By the end of A6, you will have one connected fictional package showing how a professional defender moves from SIEM mission and source evidence to normalized records, correlations, alert priority, triage, escalation, case management, dashboards, quality improvement, governance, and leadership communication.
Artifact 1
Fictional SIEM mission, purpose, stakeholders, scope, exclusions, authorization, safety boundary, ownership, and lifecycle charter
Artifact 2
Source inventory covering identity, endpoint, network, DNS, email, application, cloud, supplier, administrative, support, and source-health evidence
Artifact 3
Collection and normalization architecture with event time, collection time, processing time, parsing, schema, field mapping, enrichment, storage, and access
Artifact 4
Versioned field dictionary with provenance, meaning, type, allowed values, transformations, requirement, privacy purpose, source health, and limitations
Artifact 5
Source-health model covering Healthy, Conditional, Degraded, Blind, Conflicting, and Recovering states
Artifact 6
Correlation and alert specification library with defender questions, conditions, relationships, windows, counts, sequence, context, alternatives, limits, and tests
Artifact 7
Severity-confidence-priority matrix with mission impact, identity, privilege, scope, time sensitivity, user effect, source health, and response opportunity
Artifact 8
Fictional alert queue with triage order, evidence gaps, owners, next questions, state, escalation, and closure requirements
Artifact 9
Alert triage worksheets and evidence-review matrices using only inert invented evidence
Artifact 10
Escalation matrix with technical, service, privacy, leadership, supplier, recovery, and source-health criteria
Artifact 11
Case-management package with chronology, notes, evidence requests, owners, decisions, actions, validation, residual risk, closure, and reopen criteria
Artifact 12
Analyst, source-health, detection-quality, workload, service-impact, and leadership dashboard designs
Artifact 13
Metric definitions covering counts, rates, denominators, periods, confidence, limitations, owners, actions, and review triggers
Artifact 14
SIEM noise and quality review with expected alerts, false positives, false negatives, Unknown outcomes, duplicate work, source gaps, and decision latency
Artifact 15
Tuning and quality-improvement plan with root-cause hypotheses, context, grouping, deduplication, thresholds, exceptions, expiration, testing, observation, and rollback
Artifact 16
Complete fictional SIEM Triage Lab package, leadership brief, technical appendix, analyst guide, portfolio reflection, and fictionalization statement