High School IntermediateModule I15Lesson 3 of 8

I15.3 Case Management and Evidence Handling

Learn how defenders open, scope, own, document, link, investigate, communicate, validate, review, and close fictional SOC cases while preserving traceable evidence and clear limitations.

Lesson Progress

Case Management and Evidence Handling

High School IntermediateI15: Security Operations Basics • Lesson 3 of 8

38% complete

Readiness Check

Before You Start

0/5 ready

Professional Hook

A Case Should Explain the Decision without Requiring the Original Analyst

A fictional Northbridge case moves across shifts, service owners, telemetry teams, detection engineers, suppliers, responders, and leadership. If the record contains only a few informal notes, each new reviewer must guess what happened. A professional case allows another authorized reviewer to reconstruct the question, scope, evidence, timeline, actions, decisions, communications, limitations, validation, and closure.

Weak case record

Paste untraceable evidence, mix facts and guesses, omit timestamps, record actions without authority, communicate inconsistently, and close when the alert stops.

Professional case record

Define scope, index evidence, build a timeline, preserve uncertainty, assign ownership, document decisions, validate outcomes, and complete quality review.

Objective 1

Explain how fictional case management connects triage, ownership, scope, evidence, timeline, actions, decisions, communications, validation, closure, and improvement.

Objective 2

Distinguish fictional alerts, cases, incidents, evidence items, analyst notes, findings, hypotheses, decisions, tasks, and closure records.

Objective 3

Build a fictional SOC case file that is reconstructable, privacy-safe, evidence-limited, and suitable for shift handoff and quality review.

Objective 4

Evaluate fictional evidence using relevance, source health, timestamps, traceability, integrity concepts, scope, consistency, confidence, and limitations.

Objective 5

Create a portfolio-safe fictional case-management package with a case charter, evidence register, timeline, action log, communication record, findings, closure criteria, and leadership summary.

Why This Matters

Case Quality Protects Evidence, Decisions, Handoffs, and Trust

Fictional SOC decisions may affect access, critical services, suppliers, recovery, privacy, leadership communication, and residual risk. Weak case records create duplicated work, unsupported conclusions, delayed response, poor handoffs, and unreliable metrics. Strong case management turns separate actions into one reviewable evidence-to-decision chain.

Core Concept

Use the Scope–Evidence–Timeline–Decision–Closure Model

Scope

Which fictional question, assets, identities, services, data, suppliers, time window, environment, and exclusions define the case?

Evidence

Which fictional sources, records, owners, timestamps, health checks, handling details, confidence, and limitations support review?

Timeline

Which fictional events, alerts, actions, approvals, communications, source gaps, decisions, and validations occurred and when?

Decision

Which fictional finding, owner, authority, action, deadline, rollback, communication, and residual-risk decision follow from the evidence?

Closure

Which fictional security, business, source-health, control, supplier, communication, signoff, retention, and improvement conditions are complete?

Key Vocabulary

Case Management and Evidence Terms

Case

A fictional organized record that connects one or more related alerts, evidence items, actions, decisions, owners, communications, and outcomes.

Case owner

The fictional analyst or responder accountable for maintaining case quality, status, evidence references, actions, decisions, communications, and next steps.

Evidence item

A fictional approved record, event, configuration, statement, test result, source-health record, or artifact used to support or challenge a conclusion.

Evidence register

A fictional index that records evidence identifiers, sources, owners, timestamps, relevance, health, scope, handling, confidence, and limitations.

Timeline

A fictional ordered record of alerts, evidence, actions, communications, approvals, changes, decisions, and validation events.

Action log

A fictional record of tasks performed, requested, blocked, approved, completed, validated, or reassigned during a case.

Decision log

A fictional record of what was decided, by whom, with which authority, based on which evidence, under which limitations, and with which review date.

Finding

A fictional evidence-supported statement that separates direct observations, interpretation, alternatives, confidence, limitations, and required action.

Hypothesis

A fictional possible explanation that guides evidence collection but is not treated as a proven conclusion.

Chain of custody concept

A fictional record of who collected, transferred, accessed, stored, or reviewed an evidence item and when.

Evidence integrity

A fictional assurance concept that an evidence item remains traceable, protected from unauthorized change, and suitable for the intended decision.

Case status

A fictional label such as New, Triaging, Investigating, Awaiting Owner, Responding, Monitoring, Ready for Review, or Closed.

Case linkage

A fictional relationship between alerts, cases, incidents, suppliers, changes, controls, risks, or prior records.

Closure criteria

Fictional conditions that must be satisfied before the case is considered complete.

Retention

A fictional rule describing how long approved case records and evidence references should remain available.

Quality review

A fictional peer or management check of case reasoning, evidence, ownership, timeliness, communication, validation, and closure.

Case Design

Eight Fields That Make a Fictional Case Reconstructable

Case identity and scope

Strong case

The fictional case has a unique identifier, clear title, business service, assets, identities, data, suppliers, time window, environment, and explicit exclusions.

Weak case

The case title repeats the alert name but does not define what is actually being investigated.

Reviewer question

What exact question does the case answer?

Ownership and authority

Strong case

The fictional case owner, service owner, control owner, risk owner, supplier owner, responder, communicator, and decision authority are identified.

Weak case

The case is assigned to the SOC with no specific accountable role.

Reviewer question

Who owns the work, service, control, risk, and final decision?

Evidence references

Strong case

Each fictional item has an identifier, source, owner, timestamp, relevance, source health, scope, handling record, confidence, and limitation.

Weak case

The analyst pastes untraceable text or screenshots into notes.

Reviewer question

Can another reviewer locate and understand each supporting item?

Timeline

Strong case

The fictional case records alert receipt, event time, evidence collection, actions, approvals, communications, source gaps, decisions, validation, and closure in order.

Weak case

Notes are written as a paragraph with no timestamps.

Reviewer question

Can another reviewer reconstruct what happened and when?

Facts and hypotheses

Strong case

The fictional case separates direct observations, supported conclusions, hypotheses, alternatives, missing evidence, potential impact, confirmed impact, and unsupported claims.

Weak case

Possible explanations are written as facts.

Reviewer question

Which statements are observed, inferred, possible, or unproven?

Actions and decisions

Strong case

The fictional record identifies requested and completed actions, owner, authority, reason, result, rollback, validation, and decision deadline.

Weak case

A ticket is marked complete without explaining what changed or who approved it.

Reviewer question

What was done, why, by whom, with what result?

Communication

Strong case

The fictional case records audience, sender, approved facts, uncertainty, impact status, decision needs, commitments, and next update.

Weak case

Informal messages create conflicting or unsupported statements.

Reviewer question

Who was told what, when, and under which evidence limits?

Closure and improvement

Strong case

The fictional case closes only after security and business validation, source-health review, residual risk, owner signoff, follow-up, metrics, and improvement actions.

Weak case

The case closes when the alert disappears or the shift ends.

Reviewer question

What proves the case is complete and what must improve?

Evidence Quality

Eight Fictional Evidence Review Dimensions

Relevance

Good practice

The fictional evidence directly supports or challenges the case question, scope, timeline, identity, service, control, impact, or action.

Quality risk

A large amount of technically interesting data is included even though it does not affect the decision.

Review check

Why is this item needed?

Source health

Good practice

The fictional source is current, timely, correctly parsed, available, owned, and known to cover the intended data.

Quality risk

A delayed, stale, incomplete, duplicated, or misparsed source is treated as fully reliable.

Review check

Can the source support the conclusion?

Timestamp quality

Good practice

The fictional event, receipt, collection, action, communication, and validation times are distinguished and normalized.

Quality risk

Different time zones or delayed ingestion create a false sequence.

Review check

Which time does each timestamp represent?

Traceability

Good practice

The fictional item has a stable identifier, origin, owner, collection method, case link, and reviewer path.

Quality risk

Evidence is copied without a source reference.

Review check

Can another reviewer find the original approved record?

Integrity concept

Good practice

The fictional item is protected, access-controlled, versioned, and documented during collection, transfer, review, and storage.

Quality risk

Analyst notes overwrite the original or mix observations with interpretations.

Review check

How do we know which record was reviewed?

Consistency

Good practice

The fictional evidence is compared across independent or complementary sources and conflicts are documented.

Quality risk

One source is accepted even when another healthy source disagrees.

Review check

Do related sources support the same event and scope?

Scope

Good practice

The fictional item identifies included systems, identities, data, actions, time periods, regions, suppliers, and exclusions.

Quality risk

A narrow event is described as organization-wide.

Review check

What does the item cover and not cover?

Confidence and limitation

Good practice

The fictional case records how strongly the evidence supports the conclusion and what remains unknown.

Quality risk

The finding sounds certain even when evidence is partial.

Review check

What could change this conclusion?

Case Status Model

Eight Fictional Case States

New

Meaning

A fictional alert or request has been received but source validation and ownership are not complete.

Entry condition

Alert or request meets case-opening criteria.

Exit condition

Owner, scope, source health, and initial priority are documented.

Triaging

Meaning

A fictional analyst is validating sources, gathering context, checking duplicates, and assigning priority.

Entry condition

Initial owner accepts the record.

Exit condition

Disposition is documented and the case is closed, linked, monitored, or advanced.

Investigating

Meaning

The fictional case requires deeper evidence correlation, owner context, hypotheses, findings, or scope review.

Entry condition

Triage identifies unresolved questions or meaningful risk.

Exit condition

The case moves to response, owner decision, monitoring, or review.

Awaiting Owner

Meaning

A fictional service, control, supplier, risk, privacy, or business owner must provide evidence or authority.

Entry condition

The request, deadline, and escalation path are documented.

Exit condition

The owner responds or escalation changes the action path.

Responding

Meaning

Authorized fictional containment, correction, recovery, source repair, access change, or supplier action is underway.

Entry condition

Action authority, plan, owner, rollback, communication, and validation are approved.

Exit condition

Action results are available for validation.

Monitoring

Meaning

The fictional immediate action is complete or risk is stable, but defined observation or supplier recovery continues.

Entry condition

Monitoring objective, duration, source, threshold, owner, and escalation trigger are documented.

Exit condition

The monitoring condition is satisfied or requires renewed action.

Ready for Review

Meaning

The fictional case owner believes evidence, actions, validation, decisions, and closure criteria are complete.

Entry condition

Required records and signoffs are assembled.

Exit condition

Peer or manager approves closure or returns the case for correction.

Closed

Meaning

The fictional case has approved closure, retained evidence references, residual-risk disposition, follow-up, and review triggers.

Entry condition

Security and business outcomes are validated and owner signoff is recorded.

Exit condition

A new event or reassessment trigger may reopen or create a linked case.

Case Register

Northbridge Fictional SOC Cases

NBR-CASE-221

Scheduled maintenance access alert

InvestigatingTier 2 Analyst

Scope

Confidential support service, maintenance identity, approved change window, related alert and storage evidence.

Evidence

Healthy primary alert source, approved change, authorized identity, two prior similar events, delayed supporting storage source.

Decision

Continue validation and detection-tuning review; incident declaration is not supported.

Next action

Recover or justify the delayed source and complete service-owner validation.

Evidence limit

No unauthorized access, exposure, or service impact is confirmed.

NBR-CASE-222

Expired supplier account

Awaiting OwnerThird-Party Risk Owner

Scope

One limited supplier account, confidential support service, expired exception, ended project, and incomplete activity review.

Evidence

Identity register, exception record, sponsor record, project closure, service scope, and access status.

Decision

Remove or narrowly renew the access through authorized governance.

Next action

Complete post-expiration activity review and validate approved support needs.

Evidence limit

No misuse or disclosure is confirmed.

NBR-CASE-223

Critical audit-source delivery gap

RespondingTelemetry Owner

Scope

Reporting Service audit source, forty-minute gap, compensating sources, affected case coverage, and restoration.

Evidence

Source-health monitor, expected delivery, last received event, parser status, service ownership, and compensating records.

Decision

Treat as High-priority monitoring risk and restore source delivery.

Next action

Validate recovered events, gap completeness, parsing, retention, and alert function.

Evidence limit

No malicious activity during the gap is confirmed.

NBR-CASE-224

Unapproved confidential storage-policy change

InvestigatingService Owner

Scope

One storage policy, confidential collection, change identity, approved baseline, effective permissions, and change window.

Evidence

Configuration history, identity activity, change calendar, policy baseline, service map, and current permissions.

Decision

Confirm intent and coordinate authorized rollback if the change is unsupported.

Next action

Validate effective access, service function, monitoring, and owner approval.

Evidence limit

No unauthorized data access is confirmed.

NBR-CASE-225

Historical endpoint alert duplicate

Ready for ReviewTier 1 Analyst

Scope

One three-week-old endpoint alert linked to a validated closed case with no new activity.

Evidence

Original case, containment record, endpoint health, validation, closure, and duplicate relationship.

Decision

Link as duplicate and close proportionately.

Next action

Peer-review the linkage and confirm no new scope.

Evidence limit

A new related event would require reassessment.

NBR-CASE-226

Supplier notification delay

MonitoringCommunications Service Owner

Scope

Communications provider, major user-notification window, delayed delivery, alternate channel, supplier status, and business deadline.

Evidence

Supplier status, internal delivery metrics, user-notification plan, alternate channel test, and owner communications.

Decision

Use alternate communication and monitor provider recovery.

Next action

Validate delivery completion and document supplier follow-up.

Evidence limit

Operational degradation is supported; malicious cause is not.

NBR-CASE-227

Emergency exercise sign-in

Ready for ReviewTier 2 Analyst

Scope

One administrator, approved emergency network, documented exercise, privileged session, and exercise tasks.

Evidence

Exercise plan, access approval, sign-in, session actions, owner validation, and closure record.

Decision

Classify as expected exercise behavior after final validation.

Next action

Close with evidence and note detection-tuning considerations.

Evidence limit

The exercise result does not make future unusual sign-ins automatically benign.

NBR-CASE-228

Repeated user lockouts

ClosedIdentity Support

Scope

One fictional user, password-reset issue, repeated lockouts, help-desk case, and identity health.

Evidence

Help-desk record, password-reset timeline, sign-in failures, user validation, and identity owner review.

Decision

Resolved as a supported user issue with no compromise evidence.

Next action

Monitor only if pattern or scope changes.

Evidence limit

The result applies only to this user and time period.

Case Workflow

Eight Steps from Case Opening to Improvement

1

Open or link the case

Confirm the fictional alert relationship, case question, scope, priority, owner, service, time window, privacy boundary, and existing records.

Output: Case charter.

2

Create the evidence register

Index fictional sources, identifiers, owners, timestamps, relevance, health, scope, handling, confidence, and limitations.

Output: Evidence register.

3

Build the timeline

Order fictional event, alert, receipt, collection, action, communication, approval, source-gap, validation, and closure times.

Output: Case timeline.

4

Document facts and hypotheses

Separate fictional observations, supported conclusions, hypotheses, alternatives, missing evidence, potential impact, confirmed impact, and unsupported claims.

Output: Reasoning matrix.

5

Track actions and decisions

Record fictional owner, authority, request, task, result, blocked condition, deadline, rollback, validation, and decision rationale.

Output: Action and decision log.

6

Coordinate communication

Document fictional audience, approved facts, uncertainty, service status, decision needs, commitments, supplier contacts, and next update.

Output: Communication record.

7

Validate outcomes

Confirm fictional security result, business function, source health, control operation, supplier action, recovery, residual risk, and owner approval.

Output: Validation record.

8

Review, close, and improve

Complete fictional peer review, closure criteria, retention, linkage, lessons learned, detection or runbook updates, metrics, and reassessment triggers.

Output: Closure and improvement package.

Fake Dashboard

Fake Northbridge Case Management Dashboard

Training dashboard for fictional SOC case evidence only.

Open cases

6

Investigating, Awaiting Owner, Responding, Monitoring, and Ready for Review states are represented.

Evidence-quality issues

2

One delayed supporting source and one incomplete post-expiration activity review limit confidence.

Cases ready to close

3

Duplicate, exercise, and user-lockout cases are ready or already closed with proportional validation.

Fake SOC Alert

Case Ready for Closure but Supporting Evidence Is Still Delayed

Source: Fake Northbridge Case Quality Console • Time: 8:18 PM

Medium Severity
A fictional maintenance-access case has healthy primary evidence and approved context, but one supporting storage source remains delayed while the case owner marked the record Ready for Review.
Defensive recommendation: Return the case to Investigating unless the owner documents why the missing source is non-material. Preserve the limitation, confirm scope, validate service behavior, review detection tuning, and require peer approval before closure.

Fake Log Panel

Fake Northbridge Case Timeline

training-log-viewer.log
18:20 EVENT maintenance-access='observed'
18:21 ALERT received='primary detection'
18:22 SOURCE primary='healthy'
18:24 SOURCE storage-support='delayed'
18:28 CASE opened='NBR-CASE-221'
18:32 OWNER assigned='Tier2-A'
18:40 CONTEXT change-window='approved'
18:44 IDENTITY maintenance='authorized'
18:52 HYPOTHESIS expected-maintenance='supported but unproven'
19:05 REQUEST service-owner='validation'
19:18 FINDING incident='not supported'
19:32 ACTION tuning-review='opened'
19:48 COMMUNICATION impact='unconfirmed'
20:05 SOURCE storage-support='still delayed'
20:12 STATUS ready-for-review='premature'
20:18 QUALITY return-to='Investigating'

Training note: this is fake data for defensive analysis practice only.

Findings Matrix

Northbridge Case-Management Findings and Limits

NBR-CAS-F01Medium-High

The fictional maintenance-access case should remain open until the delayed source is recovered or its absence is formally accepted as non-material.

Evidence support

Open investigation, delayed supporting source, approved maintenance context, healthy primary evidence, and defined closure criteria.

Alternative

The available evidence may already be sufficient if the missing source cannot change the decision.

Limitation

The value of the missing source is not yet fully known.

NBR-CAS-F02High

The fictional expired supplier account requires a distinct owned case because active unsupported capability remains after project closure.

Evidence support

Active account, expired exception, ended project, confidential service scope, named supplier owner, and incomplete activity review.

Alternative

A current support need may justify a narrow renewed access path.

Limitation

No misuse or disclosure is confirmed.

NBR-CAS-F03High

The fictional source-gap case should record both the monitoring risk and the absence of confirmed malicious activity.

Evidence support

Confirmed forty-minute delivery gap, critical service, healthy source monitor, compensating sources, and no suspicious-event evidence.

Alternative

Later recovered events could change the case scope.

Limitation

The blind-spot period is not yet fully reconstructed.

NBR-CAS-F04High

The fictional historical endpoint alert should be linked to the original case rather than managed as an independent high-priority case.

Evidence support

Old event, validated containment, closed original case, no new activity, and direct duplicate relationship.

Alternative

New scope or activity would justify a separate or reopened case.

Limitation

The analyst must verify that no new evidence exists.

NBR-CAS-F05Medium-High

The fictional supplier delay case supports operational impact and alternate communication, but not a security-incident conclusion.

Evidence support

Supplier status, delayed delivery, major notification window, alternate channel, business-owner decision, and no malicious indicators.

Alternative

Later supplier evidence could identify a security cause.

Limitation

Supplier root cause is not yet final.

NBR-CAS-F06High

A fictional case should not be closed solely because the alert stopped or the action ticket completed.

Evidence support

Case workflow, evidence requirements, business validation, source health, residual risk, owner signoff, and improvement needs.

Alternative

Low-risk duplicate cases may use simplified closure under an approved runbook.

Limitation

Closure depth should remain proportionate to case risk.

Analyze the Evidence

Is the Maintenance Case Ready to Close?

The fictional primary alert source is healthy.
The maintenance change and identity are approved.
The service owner supports the expected activity explanation.
One supporting storage source remains delayed.
The detection-tuning review is open.
No unauthorized access or impact is confirmed.

Which conclusion is strongest?

Common Mistakes

Mistakes That Weaken Case Management and Evidence Handling

Treating fictional analyst notes as a substitute for traceable evidence references.
Combining alerts with different assets, identities, time periods, causes, or owners into one unclear case.
Opening separate cases for duplicates without preserving one coherent timeline and owner.
Using the alert timestamp as though it were also the event, receipt, collection, and action time.
Writing hypotheses, assumptions, or potential impact as confirmed facts.
Failing to record source delays, missing data, conflicting evidence, or scope exclusions.
Pasting unnecessary sensitive information into a case rather than minimizing and referencing approved evidence.
Recording an action without its owner, authority, reason, result, rollback, and validation.
Allowing informal messages to replace the approved communication record.
Closing a case when the alert disappears, the shift ends, or the ticket is marked complete.
Failing to link related cases, incidents, suppliers, risks, controls, changes, or lessons learned.
Editing original evidence or mixing it with analyst interpretation.
Retaining fictional case data forever without a defined purpose or review.
Using or exposing any real credentials, employee information, school records, private company alerts, logs, supplier records, incident evidence, case data, or confidential SOC information.

Safe Practice Lab

Build the Northbridge Case Management and Evidence Package

Your fictional assignment

Case Scope, Evidence, Timeline, Actions, Decisions, and Closure

Use only the supplied fictional Northbridge records to produce a complete, reviewable SOC case package.

Required deliverables

  1. Case charter with question, scope, exclusions, priority, owners, authority, privacy, and decision deadline.
  2. Evidence register with identifiers, sources, owners, timestamps, relevance, health, scope, handling, confidence, and limits.
  3. Normalized case timeline distinguishing event, receipt, collection, action, communication, approval, and validation time.
  4. Facts, findings, hypotheses, alternatives, missing evidence, potential impact, confirmed impact, and unsupported claims matrix.
  5. Action, decision, communication, supplier-contact, rollback, and validation logs.
  6. Case linkage and duplicate-handling record.
  7. Status, handoff, closure, retention, quality-review, metrics, and improvement plan.
  8. Technical summary, leadership summary, reflection, and portfolio-safety statement.
Complete the lab only with fictional evidence displayed on this page. Do not use real credentials, employee information, school records, company alerts, logs, supplier records, incidents, case data, or confidential SOC information.

Scenario Decision Lab

A Reviewer Wants to Close the Case before the Delayed Source Recovers

The fictional maintenance explanation is well supported, but one source remains delayed and the case’s tuning action is still open.

Scenario Decision Lab

A Duplicate High-Severity Alert Appears after the Original Case Closed

The fictional alert matches the same historical event and adds no new identity, asset, time period, activity, or impact.

Defender Habits

Case Management and Evidence Handling Checklist

Check Your Understanding

I15.3 Mini Quiz: Case Management and Evidence Handling

Choose your answers first. Explanations appear only after submission.

1. What is the main purpose of a fictional SOC case?

2. What makes a fictional evidence item traceable?

3. Why should a fictional timeline distinguish event time from receipt time?

4. What should happen to a fictional hypothesis?

5. When is a fictional case ready for closure?

6. What should happen to a fictional duplicate alert?

7. What makes a fictional case-management finding defensible?

Portfolio Prompt

Portfolio Prompt

Create a fictional Case Management and Evidence Handling Package for Northbridge. Include the case charter, case register, evidence register, normalized timeline, facts and hypothesis matrix, action log, decision log, communication record, case-linkage model, status workflow, handoff, validation, closure criteria, retention, quality review, metrics, leadership summary, reflection, and a portfolio-safety statement.

Use only fictional alerts, cases, systems, identities, suppliers, services, evidence, timestamps, actions, decisions, communications, and outcomes.
Do not treat analyst notes, alert severity, source delays, duplicate titles, completed tickets, or likely explanations as automatic proof.
Make every finding traceable to evidence, scope, timeline, confidence, limitations, owner, authority, and next action.
Show why a case can have a likely benign explanation and still remain open because required evidence or follow-up is incomplete.

Key Takeaways

What You Should Remember

1.A SOC case connects related alerts, evidence, actions, decisions, owners, communications, validation, and outcomes.
2.Evidence should be relevant, healthy enough, timestamped, traceable, scoped, protected, and limited.
3.Hypotheses guide investigation but should never be written as confirmed findings.
4.Case timelines should distinguish event, receipt, collection, action, communication, approval, and validation times.
5.Duplicate alerts should be linked without losing history or new scope.
6.Closure requires validated security and business outcomes, source-health review, residual risk, signoff, and improvement.
7.Portfolio artifacts should use fully fictional evidence and never expose real organizational records.

Navigation

Continue Module I15