High School AdvancedModule A7Lesson 2 of 10Plans, Playbooks, Branches, Exercises, and Versioning

A7.2 Preparation and Playbook Design

Learn how fictional response teams transform mission, authority, evidence, source health, containment, continuity, communication, recovery, validation, rollback, closure, reopening, ownership, and exercises into usable plans and playbooks.

Lesson Progress

Preparation and Playbook Design

High School AdvancedA7: Incident Response Lifecycle • Lesson 2 of 10

20% complete

Readiness Check

Before You Start

0/6 ready

Professional Hook

A Playbook Can Create Risk When It Is Too Simple

A fictional playbook says: “If a critical alert appears, isolate the service, notify everyone, restore from backup, and close when the service responds.” During a tabletop, the source is Blind, the service supports urgent student assistance, the supplier contact is stale, recovery has not been validated, and the incident lead is unavailable. The document contains steps but not the decisions needed for safe response.

Weak playbook

“Follow the same steps quickly whenever the alert appears.”

Strong playbook

“Use activation criteria, bounded questions, source-health branches, authorized options, continuity tradeoffs, validation, rollback, and lifecycle gates.”

Exactly Five Learning Objectives

What You Will Be Able to Do

Objective 1

Distinguish fictional incident response policy, plan, playbook, checklist, reference, contact list, decision record, and evidence register by purpose and level of detail.

Objective 2

Design fictional playbooks with activation criteria, roles, bounded questions, evidence, source-health behavior, branches, containment, continuity, communication, recovery, validation, rollback, closure, and reopening.

Objective 3

Evaluate fictional playbooks for rigid scripting, missing authority, stale assumptions, untested branches, absent privacy boundaries, weak recovery gates, and unclear ownership.

Objective 4

Create fictional tabletop exercises that test decisions, handoffs, owner unavailability, source degradation, scope change, containment tradeoffs, supplier delays, communication, recovery, and improvement.

Objective 5

Create a portfolio-ready fictional Preparation and Playbook Design Package containing a response plan, scenario playbooks, activation matrix, evidence map, exercise record, validation cases, version history, debt register, and reflection.

Why This Matters

Preparation Protects Decision Quality Before Time Pressure

Fictional response becomes safer when teams decide in advance who has authority, which evidence is needed, how source health changes conclusions, which continuity options exist, how containment is validated, who approves communication, what proves recovery, and when closure or reopening is justified.

Prepared decisions

Activation, containment, communication, recovery, and closure criteria are defined before urgency distorts judgment.

Tested assumptions

Roles, contacts, sources, suppliers, branches, recovery gates, and fallbacks are exercised rather than trusted on paper.

Governed lifecycle

Owners, versions, approvals, expiration, debt, corrective actions, and retest prevent silent decay.

Core Framework

The P-L-A-Y-B-O-O-K Method

P — Purpose

Define the fictional scenario, mission question, supported decisions, users, exclusions, and safety boundary.

L — Launch criteria

Document entry conditions, activation levels, roles, authority, alternates, and escalation.

A — Ask bounded questions

List observation, authorization, service, impact, source-health, scope, supplier, privacy, continuity, and recovery questions.

Y — Yield evidence

Map sources, fields, provenance, timing, health, alternate evidence, privacy, retention, and limitations.

B — Branch by conditions

Create Expected, Source-Degraded, Containment, Continuity, Supplier, Leadership, Recovery, Closure, and Reopen paths.

O — Options and owners

Compare choices using authority, benefit, cost, dependencies, evidence effect, continuity, validation, rollback, and risk.

O — Observe outcomes

Define expected state, validation evidence, monitoring, owner acceptance, failure triggers, and rollback.

K — Keep current

Assign owner, version, approval, exercises, corrective actions, expiration, debt, archive, and replacement.

Advanced Vocabulary

Terms for Preparation and Playbooks

Incident response policy

A fictional high-level statement of purpose, authority, scope, responsibilities, governance, and minimum program expectations.

Incident response plan

A fictional organization-wide framework describing preparation, activation, coordination, evidence, containment, communication, recovery, closure, and improvement.

Playbook

A fictional scenario-focused decision guide containing triggers, questions, roles, evidence, branches, options, validation, rollback, communication, continuity, and lifecycle steps.

Checklist

A fictional concise list used to confirm required evidence, actions, approvals, or validation without replacing judgment.

Reference

A fictional supporting document containing definitions, maps, source details, decision criteria, role information, or communication templates.

Contact list

A fictional readiness record containing primary owners, alternates, authority, availability, escalation, and review dates.

Decision record

A fictional log of the question, options, evidence, uncertainty, owner, authority, selected action, rationale, validation, and review trigger.

Evidence register

A fictional record of evidence identity, source, purpose, provenance, timing, health, integrity, access, custody, retention, and case use.

Activation criterion

A fictional condition that triggers routine review, incident coordination, specialist escalation, leadership review, source recovery, or another workflow.

Decision point

A fictional moment at which evidence, source health, scope, authority, continuity, privacy, impact, or recovery requires an explicit choice.

Branch condition

A fictional condition that moves a playbook into a different path based on evidence or mission context.

Entry condition

A fictional requirement that must be true before a playbook or phase begins.

Exit criterion

A fictional requirement that must be satisfied before a response phase ends.

Quality gate

A fictional required evidence, approval, validation, source-health, privacy, continuity, or lifecycle check.

Assumption

A fictional planning belief that must be documented, tested, reviewed, and changed when evidence or conditions change.

Dependency

A fictional identity, service, platform, source, supplier, data, communication, continuity, or authority condition needed for a response step.

Fallback

A fictional alternate path used when a primary role, source, service, supplier, communication channel, or recovery method is unavailable.

Tabletop exercise

A fictional discussion-based simulation used to test roles, decisions, evidence, authority, continuity, communication, recovery, and improvement.

Exercise inject

A fictional new fact, source failure, owner response, scope change, impact update, or constraint introduced during a simulation.

Expected action

A fictional documented response that should occur when a specific exercise condition appears.

Observed action

The fictional decision or response actually produced during an exercise.

Playbook debt

Fictional unresolved work involving stale roles, missing evidence, untested branches, weak recovery, unclear authority, or outdated assumptions.

Version history

A fictional record of playbook changes, owner, reason, date, evidence, test result, approval, and rollback reference.

Playbook expiration

A fictional date or condition requiring review because mission, services, identities, suppliers, sources, ownership, policy, or architecture may have changed.

Instructional Section 1

Separate Eight Response Document Types

Policy

Define fictional program authority, scope, governance, responsibilities, required outcomes, and exception rules.

Contains

Purpose, scope, authority, responsibilities, minimum controls, exceptions, review, and accountability.

Boundary

Does not contain live case decisions or detailed scenario steps.

Owner

Program governance or leadership authority.

Plan

Describe the fictional organization-wide incident response lifecycle and coordination model.

Contains

Activation, command, roles, evidence, communication, containment, continuity, recovery, closure, reopening, review, and metrics.

Boundary

Does not attempt to contain every scenario branch.

Owner

Incident response program owner.

Playbook

Guide fictional scenario-specific evidence and decision workflows.

Contains

Triggers, questions, sources, health rules, roles, branches, options, validation, rollback, communication, recovery, and exit criteria.

Boundary

Does not authorize one rigid response for every case.

Owner

Scenario owner with program approval.

Checklist

Confirm fictional required evidence, actions, approvals, validation, and lifecycle steps.

Contains

Short verification items, status, owner, and completion evidence.

Boundary

Does not replace complex decision reasoning.

Owner

Operational or quality owner.

Reference

Provide fictional definitions, service maps, source details, role information, criteria, and templates.

Contains

Definitions, maps, sources, criteria, templates, role details, and review dates.

Boundary

Does not contain unsupported case conclusions.

Owner

Domain owner.

Contact and authority list

Provide fictional primary owners, alternates, availability, decision rights, and escalation.

Contains

Role, primary, alternate, authority, response expectation, access readiness, escalation, and review date.

Boundary

Public learning versions contain no real contacts.

Owner

Program owner and role owners.

Decision record

Preserve fictional case-specific reasoning and authority.

Contains

Question, evidence, source health, options, owner, authority, decision, rationale, conditions, validation, and review trigger.

Boundary

Excludes unnecessary personal details and unsupported certainty.

Owner

Incident lead or decision owner.

Evidence register

Preserve fictional evidence traceability and governance.

Contains

Evidence ID, source, purpose, provenance, timing, health, integrity, access, custody, retention, transfer, limitations, and use.

Boundary

Technical interpretation stays in the analysis record.

Owner

Evidence coordinator.

Instructional Section 2

Build a Ten-Section Playbook

1. Purpose and scenario

Core question

What fictional condition does the playbook address, and which mission decision does it support?

Required content

Scenario, mission relevance, users, supported decisions, exclusions, and safety boundary.

Weak pattern

A vague title such as suspicious activity with no bounded question.

2. Entry and activation

Core question

Which fictional observations, evidence, health states, reports, impacts, or owner concerns justify activation?

Required content

Routine, incident, specialist, leadership, source-recovery, privacy, continuity, and supplier triggers.

Weak pattern

Every alert automatically becomes a confirmed incident.

3. Roles and authority

Core question

Who coordinates, analyzes, owns decisions, preserves evidence, communicates, maintains continuity, recovers, and accepts risk?

Required content

Primary roles, alternates, decision rights, availability, handoff acceptance, conflicts, and escalation.

Weak pattern

Roles are named without authority or backups.

4. Questions and scope

Core question

Which fictional observation, authorization, identity, service, impact, source-health, supplier, privacy, continuity, and recovery questions matter?

Required content

Bounded questions, evidence, owners, deadlines, affected/possible/unknown categories, and scope-change history.

Weak pattern

Investigate everything related to the alert.

5. Evidence and source health

Core question

Which fictional sources, fields, provenance, times, health states, alternatives, and limitations support each decision?

Required content

Source inventory, evidence IDs, event/collection/processing time, health behavior, privacy, retention, and missing-data rules.

Weak pattern

No visible evidence is treated as absence.

6. Severity, confidence, and priority

Core question

How do consequence, certainty, active impact, scope, time sensitivity, source health, and recoverability affect urgency?

Required content

Separate severity, confidence, priority, rationale, owner, and reassessment triggers.

Weak pattern

Severity alone determines the full response.

7. Options and branches

Core question

Which fictional containment, continuity, communication, evidence, supplier, privacy, and leadership options exist under different conditions?

Required content

Options, entry conditions, authority, dependencies, benefits, costs, evidence effects, validation, rollback, and break conditions.

Weak pattern

One irreversible action for every case.

8. Communication

Core question

Which fictional audiences need which facts, uncertainty, guidance, approvals, timing, correction, and next update?

Required content

Audience, owner, review, approval, privacy, version, distribution, correction, and next-update commitment.

Weak pattern

One generic message goes to every audience.

9. Continuity and recovery

Core question

How will fictional critical functions continue, and what proves trustworthy restoration?

Required content

Continuity options, clean-state criteria, dependencies, identity, configuration, data, source recovery, monitoring, rollback, and acceptance.

Weak pattern

Service reachable equals recovered.

10. Closure, reopening, and lifecycle

Core question

Which fictional evidence and approvals end phases, close the response, reopen it, and keep the playbook current?

Required content

Exit criteria, residual uncertainty, residual risk, corrective actions, reopen triggers, owner, version, expiration, debt, archive, and replacement.

Weak pattern

Alerts stop, so the case and playbook are complete.

Instructional Section 3

Create an Eight-Condition Activation Matrix

Single low-confidence alert

Fictional evidence

One fictional alert, Healthy sources, no confirmed impact, narrow scope, and plausible expected alternatives.

Workflow

Routine triage with bounded questions and source-health review.

Authority

Analyst or incident lead within routine authority.

Escalation

Escalate if confidence, scope, impact, source health, or owner deadlines change.

Multiple independent reports

Fictional evidence

Fictional SIEM alert, user reports, service symptoms, or supplier notice align around one mission service.

Workflow

Incident coordination readiness review.

Authority

Incident lead or authorized alternate.

Escalation

Activate when evidence crosses documented mission or coordination criteria.

Critical service impact

Fictional evidence

Fictional Healthy service evidence confirms broad user effect or loss of critical function.

Workflow

Incident coordination plus service and continuity activation.

Authority

Incident lead, service owner, and continuity owner.

Escalation

Leadership when containment, resources, continuity, or risk exceed routine authority.

Privileged authority unresolved

Fictional evidence

Fictional role or session remains active after expiration while authorization evidence is incomplete.

Workflow

Time-sensitive identity and incident coordination.

Authority

Incident lead with identity owner.

Escalation

Alternate owner or leadership if the identity decision deadline is missed.

Required source Blind

Fictional evidence

Fictional evidence source is Blind during the key period and affects mission-relevant conclusions.

Workflow

Source-recovery and evidence-limited response path.

Authority

Incident lead with source and affected decision owners.

Escalation

Leadership if evidence loss blocks critical decisions.

Privacy-sensitive concern

Fictional evidence

Fictional evidence suggests unnecessary access, sharing, or exposure of protected information.

Workflow

Incident coordination with privacy and governance review.

Authority

Incident lead and privacy authority.

Escalation

Legal, policy, or leadership authority according to documented triggers.

Supplier dependency

Fictional evidence

Fictional critical service depends on an external provider and local evidence cannot answer the bounded question.

Workflow

Incident coordination plus supplier escalation.

Authority

Supplier owner with incident lead.

Escalation

Leadership when service continuity, data sharing, contract, or delay creates mission risk.

Recovery validation failure

Fictional evidence

Fictional service is reachable but clean-state, identity, configuration, data, source, or dependency validation fails.

Workflow

Recovery remains Conditional; rollback or continued containment is evaluated.

Authority

Recovery owner with service and incident owners.

Escalation

Leadership if restoration delay or rollback has major mission consequences.

Instructional Section 4

Define Six Source-Health Rules

Healthy

Behavior

Fictional freshness, completeness, schema, parser, queue, timing, and coverage support normal-confidence use.

Playbook rule

Use evidence normally while preserving provenance, scope, and limitations.

Prohibited conclusion

Healthy evidence still does not prove intent or complete scope.

Conditional

Behavior

Fictional evidence is usable for some questions but limited by delay, partial coverage, stale context, or assumptions.

Playbook rule

Label affected conclusions, request alternate evidence, assign owner, and define reassessment.

Prohibited conclusion

Do not present Conditional evidence as complete.

Degraded

Behavior

Fictional evidence is materially weakened by delay, missing fields, parser defects, conflicts, or incomplete coverage.

Playbook rule

Reduce confidence, narrow decisions, use alternate evidence, and escalate source repair.

Prohibited conclusion

Do not treat missing records as no activity.

Blind

Behavior

Fictional required evidence is unavailable for the relevant population or period.

Playbook rule

Use Source-Degraded or Unknown, activate alternate evidence and recovery, and require historical reassessment.

Prohibited conclusion

Do not claim confirmation, absence, success, or full scope.

Conflicting

Behavior

Fictional sources disagree beyond timing or semantic tolerance.

Playbook rule

Preserve both observations, compare authority, timing, mapping, scope, and ownership, and assign reconciliation.

Prohibited conclusion

Do not choose the preferred source without documented reason.

Recovering

Behavior

Fictional connectivity is returning but backlog, replay, duplicates, schema, timing, or historical gaps remain.

Playbook rule

Keep recovery obligations open, reconcile affected cases, and delay final closure conclusions.

Prohibited conclusion

Connected does not equal trustworthy recovery.

Instructional Section 5

Design Six Response Branches

Expected activity

Entry condition

Fictional identity, service, destination, purpose, owner, approval, timing, and source health match current approved activity.

Fictional action

Document Expected state, preserve visibility, set expiration, monitor break conditions, and record owner confirmation.

Break condition

New identity, session, destination, service, scope, result, time, owner, impact, or source-health change.

Exit criterion

Expected context remains valid through observation or returns to active triage.

Source-Degraded

Entry condition

A fictional required source is Conditional, Degraded, Blind, Conflicting, or Recovering.

Fictional action

Lower confidence, preserve affected periods, use alternate evidence, assign source owner, and define reassessment.

Break condition

Source recovery, conflicting evidence, wider scope, active impact, or deadline failure.

Exit criterion

Source obligations and historical reassessment support the needed decision.

Identity containment

Entry condition

Fictional privileged authority or active session creates time-sensitive risk under authorization uncertainty.

Fictional action

Compare scoped restriction, session closure, monitoring, continuity, validation, and rollback with identity-owner approval.

Break condition

New identity, service, session, active impact, health change, or broader scope.

Exit criterion

Authorized action is validated and remaining authorization, scope, continuity, and risk work is assigned.

Service continuity

Entry condition

Fictional containment or recovery may interrupt critical users or workflows.

Fictional action

Activate approved alternate workflows, prioritize critical users, communicate limits, monitor capacity, and define transition-back criteria.

Break condition

Worsening impact, capacity failure, dependency loss, privacy issue, supplier failure, or recovery milestone.

Exit criterion

Trusted restoration is accepted and temporary workflows retire safely.

Supplier coordination

Entry condition

Fictional evidence, service, recovery, or source questions depend on an external provider.

Fictional action

Send purpose-limited request, track commitment, preserve confidentiality, compare evidence, and escalate mission issues.

Break condition

Missed deadline, conflicting evidence, broader impact, data-sharing concern, or continuity risk.

Exit criterion

Dependency resolves, becomes accepted residual risk, or transfers to a long-term owner.

Leadership decision

Entry condition

Fictional resource conflict, major interruption, policy exception, public communication, or risk decision exceeds operational authority.

Fictional action

Provide bounded decision, options, evidence, uncertainty, mission impact, recommendations, urgency, and residual risk.

Break condition

Evidence changes, deadline expires, an option disappears, or impact increases.

Exit criterion

Authorized decision is recorded with conditions, owners, review trigger, and communication.

Instructional Section 6

Run Eight Tabletop Injects

INJECT-01

The fictional primary incident lead is unavailable when the first alert arrives.

Tests

Alternate authority, activation, handoff, contact readiness, and command continuity.

Expected response

Named alternate accepts the role using the documented transfer checklist.

INJECT-02

A fictional required identity source becomes Degraded during authorization review.

Tests

Source-health behavior, alternate evidence, confidence, ownership, and reassessment.

Expected response

Authorization becomes Conditional rather than forced into yes or no.

INJECT-03

A fictional second service appears after initial scope is documented.

Tests

Scope change, service ownership, severity, priority, communication, and continuity.

Expected response

Scope version updates without assuming the second service is fully affected.

INJECT-04

A fictional broad containment option would interrupt urgent support workflows.

Tests

Containment tradeoff, continuity, authority, alternatives, validation, rollback, and leadership escalation.

Expected response

Team compares narrow and broad options and selects only an authorized evidence-supported path.

INJECT-05

Two fictional owners provide conflicting impact statements.

Tests

Evidence reconciliation, message approval, uncertainty, correction, and versioning.

Expected response

Incident lead establishes supported wording and assigns a technical decision deadline.

INJECT-06

A fictional supplier misses the committed response deadline.

Tests

Supplier escalation, local fallback, continuity, evidence limits, and leadership decision need.

Expected response

Supplier owner activates alternate escalation and the incident lead records decision impact.

INJECT-07

The fictional service becomes reachable, but one source remains Blind and data validation is incomplete.

Tests

Recovery gates, source reconciliation, data integrity, business acceptance, rollback, and closure.

Expected response

Recovery remains Conditional and closure is blocked.

INJECT-08

Leadership requests immediate closure before residual-risk ownership is assigned.

Tests

Closure authority, risk acceptance, evidence, owner recommendations, and communication.

Expected response

Incident lead presents closure gaps and requires the documented risk authority or continued Conditional state.

Instructional Section 7

Score Eight Exercise Domains

Activation quality

Strong behavior

Fictional activation uses evidence, source health, mission relevance, authority, scope, and non-proof statements.

Weak behavior

The alert title alone declares the incident.

Evidence record

Activation record and decision rationale.

Role quality

Strong behavior

Fictional primary and alternate owners accept bounded responsibilities under documented authority.

Weak behavior

Roles are assigned without acknowledgement, authority, or alternate.

Evidence record

Role roster, handoff log, and decision-rights matrix.

Evidence quality

Strong behavior

Fictional evidence includes provenance, timing, source health, supports, limitations, privacy, and purpose.

Weak behavior

Missing evidence becomes absence or raw records are shared broadly.

Evidence record

Evidence register and source-health map.

Scope quality

Strong behavior

Fictional affected, possible, unknown, excluded, and out-of-scope categories are versioned.

Weak behavior

Scope is permanently defined by the first alert.

Evidence record

Scope register and change log.

Containment quality

Strong behavior

Fictional options compare risk reduction, continuity, evidence, authority, reversibility, validation, rollback, and risk.

Weak behavior

The fastest or broadest action is selected automatically.

Evidence record

Containment decision matrix.

Communication quality

Strong behavior

Fictional messages preserve facts, uncertainty, audience need, approvals, privacy, versions, and corrections.

Weak behavior

One message goes to everyone or conflicting statements remain unresolved.

Evidence record

Communication log and approvals.

Recovery quality

Strong behavior

Fictional clean-state, identity, configuration, data, source, dependency, monitoring, rollback, and acceptance gates pass.

Weak behavior

Availability alone is treated as recovery.

Evidence record

Recovery and validation checklist.

Lifecycle quality

Strong behavior

Fictional closure, reopening, corrective actions, debt, owners, review, and versioning are complete.

Weak behavior

The exercise ends without improvement or retest.

Evidence record

Closure review, after-action report, and updated playbook.

Instructional Section 8

Validate Twelve Playbook Scenarios

CaseTypeFictional inputExpected resultQuality protected
PLAY-T01Routine alertOne fictional low-confidence alert, Healthy sources, no impact, and narrow scope.Use routine triage rather than automatic incident activation.Proportionate response
PLAY-T02Multiple evidence categoriesFictional alert, user reports, and service symptoms align around one mission service.Trigger coordinated response review.Mission-aware activation
PLAY-T03Primary unavailableFictional incident lead is unavailable.Authorized alternate accepts command through the handoff process.Command continuity
PLAY-T04Blind sourceFictional required source is Blind during the key period.Follow Source-Degraded branch, alternate evidence, and reassessment.Evidence honesty
PLAY-T05Scope expansionFictional second service appears after initial scope.Update scope version, owners, and priority.Dynamic scoping
PLAY-T06Containment tradeoffFictional broad shutdown interrupts critical support.Compare narrow, broad, continuity, validation, and rollback options.Mission continuity
PLAY-T07Privacy-sensitive evidenceFictional request includes fields unnecessary for the decision.Apply minimization and privacy review.Purpose limitation
PLAY-T08Supplier delayFictional critical supplier misses a response commitment.Activate supplier escalation and local fallback.External readiness
PLAY-T09Recovery incompleteFictional service is reachable while data and source validation remain incomplete.Keep recovery Conditional and block closure.Trustworthy restoration
PLAY-T10Stale playbookFictional ownership, contacts, and supplier paths changed after review.Fail readiness validation and update plus retest.Lifecycle accuracy
PLAY-T11Closure pressureFictional leadership requests closure before residual-risk ownership exists.Route risk decision to documented authority.Evidence-based closure
PLAY-T12Public portfolioStudent plans to adapt a real playbook and contact tree.Fail portfolio validation and invent every detail.Confidentiality and safety

Instructional Section 9

Maintain a Twelve-Field Version Record

FieldPurposeFictional example
Playbook identifierTrace across versions, exercises, cases, approvals, and archive.IR-PB-NB-004
VersionIdentify the fictional approved state.Version 2.3
OwnerAssign content, testing, review, debt, and retirement accountability.Incident response program owner
ApproversRecord required incident, technical, service, privacy, continuity, evidence, recovery, supplier, and leadership approvals.Incident lead, service owner, privacy reviewer, recovery owner
Change reasonExplain which exercise, incident, source, role, supplier, policy, or architecture change required revision.Tabletop found missing supplier fallback
Affected sectionsIdentify activation, roles, evidence, branches, communication, recovery, closure, or other sections changed.Sections 3, 8, 9, and 10
Supporting evidenceLink exercise observations, validation cases, source changes, owner review, or corrective actions.EX-NB-07 and PLAY-T08 to PLAY-T11
Test resultDocument expected and observed behavior after revision.Supplier delay, recovery gate, and closure cases passed
Approval dateRecord fictional authorization for use.Invented date: 2026-08-01
Review and expirationPrevent use after assumptions or dependencies change.Review in ninety days or after service, role, source, supplier, policy, or architecture change
Rollback referenceIdentify the prior validated version if the new version causes defects.Return to 2.2 if recovery branch validation fails
Archive and replacementDocument retirement, replacement coverage, history, and access.Archive 2.2 read-only after 2.3 approval

Instructional Section 10

Measure Eight Preparation Outcomes

Playbook coverage

Review question

Do fictional mission-critical scenarios, services, identities, suppliers, privacy concerns, source failures, and recovery conditions have playbooks?

Evidence

Scenario inventory, mission map, service criticality, source map, supplier map, and residual-risk register.

Limitation

A written playbook does not prove readiness.

Activation clarity

Review question

Can fictional responders distinguish routine triage, incident coordination, specialist, leadership, source-recovery, and privacy paths?

Evidence

Activation matrix, exercise decisions, false activations, delayed activations, and owner review.

Limitation

Real conditions may not match exercise categories exactly.

Branch validation

Review question

Have fictional Expected, Source-Degraded, Containment, Continuity, Supplier, Leadership, Recovery, Closure, and Reopen paths been tested?

Evidence

Validation cases, injects, observed actions, defects, corrections, and retest.

Limitation

Passing known branches does not cover unknown future conditions.

Role readiness

Review question

Do fictional playbook roles have current authority, alternates, access, training, contacts, and handoff acceptance?

Evidence

Role roster, alternate map, contact test, access review, and tabletop performance.

Limitation

A tested role may still be unavailable later.

Evidence-source readiness

Review question

Are fictional sources, fields, health rules, alternate evidence, privacy, retention, and owners current?

Evidence

Source inventory, schema tests, health exercises, alternate evidence, and review dates.

Limitation

Source behavior can change after review.

Exercise quality

Review question

Do fictional exercises test authority, uncertainty, source degradation, scope change, containment, communication, recovery, closure, and improvement?

Evidence

Exercise plan, injects, expected actions, observed actions, scoring, defects, and retest.

Limitation

Discussion success does not prove operational execution.

Corrective-action aging

Review question

How long do fictional exercise and playbook defects remain open?

Evidence

Action owner, due date, mission effect, dependency, evidence, validation, escalation, and closure.

Limitation

Fast closure does not prove the correction worked.

Playbook debt

Review question

Which fictional assumptions, roles, contacts, branches, sources, suppliers, recovery gates, tests, approvals, and review dates remain incomplete?

Evidence

Debt register, age, mission effect, owner, due date, priority, escalation, and residual risk.

Limitation

Debt count alone does not show mission impact.

Fictional Preparation Architecture

Northbridge Plan-to-Playbook Model

This conceptual model is completely invented and intentionally non-operational. It teaches preparation without real organizations, contacts, systems, sources, suppliers, incidents, containment actions, or internal procedures.

Mission inputs

Critical services, users, data, privacy, continuity

Readiness inputs

Roles, authority, alternates, contacts, suppliers

Evidence inputs

Sources, fields, health, provenance, timing, limits

Lifecycle inputs

Activation, branches, recovery, closure, review

Fictional Playbook Core

Purpose

Scenario, mission question, users, exclusions

Activation

Entry criteria, authority, roles, alternatives

Questions

Evidence, scope, impact, source health, owners

Branches

Expected, degraded, containment, continuity, supplier

Decisions

Options, authority, cost, validation, rollback

Communication

Audience, facts, uncertainty, approval, correction

Recovery

Clean state, dependencies, monitoring, acceptance

Lifecycle

Exercise, version, expiration, debt, archive

Operational output

Plan, playbooks, checklists, contacts, decisions

Exercise output

Injects, observations, scoring, defects, retest

Leadership output

Coverage, debt, resources, risk, improvement

Portfolio boundary

Fully fictional, privacy-safe, non-operational

Fake Dashboard

Fake Northbridge Playbook Readiness Dashboard

Fictional scenario coverage, activation clarity, branch validation, role readiness, evidence-source readiness, exercise quality, action aging, and playbook debt.

Critical fictional scenarios with tested playbooks

6 / 9

Supplier evidence loss, broad source Blindness, and extended recovery still require exercises.

Playbook branches passing validation

11 / 15

Leadership risk, supplier fallback, recovery rollback, and reopen branches remain incomplete.

Open fictional preparation debt

13

Contacts, alternates, health rules, branch tests, supplier path, privacy review, communication correction, recovery gates, closure authority, expiration, rollback, archive, and retest remain open.

Fake SOC Alert

Incident Playbook Failed Recovery and Closure Validation

Source: Fake Northbridge Preparedness Governance Console • Time: 10:42 AM

High Severity
The fictional tabletop restored service availability, but identity validation, data reconciliation, supplier dependency, source recovery, residual-risk ownership, and reopen criteria remained incomplete. The team closed because the service responded.
Defensive recommendation: Keep the fictional playbook unapproved. Add clean-state criteria, multi-owner validation, source reconciliation, risk authority, closure gates, reopen triggers, version ownership, and a retest.

Fake Log Panel

Fake Playbook Exercise Timeline

training-log-viewer.log
09:00 EXERCISE id='EX-NB-07'
09:02 ALERT confidence='low'
09:05 REPORTS users='2'
09:06 ACTIVATION state='coordinated'
09:10 SOURCE identity='degraded'
09:12 SCOPE service='1'
09:20 INJECT second-service='added'
09:25 CONTAINMENT option='broad-shutdown'
09:27 CONTINUITY review='missing'
09:30 SUPPLIER response='late'
09:45 SERVICE availability='restored'
09:47 IDENTITY validation='incomplete'
09:48 DATA validation='incomplete'
09:49 SOURCE recovery='incomplete'
09:50 RISK owner='missing'
09:51 REOPEN criteria='missing'
09:52 CASE state='closed'
10:42 ALERT issue='playbook-validation-failed'

Training note: this is fake data for defensive analysis practice only.

Fictional Evidence Matrix

What Preparation Evidence Supports—and What It Does Not Prove

PLAY-E01

Fictional playbook inventory

Observation

Northbridge has identity and service playbooks but none for supplier evidence loss.

Supports

Supplier-dependent response coverage is incomplete.

Does not prove

Does not prove a supplier event will occur.

Preparation use

Create and test supplier coordination and fallback branches.

PLAY-E02

Fictional activation matrix

Observation

A low-confidence alert and multi-source service-impact condition use the same activation path.

Supports

Activation criteria are too broad.

Does not prove

Does not prove every activation was wrong.

Preparation use

Separate routine triage from coordinated response.

PLAY-E03

Fictional source-health review

Observation

Playbook says no record means no activity even when the source is Blind.

Supports

The playbook can create false absence.

Does not prove

Does not prove prior cases were misclassified.

Preparation use

Add six source-health states and alternate evidence.

PLAY-E04

Fictional tabletop record

Observation

Responders selected broad shutdown before reviewing continuity or rollback.

Supports

Containment criteria and authority are incomplete.

Does not prove

Does not prove they would always choose that action.

Preparation use

Add option comparison, continuity, validation, rollback, and approvals.

PLAY-E05

Fictional communication exercise

Observation

Two audiences received different impact statements because no message owner was assigned.

Supports

Communication ownership and version control are weak.

Does not prove

Does not determine which statement is correct.

Preparation use

Add communication owner, approval, correction, and next-update rules.

PLAY-E06

Fictional recovery checklist

Observation

Service availability is checked, but identity, configuration, data, supplier, source, and monitoring validation are absent.

Supports

Recovery criteria are incomplete.

Does not prove

Does not prove a recovery failed.

Preparation use

Add clean-state and multi-owner validation gates.

PLAY-E07

Fictional version history

Observation

Playbook owner changed, but approval and review records were not updated.

Supports

Current authority and lifecycle are uncertain.

Does not prove

Content may still be technically useful.

Preparation use

Assign current owner, approval, expiration, validation, and debt.

PLAY-E08

Fictional closure exercise

Observation

Team closed after service restoration while one source remained Recovering and risk was unassigned.

Supports

Closure and recovery gates are weak.

Does not prove

Does not prove every closure would be premature.

Preparation use

Add source reconciliation, risk authority, observation, and reopen triggers.

Analyze the Evidence

Which Playbook Decision Is Best Supported?

Service availability was restored.
Identity validation remained incomplete.
Data reconciliation remained incomplete.
Supplier dependency remained unresolved.
One required source remained Recovering.
Residual-risk ownership was not assigned.
Reopen criteria were missing.
The team closed because the service responded.

Which fictional response best addresses the Northbridge tabletop failure?

Common Mistakes

Avoid Ten Preparation and Playbook Errors

The playbook becomes an inflexible script

Fictional observation

Team follows one path even when source health, scope, impact, continuity, or authority changes.

Impact

Responders may take inappropriate actions or miss important branches.

Correction

Use decision points, branches, alternatives, validation, and rollback.

Every alert activates an incident

Fictional observation

A single low-confidence alert triggers full coordination.

Impact

Resources are consumed and triage disappears.

Correction

Define evidence-based activation and reassessment criteria.

Every source is assumed Healthy

Fictional observation

A missing record is treated as no activity.

Impact

Blind or delayed evidence creates false certainty.

Correction

Document health states, alternatives, confidence changes, and reassessment.

Roles lack authority

Fictional observation

Tasks are assigned but no one knows who may contain, communicate, recover, close, or reopen.

Impact

Teams delay or exceed authority.

Correction

Link every decision point to rights and escalation.

Containment is one mandatory action

Fictional observation

The playbook always shuts down the service.

Impact

Continuity, evidence, privacy, users, and recovery may be harmed.

Correction

Compare options with dependencies, validation, rollback, and authority.

Communication is generic

Fictional observation

One identical message goes to analysts, users, suppliers, and leadership.

Impact

Audiences receive too much, too little, or unsupported information.

Correction

Use audience-specific facts, uncertainty, approvals, versions, and corrections.

Recovery means the service responds

Fictional observation

The playbook closes when connectivity returns.

Impact

Identity, data, source health, monitoring, and risk may remain unresolved.

Correction

Use clean-state, staged validation, observation, rollback, and reopen triggers.

Exercises test only happy paths

Fictional observation

No inject covers unavailable owners, Blind sources, scope growth, supplier delay, or failed recovery.

Impact

Important branches remain untested.

Correction

Use difficult injects, expected outcomes, defects, owners, and retest.

Playbooks never expire

Fictional observation

Contacts, sources, suppliers, authority, and assumptions remain unchanged on paper.

Impact

The documented process may fail under pressure.

Correction

Assign owner, review, expiration, debt, exercises, and archive.

Real playbooks enter the portfolio

Fictional observation

A student sanitizes real role names, contacts, service maps, triggers, or steps.

Impact

Sensitive structures and capabilities may remain identifiable.

Correction

Invent every organization, role, service, source, supplier, trigger, action, and outcome.

Safe Fictional Practice Lab

Build the Northbridge Preparation and Playbook Design Package

Use only invented Northbridge information. Do not access, copy, sanitize, upload, test, adapt, approve, or modify any real response plan, playbook, role chart, contact tree, service map, source list, supplier path, organization, system, or person.
1

Define the mission

Document fictional critical services, users, identity, data, suppliers, continuity, privacy, evidence, recovery, and leadership priorities.

Required output

Preparation mission and safety charter.

Quality check

Every organization, service, identity, source, and decision is invented.

2

Separate document types

Create fictional policy, plan, playbook, checklist, reference, contact list, decision record, and evidence register purposes.

Required output

Response-document architecture.

Quality check

Each document has a clear owner, scope, detail level, and lifecycle.

3

Build the plan

Define fictional activation, roles, evidence, health, severity, priority, containment, communication, continuity, recovery, closure, reopening, review, and metrics.

Required output

Incident response plan.

Quality check

The plan coordinates the lifecycle without becoming a rigid script.

4

Design scenario playbooks

Create purpose, entry criteria, roles, questions, scope, evidence, branches, options, validation, rollback, communication, recovery, and exit criteria.

Required output

Scenario playbook set.

Quality check

Every decision point identifies evidence, owner, authority, alternatives, and reassessment.

5

Add source-health behavior

Define fictional Healthy, Conditional, Degraded, Blind, Conflicting, and Recovering rules.

Required output

Source-health decision matrix.

Quality check

Missing or delayed evidence cannot become absence or success.

6

Create branch conditions

Design fictional Expected, Source-Degraded, Containment, Continuity, Supplier, Leadership, Recovery, Closure, and Reopen paths.

Required output

Branch map.

Quality check

Each branch has entry, action, break, validation, and exit.

7

Plan the tabletop

Write fictional purpose, participants, observers, initial state, injects, expected actions, scoring, safety, and timing.

Required output

Tabletop exercise plan.

Quality check

The exercise tests difficult paths rather than only the happy path.

8

Run and score

Compare fictional expected and observed actions across activation, roles, evidence, scope, containment, communication, recovery, and lifecycle.

Required output

Exercise observation and score record.

Quality check

Defects are evidence-based, non-blaming, and tied to mission effect.

9

Correct and retest

Assign fictional defects, owners, due dates, dependencies, revisions, validation, approval, rollback reference, and retest.

Required output

Corrective-action and version package.

Quality check

A change is incomplete until intended behavior is validated.

10

Prepare the portfolio

Combine the fictional mission, documents, plan, playbooks, activation, sources, branches, exercise, validation, versioning, debt, risk, and reflection.

Required output

Public-safe Preparation and Playbook Design Package.

Quality check

No real playbook, contact tree, service, source, supplier, or action is used.

Scenario Decision Lab

A Required Source Becomes Blind

During a fictional tabletop, the identity source becomes Blind during the key authorization period. The playbook says that no visible extension means no extension existed.

Scenario Decision Lab

The Service Is Reachable but Recovery Is Incomplete

A fictional service responds after containment. Identity validation, data reconciliation, supplier dependency, source recovery, and residual-risk ownership remain incomplete.

Advanced Challenge

Defend a Playbook before a Readiness Review Board

Fictional Northbridge has nine critical scenarios, three untested playbooks, one stale supplier path, two missing alternates, a playbook that treats missing evidence as absence, a generic communication template, incomplete recovery gates, no rollback reference, and overdue corrective actions.

Defend document architecture

Explain fictional policy, plan, playbook, checklist, reference, contact list, decision record, and evidence register.

Defend activation

Explain routine triage, coordinated response, specialist, leadership, source-recovery, privacy, continuity, and supplier criteria.

Defend evidence

Explain sources, fields, provenance, timing, health, alternatives, privacy, retention, and limitations.

Defend branches

Explain Expected, Source-Degraded, Containment, Continuity, Supplier, Leadership, Recovery, Closure, and Reopen paths.

Defend exercise design

Explain injects, expected actions, observers, scoring, defects, owners, validation, and retest.

Defend lifecycle

Explain owner, approvers, version, reason, review, expiration, debt, rollback, archive, replacement, and residual risk.

Defender Habits

Preparation and Playbook Design Checklist

Check Your Understanding

A7.2 Mini Quiz: Preparation and Playbook Design

Choose your answers first. Explanations appear only after submission.

1. Which statement best distinguishes a fictional incident response plan from a playbook?

2. What should happen when a fictional required source is Blind?

3. Why should a fictional playbook contain branch conditions?

4. Which fictional containment section is strongest?

5. What makes a fictional tabletop exercise useful?

6. A fictional service is reachable, but data and source validation remain incomplete. What is strongest?

7. Which public portfolio approach is safest?

Portfolio Prompt

Portfolio Prompt

Create a fully fictional Preparation and Playbook Design Package for the Northbridge Student-Support Cooperative. Include mission, critical services, users, data categories, identity model, supplier dependencies, continuity priorities, privacy boundary, response policy, organization-wide plan, scenario playbooks, checklists, references, contact and authority list, decision record, evidence register, activation criteria, routine-triage path, incident path, specialist path, leadership path, source-recovery path, privacy path, continuity path, supplier path, roles, alternates, decision rights, authority limits, handoff acceptance, bounded questions, evidence sources, required fields, provenance, event time, collection time, processing time, Healthy behavior, Conditional behavior, Degraded behavior, Blind behavior, Conflicting behavior, Recovering behavior, alternate evidence, privacy, retention, limitations, severity, confidence, priority, Expected branch, Source-Degraded branch, Identity Containment branch, Continuity branch, Supplier branch, Leadership branch, Recovery branch, Closure branch, Reopen branch, entry criteria, actions, break conditions, validation, exit criteria, containment options, benefits, costs, dependencies, evidence effects, continuity effects, authority, rollback, residual risk, audience matrix, message ownership, approvals, uncertainty, versioning, distribution, correction, next update, clean-state criteria, identity validation, configuration validation, data reconciliation, source recovery, supplier validation, monitoring, observation period, owner acceptance, closure criteria, reopen triggers, tabletop purpose, participants, observers, initial state, injects, expected actions, observed actions, scoring, defects, owners, due dates, dependencies, validation, retest, playbook identifier, version, owner, approvers, change reason, affected sections, evidence, test result, approval date, review date, expiration, rollback reference, archive, replacement, playbook coverage, activation clarity, branch validation, role readiness, source readiness, exercise quality, corrective-action aging, playbook debt, residual risk, leadership summary, reflection, and a statement that every organization, role, service, source, supplier, trigger, contact, action, decision, date, and outcome is invented.

Use fictional decision points and branches instead of one rigid script.
Connect every fictional choice to evidence, source health, authority, continuity, privacy, validation, rollback, and ownership.
Test fictional owner unavailability, Blind sources, scope growth, conflicting evidence, supplier delay, containment tradeoffs, failed recovery, closure pressure, and reopening.
Treat exercise findings as evidence requiring corrective action and retest before approval.
Keep the artifact completely fictional, defensive, non-operational, privacy-safe, evidence-aware, maintainable, and suitable for a public learning portfolio.

Confidence / Readiness Reflection

Are You Ready for Detection and Scoping?

Rate your readiness from 1 to 5 for response documents, activation, roles, authority, evidence, source health, scope questions, branches, containment, continuity, communication, recovery, exercises, validation, versioning, debt, risk, and fictionalization.

I can explain the difference between a fictional plan and playbook.
I can define activation criteria without treating every alert as an incident.
I can connect decisions to roles, authority, evidence, source health, and deadlines.
I can design branches for different evidence and mission conditions.
I can build recovery and closure gates beyond service availability.
I can design a tabletop with difficult injects and measurable behavior.
I can maintain versions, approvals, expiration, debt, actions, and retest.
I can produce a safe fictional package without adapting real playbooks or contacts.
Record one fictional activation criterion, one source-health rule, one branch condition, one containment tradeoff, one recovery gate, one exercise inject, and one question for A7.3.

Key Takeaways

What You Should Remember

1.Fictional policy, plan, playbook, checklist, reference, contact list, decision record, and evidence register serve different purposes.
2.A professional fictional playbook organizes judgment through evidence, authority, alternatives, branches, validation, rollback, and lifecycle controls.
3.Activation should distinguish routine triage, coordinated response, specialist, leadership, source-recovery, privacy, continuity, and supplier paths.
4.Fictional source-health states must change confidence, evidence use, alternate paths, and reassessment.
5.Branches should have entry conditions, actions, break conditions, validation, and exit criteria.
6.Containment, communication, continuity, recovery, closure, and reopening require owners, authority, evidence, dependencies, and quality gates.
7.Tabletop exercises should test owner unavailability, source degradation, scope changes, supplier delay, containment tradeoffs, failed recovery, and closure pressure.
8.Exercise findings become corrective actions with owners, due dates, evidence, validation, and retest.
9.Playbooks require current owners, versions, approvals, review dates, expiration, debt, rollback references, archive, and replacement.
10.Every CyberShield playbook artifact must remain fully fictional, authorized, defensive, non-operational, privacy-safe, and incapable of exposing real response plans or people.

Navigation

Continue Module A7

Next, learn how fictional responders move from alerts, reports, source-health conditions, and service symptoms into an evidence-based activation and scope that separates confirmed, possible, unknown, unaffected, excluded, and out-of-scope categories.