tests, health exercises, alternate evidence, and review dates.
Limitation
Source behavior can change after review.
Review question
Do fictional exercises test authority, uncertainty, source degradation, scope change, containment, communication, recovery, closure, and improvement?
Evidence
Exercise plan, injects, expected actions, observed actions, scoring, defects, and retest.
Limitation
Discussion success does not prove operational execution.
Review question
How long do fictional exercise and playbook defects remain open?
Evidence
Action owner, due date, mission effect, dependency, evidence, validation, escalation, and closure.
Limitation
Fast closure does not prove the correction worked.
Review question
Which fictional assumptions, roles, contacts, branches, sources, suppliers, recovery gates, tests, approvals, and review dates remain incomplete?
Evidence
Debt register, age, mission effect, owner, due date, priority, escalation, and residual risk.
Limitation
Debt count alone does not show mission impact.
Fictional Preparation Architecture
This conceptual model is completely invented and intentionally non-operational. It teaches preparation without real organizations, contacts, systems, sources, suppliers, incidents, containment actions, or internal procedures.
Mission inputs
Critical services, users, data, privacy, continuity
Readiness inputs
Roles, authority, alternates, contacts, suppliers
Evidence inputs
Sources, fields, health, provenance, timing, limits
Lifecycle inputs
Activation, branches, recovery, closure, review
Fictional Playbook Core
Purpose
Scenario, mission question, users, exclusions
Activation
Entry criteria, authority, roles, alternatives
Questions
Evidence, scope, impact, source health, owners
Branches
Expected, degraded, containment, continuity, supplier
Decisions
Options, authority, cost, validation, rollback
Communication
Audience, facts, uncertainty, approval, correction
Recovery
Clean state, dependencies, monitoring, acceptance
Lifecycle
Exercise, version, expiration, debt, archive
Operational output
Plan, playbooks, checklists, contacts, decisions
Exercise output
Injects, observations, scoring, defects, retest
Leadership output
Coverage, debt, resources, risk, improvement
Portfolio boundary
Fully fictional, privacy-safe, non-operational
Fake Dashboard
Fictional scenario coverage, activation clarity, branch validation, role readiness, evidence-source readiness, exercise quality, action aging, and playbook debt.
Critical fictional scenarios with tested playbooks
6 / 9
Supplier evidence loss, broad source Blindness, and extended recovery still require exercises.
Playbook branches passing validation
11 / 15
Leadership risk, supplier fallback, recovery rollback, and reopen branches remain incomplete.
Open fictional preparation debt
13
Contacts, alternates, health rules, branch tests, supplier path, privacy review, communication correction, recovery gates, closure authority, expiration, rollback, archive, and retest remain open.
Fake SOC Alert
Source: Fake Northbridge Preparedness Governance Console • Time: 10:42 AM
Fake Log Panel
09:00 EXERCISE id='EX-NB-07' 09:02 ALERT confidence='low' 09:05 REPORTS users='2' 09:06 ACTIVATION state='coordinated' 09:10 SOURCE identity='degraded' 09:12 SCOPE service='1' 09:20 INJECT second-service='added' 09:25 CONTAINMENT option='broad-shutdown' 09:27 CONTINUITY review='missing' 09:30 SUPPLIER response='late' 09:45 SERVICE availability='restored' 09:47 IDENTITY validation='incomplete' 09:48 DATA validation='incomplete' 09:49 SOURCE recovery='incomplete' 09:50 RISK owner='missing' 09:51 REOPEN criteria='missing' 09:52 CASE state='closed' 10:42 ALERT issue='playbook-validation-failed'
Training note: this is fake data for defensive analysis practice only.
Fictional Evidence Matrix
Observation
Northbridge has identity and service playbooks but none for supplier evidence loss.
Supports
Supplier-dependent response coverage is incomplete.
Does not prove
Does not prove a supplier event will occur.
Preparation use
Create and test supplier coordination and fallback branches.
Observation
A low-confidence alert and multi-source service-impact condition use the same activation path.
Supports
Activation criteria are too broad.
Does not prove
Does not prove every activation was wrong.
Preparation use
Separate routine triage from coordinated response.
Observation
Playbook says no record means no activity even when the source is Blind.
Supports
The playbook can create false absence.
Does not prove
Does not prove prior cases were misclassified.
Preparation use
Add six source-health states and alternate evidence.
Observation
Responders selected broad shutdown before reviewing continuity or rollback.
Supports
Containment criteria and authority are incomplete.
Does not prove
Does not prove they would always choose that action.
Preparation use
Add option comparison, continuity, validation, rollback, and approvals.
Observation
Two audiences received different impact statements because no message owner was assigned.
Supports
Communication ownership and version control are weak.
Does not prove
Does not determine which statement is correct.
Preparation use
Add communication owner, approval, correction, and next-update rules.
Observation
Service availability is checked, but identity, configuration, data, supplier, source, and monitoring validation are absent.
Supports
Recovery criteria are incomplete.
Does not prove
Does not prove a recovery failed.
Preparation use
Add clean-state and multi-owner validation gates.
Observation
Playbook owner changed, but approval and review records were not updated.
Supports
Current authority and lifecycle are uncertain.
Does not prove
Content may still be technically useful.
Preparation use
Assign current owner, approval, expiration, validation, and debt.
Observation
Team closed after service restoration while one source remained Recovering and risk was unassigned.
Supports
Closure and recovery gates are weak.
Does not prove
Does not prove every closure would be premature.
Preparation use
Add source reconciliation, risk authority, observation, and reopen triggers.
Analyze the Evidence
Common Mistakes
Fictional observation
Team follows one path even when source health, scope, impact, continuity, or authority changes.
Impact
Responders may take inappropriate actions or miss important branches.
Correction
Use decision points, branches, alternatives, validation, and rollback.
Fictional observation
A single low-confidence alert triggers full coordination.
Impact
Resources are consumed and triage disappears.
Correction
Define evidence-based activation and reassessment criteria.
Fictional observation
A missing record is treated as no activity.
Impact
Blind or delayed evidence creates false certainty.
Correction
Document health states, alternatives, confidence changes, and reassessment.
Fictional observation
Tasks are assigned but no one knows who may contain, communicate, recover, close, or reopen.
Impact
Teams delay or exceed authority.
Correction
Link every decision point to rights and escalation.
Fictional observation
The playbook always shuts down the service.
Impact
Continuity, evidence, privacy, users, and recovery may be harmed.
Correction
Compare options with dependencies, validation, rollback, and authority.
Fictional observation
One identical message goes to analysts, users, suppliers, and leadership.
Impact
Audiences receive too much, too little, or unsupported information.
Correction
Use audience-specific facts, uncertainty, approvals, versions, and corrections.
Fictional observation
The playbook closes when connectivity returns.
Impact
Identity, data, source health, monitoring, and risk may remain unresolved.
Correction
Use clean-state, staged validation, observation, rollback, and reopen triggers.
Fictional observation
No inject covers unavailable owners, Blind sources, scope growth, supplier delay, or failed recovery.
Impact
Important branches remain untested.
Correction
Use difficult injects, expected outcomes, defects, owners, and retest.
Fictional observation
Contacts, sources, suppliers, authority, and assumptions remain unchanged on paper.
Impact
The documented process may fail under pressure.
Correction
Assign owner, review, expiration, debt, exercises, and archive.
Fictional observation
A student sanitizes real role names, contacts, service maps, triggers, or steps.
Impact
Sensitive structures and capabilities may remain identifiable.
Correction
Invent every organization, role, service, source, supplier, trigger, action, and outcome.
Safe Fictional Practice Lab
Document fictional critical services, users, identity, data, suppliers, continuity, privacy, evidence, recovery, and leadership priorities.
Required output
Preparation mission and safety charter.
Quality check
Every organization, service, identity, source, and decision is invented.
Create fictional policy, plan, playbook, checklist, reference, contact list, decision record, and evidence register purposes.
Required output
Response-document architecture.
Quality check
Each document has a clear owner, scope, detail level, and lifecycle.
Define fictional activation, roles, evidence, health, severity, priority, containment, communication, continuity, recovery, closure, reopening, review, and metrics.
Required output
Incident response plan.
Quality check
The plan coordinates the lifecycle without becoming a rigid script.
Create purpose, entry criteria, roles, questions, scope, evidence, branches, options, validation, rollback, communication, recovery, and exit criteria.
Required output
Scenario playbook set.
Quality check
Every decision point identifies evidence, owner, authority, alternatives, and reassessment.
Define fictional Healthy, Conditional, Degraded, Blind, Conflicting, and Recovering rules.
Required output
Source-health decision matrix.
Quality check
Missing or delayed evidence cannot become absence or success.
Design fictional Expected, Source-Degraded, Containment, Continuity, Supplier, Leadership, Recovery, Closure, and Reopen paths.
Required output
Branch map.
Quality check
Each branch has entry, action, break, validation, and exit.
Write fictional purpose, participants, observers, initial state, injects, expected actions, scoring, safety, and timing.
Required output
Tabletop exercise plan.
Quality check
The exercise tests difficult paths rather than only the happy path.
Compare fictional expected and observed actions across activation, roles, evidence, scope, containment, communication, recovery, and lifecycle.
Required output
Exercise observation and score record.
Quality check
Defects are evidence-based, non-blaming, and tied to mission effect.
Assign fictional defects, owners, due dates, dependencies, revisions, validation, approval, rollback reference, and retest.
Required output
Corrective-action and version package.
Quality check
A change is incomplete until intended behavior is validated.
Combine the fictional mission, documents, plan, playbooks, activation, sources, branches, exercise, validation, versioning, debt, risk, and reflection.
Required output
Public-safe Preparation and Playbook Design Package.
Quality check
No real playbook, contact tree, service, source, supplier, or action is used.
Scenario Decision Lab
During a fictional tabletop, the identity source becomes Blind during the key authorization period. The playbook says that no visible extension means no extension existed.
Scenario Decision Lab
A fictional service responds after containment. Identity validation, data reconciliation, supplier dependency, source recovery, and residual-risk ownership remain incomplete.
Advanced Challenge
Fictional Northbridge has nine critical scenarios, three untested playbooks, one stale supplier path, two missing alternates, a playbook that treats missing evidence as absence, a generic communication template, incomplete recovery gates, no rollback reference, and overdue corrective actions.
Defend document architecture
Explain fictional policy, plan, playbook, checklist, reference, contact list, decision record, and evidence register.
Defend activation
Explain routine triage, coordinated response, specialist, leadership, source-recovery, privacy, continuity, and supplier criteria.
Defend evidence
Explain sources, fields, provenance, timing, health, alternatives, privacy, retention, and limitations.
Defend branches
Explain Expected, Source-Degraded, Containment, Continuity, Supplier, Leadership, Recovery, Closure, and Reopen paths.
Defend exercise design
Explain injects, expected actions, observers, scoring, defects, owners, validation, and retest.
Defend lifecycle
Explain owner, approvers, version, reason, review, expiration, debt, rollback, archive, replacement, and residual risk.
Defender Habits
Check Your Understanding
Choose your answers first. Explanations appear only after submission.
Portfolio Prompt
Create a fully fictional Preparation and Playbook Design Package for the Northbridge Student-Support Cooperative. Include mission, critical services, users, data categories, identity model, supplier dependencies, continuity priorities, privacy boundary, response policy, organization-wide plan, scenario playbooks, checklists, references, contact and authority list, decision record, evidence register, activation criteria, routine-triage path, incident path, specialist path, leadership path, source-recovery path, privacy path, continuity path, supplier path, roles, alternates, decision rights, authority limits, handoff acceptance, bounded questions, evidence sources, required fields, provenance, event time, collection time, processing time, Healthy behavior, Conditional behavior, Degraded behavior, Blind behavior, Conflicting behavior, Recovering behavior, alternate evidence, privacy, retention, limitations, severity, confidence, priority, Expected branch, Source-Degraded branch, Identity Containment branch, Continuity branch, Supplier branch, Leadership branch, Recovery branch, Closure branch, Reopen branch, entry criteria, actions, break conditions, validation, exit criteria, containment options, benefits, costs, dependencies, evidence effects, continuity effects, authority, rollback, residual risk, audience matrix, message ownership, approvals, uncertainty, versioning, distribution, correction, next update, clean-state criteria, identity validation, configuration validation, data reconciliation, source recovery, supplier validation, monitoring, observation period, owner acceptance, closure criteria, reopen triggers, tabletop purpose, participants, observers, initial state, injects, expected actions, observed actions, scoring, defects, owners, due dates, dependencies, validation, retest, playbook identifier, version, owner, approvers, change reason, affected sections, evidence, test result, approval date, review date, expiration, rollback reference, archive, replacement, playbook coverage, activation clarity, branch validation, role readiness, source readiness, exercise quality, corrective-action aging, playbook debt, residual risk, leadership summary, reflection, and a statement that every organization, role, service, source, supplier, trigger, contact, action, decision, date, and outcome is invented.
Confidence / Readiness Reflection
Rate your readiness from 1 to 5 for response documents, activation, roles, authority, evidence, source health, scope questions, branches, containment, continuity, communication, recovery, exercises, validation, versioning, debt, risk, and fictionalization.
Key Takeaways
Navigation
Next, learn how fictional responders move from alerts, reports, source-health conditions, and service symptoms into an evidence-based activation and scope that separates confirmed, possible, unknown, unaffected, excluded, and out-of-scope categories.