{
  "caseVersion": "2026.08.31-practice-3",
  "caseTitle": "SilverPine payment-change incident",
  "disclosure": "This fictional, sanitized defensive-security case contains no real credentials, account numbers, personal data, or exploitable instructions. It is not legal, forensic, insurance, or cybersecurity assurance.",
  "caseBrief": "SilverPine Fabrication is a fictional 38-person manufacturer. At 9:12 a.m., accounts payable received an email inside an existing supplier thread requesting that the next $84,600 payment move to a new bank. The message used the supplier controller's display name and included an attached letter, but the phone number on the letter differs from the approved supplier record. At 9:26, an employee opened the attachment and entered a cloud password on a page that later disappeared. At 9:31, a push-notification approval arrived; the employee denied it and called the office manager. The manager told the employee to change the password from the same laptop but did not contact the incident lead. Email logs available to the internal administrator show a new forwarding rule created at 9:29 and a login from an unfamiliar region. The laptop reports that endpoint protection last checked in 11 days ago. The supplier master record can be changed by three accounts; one belongs to a former contractor and has no recorded multi-factor authentication. Backups run nightly to a connected network share. The dashboard is green, but the last documented restoration test occurred 14 months ago and recovered only one folder. The company's incident sheet lists names but no after-hours method, severity criteria, evidence-preservation steps, payment-hold authority, or customer and regulatory decision process. No payment has been released. Learners must map assets and responsibility, protect authentication and recovery, verify communication independently, manage device and software actions, assess data, vendor, and backup controls, and construct an authorized incident response. They must not investigate outside authorization, contact an attacker, destroy evidence, or declare breach scope and legal notification obligations without qualified review.",
  "facts": [
    {
      "id": "F01",
      "confidence": "confirmed",
      "record": "A supplier-thread email requests an $84,600 payment to a new bank."
    },
    {
      "id": "F02",
      "confidence": "confirmed",
      "record": "The letter's phone number differs from the approved supplier record."
    },
    {
      "id": "F03",
      "confidence": "confirmed",
      "record": "An employee entered a cloud password after opening the attachment."
    },
    {
      "id": "F04",
      "confidence": "confirmed",
      "record": "The employee denied an unexpected push notification and reported to the office manager."
    },
    {
      "id": "F05",
      "confidence": "confirmed",
      "record": "A new forwarding rule and unfamiliar-region login appear in administrative logs."
    },
    {
      "id": "F06",
      "confidence": "confirmed",
      "record": "The manager advised a password change from the same possibly affected laptop."
    },
    {
      "id": "F07",
      "confidence": "confirmed",
      "record": "Endpoint protection on the laptop last checked in eleven days ago."
    },
    {
      "id": "F08",
      "confidence": "confirmed",
      "record": "Three accounts can change supplier banking details."
    },
    {
      "id": "F09",
      "confidence": "confirmed",
      "record": "One privileged account belongs to a former contractor and lacks recorded multi-factor authentication."
    },
    {
      "id": "F10",
      "confidence": "confirmed",
      "record": "Nightly backups write to a connected network share."
    },
    {
      "id": "F11",
      "confidence": "confirmed",
      "record": "The last recorded restore test was fourteen months ago and covered one folder."
    },
    {
      "id": "F12",
      "confidence": "confirmed",
      "record": "No payment has been released and the incident sheet lacks operative decision rules."
    }
  ],
  "challenges": [
    {
      "module": 1,
      "title": "Map business exposure",
      "prompt": "Identify critical processes, assets, owners, dependencies, consequences, and immediate authority gaps.",
      "deliverable": "A prioritized asset-process map and responsibility matrix.",
      "evidenceCriteria": [
        "Connects email, identity, supplier master, payment, endpoint, logs, backups, and vendors",
        "Ranks payment diversion, account takeover, evidence loss, and operational disruption",
        "Names who may hold payment, contain accounts, preserve evidence, and escalate",
        "Cites the supplied input IDs for material statements and marks omitted operational records or results “not supplied” rather than fabricating them"
      ],
      "taskMode": "bounded-case-starter",
      "providedInputs": [
        {
          "id": "M01-I01",
          "kind": "case-fact",
          "sourceFactIds": [
            "F01"
          ],
          "confidence": "confirmed",
          "record": "A supplier-thread email requests an $84,600 payment to a new bank."
        },
        {
          "id": "M01-I02",
          "kind": "case-fact",
          "sourceFactIds": [
            "F02"
          ],
          "confidence": "confirmed",
          "record": "The letter's phone number differs from the approved supplier record."
        },
        {
          "id": "M01-I03",
          "kind": "case-fact",
          "sourceFactIds": [
            "F03"
          ],
          "confidence": "confirmed",
          "record": "An employee entered a cloud password after opening the attachment."
        },
        {
          "id": "M01-I04",
          "kind": "case-fact",
          "sourceFactIds": [
            "F04"
          ],
          "confidence": "confirmed",
          "record": "The employee denied an unexpected push notification and reported to the office manager."
        },
        {
          "id": "M01-I05",
          "kind": "case-fact",
          "sourceFactIds": [
            "F05"
          ],
          "confidence": "confirmed",
          "record": "A new forwarding rule and unfamiliar-region login appear in administrative logs."
        },
        {
          "id": "M01-I06",
          "kind": "case-fact",
          "sourceFactIds": [
            "F06"
          ],
          "confidence": "confirmed",
          "record": "The manager advised a password change from the same possibly affected laptop."
        },
        {
          "id": "M01-I07",
          "kind": "case-fact",
          "sourceFactIds": [
            "F07"
          ],
          "confidence": "confirmed",
          "record": "Endpoint protection on the laptop last checked in eleven days ago."
        },
        {
          "id": "M01-I08",
          "kind": "case-fact",
          "sourceFactIds": [
            "F08"
          ],
          "confidence": "confirmed",
          "record": "Three accounts can change supplier banking details."
        },
        {
          "id": "M01-I09",
          "kind": "case-fact",
          "sourceFactIds": [
            "F09"
          ],
          "confidence": "confirmed",
          "record": "One privileged account belongs to a former contractor and lacks recorded multi-factor authentication."
        },
        {
          "id": "M01-I10",
          "kind": "case-fact",
          "sourceFactIds": [
            "F10"
          ],
          "confidence": "confirmed",
          "record": "Nightly backups write to a connected network share."
        },
        {
          "id": "M01-I11",
          "kind": "case-fact",
          "sourceFactIds": [
            "F11"
          ],
          "confidence": "confirmed",
          "record": "The last recorded restore test was fourteen months ago and covered one folder."
        },
        {
          "id": "M01-I12",
          "kind": "case-fact",
          "sourceFactIds": [
            "F12"
          ],
          "confidence": "confirmed",
          "record": "No payment has been released and the incident sheet lacks operative decision rules."
        },
        {
          "id": "M01-B01",
          "kind": "case-brief",
          "sourceFactIds": [],
          "sourceRecordIds": [
            "CB01"
          ],
          "confidence": "mixed",
          "record": "Use CB01, the full versioned case brief printed once at the start of this packet, as a citable narrative source for details not normalized into F01–F12. Preserve its uncertainty language and do not treat narrative detail as approval, complete operational records, or professional judgment."
        },
        {
          "id": "M01-S01",
          "kind": "assignment-scope",
          "sourceFactIds": [
            "F01",
            "F02",
            "F03",
            "F04",
            "F05",
            "F06",
            "F07",
            "F08",
            "F09",
            "F10",
            "F11",
            "F12"
          ],
          "confidence": "instruction",
          "record": "Build a starter version of “A prioritized asset-process map and responsibility matrix.” from the listed case facts. Treat requested structures, controls, questions, calculations, and templates as learner-designed proposals. Where an operational record or result is absent, add a gap entry naming the missing evidence and authorized owner instead of fabricating it."
        }
      ],
      "completionBoundary": "Complete a bounded starter and gap analysis using only CB01, F01, F02, F03, F04, F05, F06, F07, F08, F09, F10, F11, F12, and the assignment-scope record below. Populate supported fields, label every unavailable field “not supplied,” and cite the input ID for each material statement. You may design a proposed template, control, question, or decision rule, but must label it as a learner proposal rather than observed case evidence. Do not contact people, access live systems, run tests, sign records, claim approval, or invent names, dates, quotations, transactions, results, or source documents.",
      "starterSchema": {
        "id": "M01-W02",
        "title": "Map business exposure guided artifact-build sheet",
        "columns": [
          "Component ID",
          "Requested artifact component",
          "Evidence criterion to test",
          "Supplied input IDs",
          "Supported entry",
          "Not-supplied gap or learner proposal",
          "Authorized owner or reviewer",
          "Status"
        ],
        "rows": [
          {
            "id": "M01-A01",
            "component": "Prioritized asset-and-process map",
            "criterion": "Connects email, identity, supplier master, payment, endpoint, logs, backups, and vendors | Names who may hold payment, contain accounts, preserve evidence, and escalate | Cites the supplied input IDs for material statements and marks omitted operational records or results “not supplied” rather than fabricating them",
            "suppliedInputIds": [
              "M01-I01",
              "M01-I02",
              "M01-I03",
              "M01-I04",
              "M01-I05",
              "M01-I06",
              "M01-I07",
              "M01-I08",
              "M01-I10",
              "M01-I12",
              "M01-I09",
              "M01-I11"
            ]
          },
          {
            "id": "M01-A02",
            "component": "Cyber responsibility matrix",
            "criterion": "Ranks payment diversion, account takeover, evidence loss, and operational disruption",
            "suppliedInputIds": [
              "M01-I09",
              "M01-I11"
            ]
          }
        ]
      },
      "workbookPlan": {
        "id": "M01-WP01",
        "version": "2026.09.01-workbook-plan-2",
        "contextInputIds": [
          "M01-B01",
          "M01-S01"
        ],
        "criterionCatalog": [
          {
            "id": "M01-EC01",
            "text": "Connects email, identity, supplier master, payment, endpoint, logs, backups, and vendors"
          },
          {
            "id": "M01-EC02",
            "text": "Ranks payment diversion, account takeover, evidence loss, and operational disruption"
          },
          {
            "id": "M01-EC03",
            "text": "Names who may hold payment, contain accounts, preserve evidence, and escalate"
          },
          {
            "id": "M01-EC04",
            "text": "Cites the supplied input IDs for material statements and marks omitted operational records or results “not supplied” rather than fabricating them"
          }
        ],
        "artifacts": [
          {
            "id": "M01-A01",
            "title": "Prioritized asset-and-process map",
            "type": "map",
            "purpose": "Produce a bounded, reviewable prioritized asset-and-process map from cited packet evidence while exposing unsupported fields and required approvals.",
            "instructions": "Use only the scoped case-fact inputs below. Cite an input ID for each supported statement; label proposed structures “learner proposal” and unavailable evidence “not supplied.”",
            "columns": [
              "Element",
              "From or trigger",
              "To or outcome",
              "Evidence and source ID",
              "Owner",
              "Open question",
              "Status"
            ],
            "rowPlan": {
              "count": 13,
              "prefix": "01A01R",
              "blankState": "Not supplied / learner to complete"
            },
            "reviewedMappingId": "cybersecurity-fundamentals:M01:A01",
            "criterionIds": [
              "M01-EC01",
              "M01-EC03",
              "M01-EC04"
            ],
            "inputIds": [
              "M01-I01",
              "M01-I02",
              "M01-I03",
              "M01-I04",
              "M01-I05",
              "M01-I06",
              "M01-I07",
              "M01-I08",
              "M01-I10",
              "M01-I12",
              "M01-I09",
              "M01-I11"
            ],
            "completionChecks": [
              "Every supported entry identifies and cites at least one applicable scoped case-fact input (M01-I01, M01-I02, M01-I03, M01-I04, M01-I05, M01-I06, M01-I07, M01-I08, M01-I10, M01-I12).",
              "Every mapped rubric criterion (M01-EC01, M01-EC03, M01-EC04) is addressed in the artifact or a named evidence gap.",
              "Unsupported fields remain “not supplied” or are explicitly labeled as a learner proposal.",
              "The Authorized system owner or qualified security specialist is named for decisions or review; no approval or execution is implied."
            ]
          },
          {
            "id": "M01-A02",
            "title": "Cyber responsibility matrix",
            "type": "matrix",
            "purpose": "Produce a bounded, reviewable cyber responsibility matrix from cited packet evidence while exposing unsupported fields and required approvals.",
            "instructions": "Use only the scoped case-fact inputs below. Cite an input ID for each supported statement; label proposed structures “learner proposal” and unavailable evidence “not supplied.”",
            "columns": [
              "Item ID",
              "Supported evidence",
              "Source input ID",
              "Criterion or required state",
              "Gap or learner proposal",
              "Owner or reviewer",
              "Status"
            ],
            "rowPlan": {
              "count": 2,
              "prefix": "01A02R",
              "blankState": "Not supplied / learner to complete"
            },
            "reviewedMappingId": "cybersecurity-fundamentals:M01:A02",
            "criterionIds": [
              "M01-EC02"
            ],
            "inputIds": [
              "M01-I09",
              "M01-I11"
            ],
            "completionChecks": [
              "Every supported entry identifies and cites at least one applicable scoped case-fact input (M01-I09, M01-I11).",
              "Every mapped rubric criterion (M01-EC02) is addressed in the artifact or a named evidence gap.",
              "Unsupported fields remain “not supplied” or are explicitly labeled as a learner proposal.",
              "The Authorized system owner or qualified security specialist is named for decisions or review; no approval or execution is implied."
            ]
          }
        ],
        "quantityContracts": [
          {
            "artifactId": "M01-A01",
            "rowCount": 13,
            "rowPrefix": "01A01R"
          },
          {
            "artifactId": "M01-A02",
            "rowCount": 2,
            "rowPrefix": "01A02R"
          }
        ],
        "workedStarter": {
          "artifactId": "M01-A01",
          "criterionId": "M01-EC01",
          "inputId": "M01-I01",
          "supportedValue": "A supplier-thread email requests an $84,600 payment to a new bank.",
          "application": "Anchor one element of the map to the supplied condition and label any inferred transition as a learner proposal. Cite M01-I01 (F01) in the row.",
          "boundary": "This is one evidence-backed starter entry, not a completed prioritized asset-and-process map or an operational result."
        },
        "knownGap": {
          "artifactId": "M01-A01",
          "criterionId": "M01-EC01",
          "missingEvidence": "The packet does not supply the complete live records, approvals, or execution results needed to finish the prioritized asset-and-process map.",
          "whyItMatters": "Without that evidence, the learner cannot truthfully satisfy M01-EC01 or represent this artifact as complete.",
          "ownerRole": "Authorized system owner or qualified security specialist",
          "boundedNextStep": "Record the missing evidence in M01-A01, name the authorized reviewer, and leave the outcome pending; do not obtain or simulate the live record in this exercise.",
          "status": "Open — not supplied"
        },
        "decisionPrompt": {
          "inputId": "M01-I12",
          "prompt": "What bounded decision can the Authorized system owner or qualified security specialist make from M01-I12, and what must remain pending until the missing evidence or approval is supplied?"
        },
        "instructionalGuide": {
          "version": "2026.09.01-academy-workbook-instruction-bank-1",
          "principalArtifactId": "M01-A01",
          "prerequisiteCheck": [
            "Confirm F01-F12; record that authoritative asset inventory, data classification, business-impact tiers, system owners, network/data-flow diagrams, supplier contacts, backup topology, and risk acceptance are not supplied.",
            "STOP. If asset ownership, classification, impact tiers, data flows, supplier contacts, backup topology, or risk acceptance is missing or conflicts across F01–F12, route the exposure map to authorized finance, security, and IT owners; do not claim risk approval or execute payment, access, containment, or recovery action."
          ],
          "operatingSteps": [
            "Inventory the payment, email, identity, endpoint, supplier-master, administrative-log, and backup processes named in the case.",
            "Map the supplier request from email receipt through banking-detail change and payment authorization.",
            "Map credential entry, unexpected push, forwarding rule, unfamiliar login, and endpoint-health facts as linked observations without declaring root cause.",
            "Map who can change banking details and flag the former-contractor privileged account as an access-governance gap.",
            "Map connected backups and stale restore testing as resilience dependencies.",
            "Prioritize by potential business impact and evidence strength, not by invented likelihood.",
            "Final-QC every node for source ID, owner role, open question, priority rationale, and no implied containment."
          ],
          "fieldGuidance": {
            "Element": "Name the process node, asset, state, or transition. Module use: Use the map to connect the payment, identity, endpoint, access, and recovery exposure before selecting controls.",
            "From or trigger": "State the observable event that activates the path. Module use: Use the map to connect the payment, identity, endpoint, access, and recovery exposure before selecting controls.",
            "To or outcome": "State the proposed next state without implying execution. Module use: Use the map to connect the payment, identity, endpoint, access, and recovery exposure before selecting controls.",
            "Evidence and source ID": "Pair the observation with its exact supplied source ID. Module use: Use the map to connect the payment, identity, endpoint, access, and recovery exposure before selecting controls.",
            "Owner": "Name the authorized operating or specialist role. Module use: Use the map to connect the payment, identity, endpoint, access, and recovery exposure before selecting controls.",
            "Open question": "Record the unanswered question that prevents a final decision. Module use: Use the map to connect the payment, identity, endpoint, access, and recovery exposure before selecting controls.",
            "Status": "Use a truthful state such as draft, open—not supplied, review pending, or blocked. Module use: Use the map to connect the payment, identity, endpoint, access, and recovery exposure before selecting controls."
          },
          "completedExampleRow": {
            "Element": "Supplier-payment change path",
            "From or trigger": "Email requests an $84,600 payment to a new bank.",
            "To or outcome": "Verification and authorized banking-change/payment decision path.",
            "Evidence and source ID": "F01, F02, F12",
            "Owner": "Finance/payment process owner with security and supplier-management reviewers",
            "Open question": "Approved supplier contact, change-control record, dual-authorization rule, and decision log are not supplied.",
            "Status": "Priority 1 - verification and review pending"
          },
          "completedKnownGapRow": {
            "Element": "Backup-recovery dependency",
            "From or trigger": "Nightly backup writes to a connected network share.",
            "To or outcome": "Verified isolated recovery path and restore evidence.",
            "Evidence and source ID": "F10, F11",
            "Owner": "IT/recovery owner",
            "Open question": "Backup separation, retention, recovery objectives, full restore scope, and current test result are not supplied.",
            "Status": "Open - recovery evidence absent"
          },
          "supportingArtifacts": [
            {
              "artifactId": "M01-A02",
              "artifactTitle": "Cyber responsibility matrix",
              "criterionIds": [
                "M01-EC02"
              ],
              "exampleType": "completed-supporting-artifact-row",
              "rationale": "The canonical M01-A02 route maps M01-EC02. The row visibly ranks all four required risk families using the supplied scenario evidence and distinguishes a provisional learner priority from an approved assessment.",
              "finalColumns": [
                "Item ID",
                "Supported evidence",
                "Source input ID",
                "Criterion or required state",
                "Gap or learner proposal",
                "Owner or reviewer",
                "Status"
              ],
              "row": {
                "Item ID": "CYBER-RISK-01",
                "Supported evidence": "Learner-proposed priority order: 1 payment diversion from the new-bank request; 2 account takeover from credential entry, suspicious forwarding, and unfamiliar login; 3 evidence loss from a stale endpoint and unverified connected-share backups; 4 operational disruption where incident decision rules are absent.",
                "Source input ID": "M01-I01 (F01), M01-I02 (F02), M01-I03 (F03), M01-I05 (F05), M01-I07 (F07), M01-I10 (F10), M01-I11 (F11), and M01-I12 (F12)",
                "Criterion or required state": "Authorized owners confirm or revise the four-category order using documented impact, likelihood, dependency, and recoverability evidence.",
                "Gap or learner proposal": "Impact values, likelihood estimates, recovery objectives, current restore evidence, and approved prioritization are not supplied; the ordering is a learner proposal, not a completed risk assessment.",
                "Owner or reviewer": "Finance/payment owner, security/identity owner, IT/recovery owner, and incident commander",
                "Status": "Draft — authorized risk review pending"
              },
              "status": "normalized"
            }
          ],
          "decisionRule": {
            "stop": "Stop payment, access, or recovery assurance claims when authoritative ownership, verification, inventory, or test evidence is absent.",
            "go": "Proceed to qualified review when assets/processes, sources, owners, impact rationale, and open questions are visible.",
            "escalate": "Escalate the payment request, identity compromise indicators, privileged former-contractor access, and recovery weakness to the designated finance/security/IT owners."
          },
          "completionTest": [
            "Payment, email, identity, endpoint, privilege, supplier, log, and backup flows are mapped.",
            "F09 and F11 are visible rather than hidden in secondary artifacts.",
            "No compromise, containment, or recovery outcome is asserted."
          ],
          "criterionSatisfiability": [
            {
              "criterionId": "M01-EC01",
              "criterionOrdinal": 1,
              "criterionText": "Connects email, identity, supplier master, payment, endpoint, logs, backups, and vendors",
              "currentSatisfiable": false,
              "afterProposedRepairsSatisfiable": true,
              "finding": "The current canonical principal-artifact route or schema cannot visibly satisfy this criterion without the listed fact-routing and/or artifact-spec repair; the learner must record the gap rather than claim completion."
            },
            {
              "criterionId": "M01-EC02",
              "criterionOrdinal": 2,
              "criterionText": "Ranks payment diversion, account takeover, evidence loss, and operational disruption",
              "currentSatisfiable": false,
              "afterProposedRepairsSatisfiable": true,
              "finding": "The current canonical principal-artifact route or schema cannot visibly satisfy this criterion without the listed fact-routing and/or artifact-spec repair; the learner must record the gap rather than claim completion."
            },
            {
              "criterionId": "M01-EC03",
              "criterionOrdinal": 3,
              "criterionText": "Names who may hold payment, contain accounts, preserve evidence, and escalate",
              "currentSatisfiable": false,
              "afterProposedRepairsSatisfiable": true,
              "finding": "The current canonical principal-artifact route or schema cannot visibly satisfy this criterion without the listed fact-routing and/or artifact-spec repair; the learner must record the gap rather than claim completion."
            },
            {
              "criterionId": "M01-EC04",
              "criterionOrdinal": 4,
              "criterionText": "Cites the supplied input IDs for material statements and marks omitted operational records or results “not supplied” rather than fabricating them",
              "currentSatisfiable": true,
              "afterProposedRepairsSatisfiable": true,
              "finding": "The criterion is teachable through the bounded instructions and artifact row, but operational evidence, execution, and reviewer acceptance remain pending."
            }
          ]
        }
      }
    },
    {
      "module": 2,
      "title": "Contain identity risk",
      "prompt": "Draft authorized account-protection and recovery steps that require a known-clean channel and administrator; do not execute containment from the training packet.",
      "deliverable": "An identity-containment checklist and access-review record template with every action, owner, authorization, time, and result field pending.",
      "evidenceCriteria": [
        "Requires a known-clean channel and authorized administrator without asserting that either is available",
        "Sequences session revocation, recovery-factor and forwarding review, and secret rotation as proposed actions rather than completed events",
        "Flags the stale privileged account and least-privilege correction for authorized execution without disabling access",
        "Cites the supplied input IDs for material statements and marks omitted operational records or results “not supplied” rather than fabricating them"
      ],
      "taskMode": "bounded-case-starter",
      "providedInputs": [
        {
          "id": "M02-I01",
          "kind": "case-fact",
          "sourceFactIds": [
            "F03"
          ],
          "confidence": "confirmed",
          "record": "An employee entered a cloud password after opening the attachment."
        },
        {
          "id": "M02-I02",
          "kind": "case-fact",
          "sourceFactIds": [
            "F04"
          ],
          "confidence": "confirmed",
          "record": "The employee denied an unexpected push notification and reported to the office manager."
        },
        {
          "id": "M02-I03",
          "kind": "case-fact",
          "sourceFactIds": [
            "F05"
          ],
          "confidence": "confirmed",
          "record": "A new forwarding rule and unfamiliar-region login appear in administrative logs."
        },
        {
          "id": "M02-I04",
          "kind": "case-fact",
          "sourceFactIds": [
            "F06"
          ],
          "confidence": "confirmed",
          "record": "The manager advised a password change from the same possibly affected laptop."
        },
        {
          "id": "M02-I05",
          "kind": "case-fact",
          "sourceFactIds": [
            "F07"
          ],
          "confidence": "confirmed",
          "record": "Endpoint protection on the laptop last checked in eleven days ago."
        },
        {
          "id": "M02-I06",
          "kind": "case-fact",
          "sourceFactIds": [
            "F08"
          ],
          "confidence": "confirmed",
          "record": "Three accounts can change supplier banking details."
        },
        {
          "id": "M02-I07",
          "kind": "case-fact",
          "sourceFactIds": [
            "F09"
          ],
          "confidence": "confirmed",
          "record": "One privileged account belongs to a former contractor and lacks recorded multi-factor authentication."
        },
        {
          "id": "M02-B01",
          "kind": "case-brief",
          "sourceFactIds": [],
          "sourceRecordIds": [
            "CB01"
          ],
          "confidence": "mixed",
          "record": "Use CB01, the full versioned case brief printed once at the start of this packet, as a citable narrative source for details not normalized into F01–F12. Preserve its uncertainty language and do not treat narrative detail as approval, complete operational records, or professional judgment."
        },
        {
          "id": "M02-S01",
          "kind": "assignment-scope",
          "sourceFactIds": [
            "F03",
            "F04",
            "F05",
            "F06",
            "F07",
            "F08",
            "F09"
          ],
          "confidence": "instruction",
          "record": "Build a starter version of “An identity-containment checklist and access-review record template with every action, owner, authorization, time, and result field pending.” from the listed case facts. Treat requested structures, controls, questions, calculations, and templates as learner-designed proposals. Where an operational record or result is absent, add a gap entry naming the missing evidence and authorized owner instead of fabricating it."
        }
      ],
      "completionBoundary": "Complete a bounded starter and gap analysis using only CB01, F03, F04, F05, F06, F07, F08, F09, and the assignment-scope record below. Populate supported fields, label every unavailable field “not supplied,” and cite the input ID for each material statement. You may design a proposed template, control, question, or decision rule, but must label it as a learner proposal rather than observed case evidence. Do not contact people, access live systems, run tests, sign records, claim approval, or invent names, dates, quotations, transactions, results, or source documents.",
      "starterSchema": {
        "id": "M02-W02",
        "title": "Contain identity risk guided artifact-build sheet",
        "columns": [
          "Component ID",
          "Requested artifact component",
          "Evidence criterion to test",
          "Supplied input IDs",
          "Supported entry",
          "Not-supplied gap or learner proposal",
          "Authorized owner or reviewer",
          "Status"
        ],
        "rows": [
          {
            "id": "M02-A01",
            "component": "Identity-containment checklist",
            "criterion": "Requires a known-clean channel and authorized administrator without asserting that either is available | Cites the supplied input IDs for material statements and marks omitted operational records or results “not supplied” rather than fabricating them",
            "suppliedInputIds": [
              "M02-I01",
              "M02-I04",
              "M02-I06",
              "M02-I02",
              "M02-I03",
              "M02-I05",
              "M02-I07"
            ]
          },
          {
            "id": "M02-A02",
            "component": "Access-review record",
            "criterion": "Sequences session revocation, recovery-factor and forwarding review, and secret rotation as proposed actions rather than completed events | Flags the stale privileged account and least-privilege correction for authorized execution without disabling access",
            "suppliedInputIds": [
              "M02-I02",
              "M02-I03",
              "M02-I05",
              "M02-I07"
            ]
          }
        ]
      },
      "workbookPlan": {
        "id": "M02-WP01",
        "version": "2026.09.01-workbook-plan-2",
        "contextInputIds": [
          "M02-B01",
          "M02-S01"
        ],
        "criterionCatalog": [
          {
            "id": "M02-EC01",
            "text": "Requires a known-clean channel and authorized administrator without asserting that either is available"
          },
          {
            "id": "M02-EC02",
            "text": "Sequences session revocation, recovery-factor and forwarding review, and secret rotation as proposed actions rather than completed events"
          },
          {
            "id": "M02-EC03",
            "text": "Flags the stale privileged account and least-privilege correction for authorized execution without disabling access"
          },
          {
            "id": "M02-EC04",
            "text": "Cites the supplied input IDs for material statements and marks omitted operational records or results “not supplied” rather than fabricating them"
          }
        ],
        "artifacts": [
          {
            "id": "M02-A01",
            "title": "Identity-containment checklist",
            "type": "checklist",
            "purpose": "Produce a bounded, reviewable identity-containment checklist from cited packet evidence while exposing unsupported fields and required approvals.",
            "instructions": "Use only the scoped case-fact inputs below. Cite an input ID for each supported statement; label proposed structures “learner proposal” and unavailable evidence “not supplied.”",
            "columns": [
              "Check ID",
              "Control or check",
              "Evidence required",
              "Source input ID",
              "Owner",
              "Result",
              "Exception or gap",
              "Status"
            ],
            "rowPlan": {
              "count": 13,
              "prefix": "02A01R",
              "blankState": "Not supplied / learner to complete"
            },
            "reviewedMappingId": "cybersecurity-fundamentals:M02:A01",
            "criterionIds": [
              "M02-EC01",
              "M02-EC04"
            ],
            "inputIds": [
              "M02-I01",
              "M02-I04",
              "M02-I06",
              "M02-I02",
              "M02-I03",
              "M02-I05",
              "M02-I07"
            ],
            "completionChecks": [
              "Every supported entry identifies and cites at least one applicable scoped case-fact input (M02-I01, M02-I04, M02-I06).",
              "Every mapped rubric criterion (M02-EC01, M02-EC04) is addressed in the artifact or a named evidence gap.",
              "Unsupported fields remain “not supplied” or are explicitly labeled as a learner proposal.",
              "The Authorized system owner or qualified security specialist is named for decisions or review; no approval or execution is implied."
            ]
          },
          {
            "id": "M02-A02",
            "title": "Access-review record",
            "type": "record",
            "purpose": "Produce a bounded, reviewable access-review record from cited packet evidence while exposing unsupported fields and required approvals.",
            "instructions": "Use only the scoped case-fact inputs below. Cite an input ID for each supported statement; label proposed structures “learner proposal” and unavailable evidence “not supplied.”",
            "columns": [
              "Record ID",
              "Supported facts",
              "Source input ID",
              "Decision or action pending",
              "Owner or reviewer",
              "Evidence needed",
              "Status"
            ],
            "rowPlan": {
              "count": 2,
              "prefix": "02A02R",
              "blankState": "Not supplied / learner to complete"
            },
            "reviewedMappingId": "cybersecurity-fundamentals:M02:A02",
            "criterionIds": [
              "M02-EC02",
              "M02-EC03"
            ],
            "inputIds": [
              "M02-I02",
              "M02-I03",
              "M02-I05",
              "M02-I07"
            ],
            "completionChecks": [
              "Every supported entry identifies and cites at least one applicable scoped case-fact input (M02-I02, M02-I03, M02-I05, M02-I07).",
              "Every mapped rubric criterion (M02-EC02, M02-EC03) is addressed in the artifact or a named evidence gap.",
              "Unsupported fields remain “not supplied” or are explicitly labeled as a learner proposal.",
              "The Authorized system owner or qualified security specialist is named for decisions or review; no approval or execution is implied."
            ]
          }
        ],
        "quantityContracts": [
          {
            "artifactId": "M02-A01",
            "rowCount": 13,
            "rowPrefix": "02A01R"
          },
          {
            "artifactId": "M02-A02",
            "rowCount": 2,
            "rowPrefix": "02A02R"
          }
        ],
        "workedStarter": {
          "artifactId": "M02-A01",
          "criterionId": "M02-EC01",
          "inputId": "M02-I01",
          "supportedValue": "An employee entered a cloud password after opening the attachment.",
          "application": "Use the supplied condition to define one check, then mark the result pending until the required verification evidence exists. Cite M02-I01 (F03) in the row.",
          "boundary": "This is one evidence-backed starter entry, not a completed identity-containment checklist or an operational result."
        },
        "knownGap": {
          "artifactId": "M02-A01",
          "criterionId": "M02-EC01",
          "missingEvidence": "The packet does not supply the complete live records, approvals, or execution results needed to finish the identity-containment checklist.",
          "whyItMatters": "Without that evidence, the learner cannot truthfully satisfy M02-EC01 or represent this artifact as complete.",
          "ownerRole": "Authorized system owner or qualified security specialist",
          "boundedNextStep": "Record the missing evidence in M02-A01, name the authorized reviewer, and leave the outcome pending; do not obtain or simulate the live record in this exercise.",
          "status": "Open — not supplied"
        },
        "decisionPrompt": {
          "inputId": "M02-I07",
          "prompt": "What bounded decision can the Authorized system owner or qualified security specialist make from M02-I07, and what must remain pending until the missing evidence or approval is supplied?"
        },
        "instructionalGuide": {
          "version": "2026.09.01-academy-workbook-instruction-bank-1",
          "principalArtifactId": "M02-A01",
          "prerequisiteCheck": [
            "Confirm F03-F09; record that the identity provider, affected account list, approved incident playbook, clean administrative workstation, session/token inventory, forensic direction, and containment results are not supplied.",
            "STOP. If the identity provider, affected accounts, approved playbook, trusted workstation, session/token inventory, or forensic direction is missing or conflicts across F03–F09, route containment to authorized security leadership and the incident coordinator; do not claim approval or execute credential, session, mailbox, privilege, or device changes."
          ],
          "operatingSteps": [
            "Open an incident-scoped checklist without changing live systems in the exercise.",
            "Record credential entry, denied push, forwarding rule, unfamiliar login, same-laptop password advice, stale endpoint check-in, banking-change access, and former-contractor privilege.",
            "Order evidence preservation and qualified triage before destructive actions.",
            "Design identity actions for session/token revocation, credential reset from an approved clean path, MFA review, mailbox-rule review, and privileged-access review.",
            "Add endpoint isolation/collection dependencies and out-of-band communication.",
            "For every check, name required evidence, authorized owner, result as pending, and exception path.",
            "Final-QC sequence, source citations, account scope, evidence preservation, owner authority, and no execution claims."
          ],
          "fieldGuidance": {
            "Check ID": "Use a stable identifier for the quality or control check. Module use: Use the checklist to coordinate identity containment while avoiding unsafe same-device changes and preserving evidence.",
            "Control or check": "State one observable check in verb-first form. Module use: Use the checklist to coordinate identity containment while avoiding unsafe same-device changes and preserving evidence.",
            "Evidence required": "Name the record or observation needed to pass the check. Module use: Use the checklist to coordinate identity containment while avoiding unsafe same-device changes and preserving evidence.",
            "Source input ID": "Cite the exact Fxx or module input ID supporting the entry. Module use: Use the checklist to coordinate identity containment while avoiding unsafe same-device changes and preserving evidence.",
            "Owner": "Name the authorized operating or specialist role. Module use: Use the checklist to coordinate identity containment while avoiding unsafe same-device changes and preserving evidence.",
            "Result": "Record pending unless the packet explicitly supplies an observed result. Module use: Use the checklist to coordinate identity containment while avoiding unsafe same-device changes and preserving evidence.",
            "Exception or gap": "Describe the missing or conflicting evidence and its consequence. Module use: Use the checklist to coordinate identity containment while avoiding unsafe same-device changes and preserving evidence.",
            "Status": "Use a truthful state such as draft, open—not supplied, review pending, or blocked. Module use: Use the checklist to coordinate identity containment while avoiding unsafe same-device changes and preserving evidence."
          },
          "completedExampleRow": {
            "Check ID": "ID-01",
            "Control or check": "Review and contain the affected cloud identity through the approved incident process.",
            "Evidence required": "Identity-provider audit/session evidence plus qualified incident-owner direction.",
            "Source input ID": "F03, F04, F05, F06",
            "Owner": "Security/identity incident owner",
            "Result": "Pending - no containment action or result is supplied.",
            "Exception or gap": "Same possibly affected laptop was proposed for password change; approved clean administrative path is not supplied.",
            "Status": "Blocked - qualified direction required"
          },
          "completedKnownGapRow": {
            "Check ID": "ID-PRIV-02",
            "Control or check": "Review and disable or otherwise resolve obsolete privileged access only under approved authority.",
            "Evidence required": "Authoritative account ownership, HR/contractor status, access log, MFA record, and change evidence.",
            "Source input ID": "F08, F09",
            "Owner": "Identity and access owner with HR/contract owner as applicable",
            "Result": "Pending",
            "Exception or gap": "One privileged account belongs to a former contractor and lacks recorded MFA; no approved action record is supplied.",
            "Status": "Urgent review pending"
          },
          "supportingArtifacts": [
            {
              "artifactId": "M02-A02",
              "artifactTitle": "Access-review record",
              "criterionIds": [
                "M02-EC02"
              ],
              "exampleType": "completed-supporting-artifact-row",
              "rationale": "The canonical M02-A02 route maps M02-EC02. This row sequences the required actions as a reviewable proposal and explicitly withholds any claim that revocation, review, or rotation occurred.",
              "finalColumns": [
                "Record ID",
                "Supported facts",
                "Source input ID",
                "Decision or action pending",
                "Owner or reviewer",
                "Evidence needed",
                "Status"
              ],
              "row": {
                "Record ID": "CONTAIN-SEQ-01",
                "Supported facts": "A cloud password was entered after an attachment opened; an unexpected push was denied; a new forwarding rule and unfamiliar-region login appear; a password change from the same possibly affected laptop was advised.",
                "Source input ID": "M02-I01 (F03), M02-I02 (F04), M02-I03 (F05), and M02-I04 (F06)",
                "Decision or action pending": "Learner-proposed authorized sequence: establish a trusted administrative path; revoke active sessions; review recovery factors and forwarding rules; then rotate affected secrets and document exceptions. No step is represented as executed.",
                "Owner or reviewer": "Authorized security/identity incident owner",
                "Evidence needed": "Identity-provider session and audit logs; recovery-factor inventory; forwarding-rule record; affected-secret inventory; approved clean administrative path; authorization; timestamps; and execution results.",
                "Status": "Proposed containment sequence — authorization and results not supplied"
              },
              "status": "normalized"
            },
            {
              "artifactId": "M02-A02",
              "artifactTitle": "Access-review record",
              "criterionIds": [
                "M02-EC03"
              ],
              "exampleType": "completed-supporting-artifact-row",
              "rationale": "The canonical M02-A02 route also maps M02-EC03. The row exposes the stale privileged account and defines an authorized least-privilege decision path without disabling access or fabricating a completed review.",
              "finalColumns": [
                "Record ID",
                "Supported facts",
                "Source input ID",
                "Decision or action pending",
                "Owner or reviewer",
                "Evidence needed",
                "Status"
              ],
              "row": {
                "Record ID": "PRIV-REVIEW-02",
                "Supported facts": "Three accounts can change supplier banking details, and one privileged account belongs to a former contractor and lacks recorded multi-factor authentication.",
                "Source input ID": "M02-I06 (F08) and M02-I07 (F09)",
                "Decision or action pending": "Verify authoritative ownership and current business need, then propose the least-privilege correction or account disablement for authorized execution; no access change is represented as completed.",
                "Owner or reviewer": "Identity and access owner with the authorized HR or contract owner and payment-process owner",
                "Evidence needed": "Authoritative worker/contract status; account owner; business justification; current roles; sign-in and change logs; MFA record; approval; change ticket; and post-change evidence.",
                "Status": "Urgent review — correction and execution not supplied"
              },
              "status": "normalized"
            }
          ],
          "decisionRule": {
            "stop": "Stop ad-hoc password, mailbox, privilege, or endpoint changes from a possibly affected device or without evidence-preservation and authority.",
            "go": "Proceed only under the approved incident process using a trusted administrative path and traceable evidence.",
            "escalate": "Escalate suspected account compromise, privileged stale access, payment-system access, and unavailable clean administration to security leadership."
          },
          "completionTest": [
            "Evidence preservation, session/token, credential, MFA, mailbox, privilege, endpoint, and communication checks are ordered.",
            "F04-F09 all shape the checklist.",
            "Every result stays pending unless directly supplied."
          ],
          "criterionSatisfiability": [
            {
              "criterionId": "M02-EC01",
              "criterionOrdinal": 1,
              "criterionText": "Requires a known-clean channel and authorized administrator without asserting that either is available",
              "currentSatisfiable": true,
              "afterProposedRepairsSatisfiable": true,
              "finding": "The criterion is teachable through the bounded instructions and artifact row, but operational evidence, execution, and reviewer acceptance remain pending."
            },
            {
              "criterionId": "M02-EC02",
              "criterionOrdinal": 2,
              "criterionText": "Sequences session revocation, recovery-factor and forwarding review, and secret rotation as proposed actions rather than completed events",
              "currentSatisfiable": false,
              "afterProposedRepairsSatisfiable": true,
              "finding": "The current canonical principal-artifact route or schema cannot visibly satisfy this criterion without the listed fact-routing and/or artifact-spec repair; the learner must record the gap rather than claim completion."
            },
            {
              "criterionId": "M02-EC03",
              "criterionOrdinal": 3,
              "criterionText": "Flags the stale privileged account and least-privilege correction for authorized execution without disabling access",
              "currentSatisfiable": false,
              "afterProposedRepairsSatisfiable": true,
              "finding": "The current canonical principal-artifact route or schema cannot visibly satisfy this criterion without the listed fact-routing and/or artifact-spec repair; the learner must record the gap rather than claim completion."
            },
            {
              "criterionId": "M02-EC04",
              "criterionOrdinal": 4,
              "criterionText": "Cites the supplied input IDs for material statements and marks omitted operational records or results “not supplied” rather than fabricating them",
              "currentSatisfiable": true,
              "afterProposedRepairsSatisfiable": true,
              "finding": "The criterion is teachable through the bounded instructions and artifact row, but operational evidence, execution, and reviewer acceptance remain pending."
            }
          ]
        }
      }
    },
    {
      "module": 3,
      "title": "Verify the payment request",
      "prompt": "Create an independent communication and payment-change control that does not trust the suspect thread.",
      "deliverable": "A payment-hold decision record and out-of-band verification plan that marks the approved supplier contact identity and verification result not supplied.",
      "evidenceCriteria": [
        "Requires independently retrieved, previously approved supplier contact information and explicitly records that the contact details are not included in the packet",
        "Separates identity confirmation, change approval, and payment release as pending authorized decisions",
        "Defines message-and-attachment preservation and no-further-interaction rules without claiming evidence was collected",
        "Cites the supplied input IDs for material statements and marks omitted operational records or results “not supplied” rather than fabricating them"
      ],
      "taskMode": "bounded-case-starter",
      "providedInputs": [
        {
          "id": "M03-I01",
          "kind": "case-fact",
          "sourceFactIds": [
            "F01"
          ],
          "confidence": "confirmed",
          "record": "A supplier-thread email requests an $84,600 payment to a new bank."
        },
        {
          "id": "M03-I02",
          "kind": "case-fact",
          "sourceFactIds": [
            "F02"
          ],
          "confidence": "confirmed",
          "record": "The letter's phone number differs from the approved supplier record."
        },
        {
          "id": "M03-I03",
          "kind": "case-fact",
          "sourceFactIds": [
            "F12"
          ],
          "confidence": "confirmed",
          "record": "No payment has been released and the incident sheet lacks operative decision rules."
        },
        {
          "id": "M03-B01",
          "kind": "case-brief",
          "sourceFactIds": [],
          "sourceRecordIds": [
            "CB01"
          ],
          "confidence": "mixed",
          "record": "Use CB01, the full versioned case brief printed once at the start of this packet, as a citable narrative source for details not normalized into F01–F12. Preserve its uncertainty language and do not treat narrative detail as approval, complete operational records, or professional judgment."
        },
        {
          "id": "M03-S01",
          "kind": "assignment-scope",
          "sourceFactIds": [
            "F01",
            "F02",
            "F12"
          ],
          "confidence": "instruction",
          "record": "Build a starter version of “A payment-hold decision record and out-of-band verification plan that marks the approved supplier contact identity and verification result not supplied.” from the listed case facts. Treat requested structures, controls, questions, calculations, and templates as learner-designed proposals. Where an operational record or result is absent, add a gap entry naming the missing evidence and authorized owner instead of fabricating it."
        }
      ],
      "completionBoundary": "Complete a bounded starter and gap analysis using only CB01, F01, F02, F12, and the assignment-scope record below. Populate supported fields, label every unavailable field “not supplied,” and cite the input ID for each material statement. You may design a proposed template, control, question, or decision rule, but must label it as a learner proposal rather than observed case evidence. Do not contact people, access live systems, run tests, sign records, claim approval, or invent names, dates, quotations, transactions, results, or source documents.",
      "starterSchema": {
        "id": "M03-W02",
        "title": "Verify the payment request guided artifact-build sheet",
        "columns": [
          "Component ID",
          "Requested artifact component",
          "Evidence criterion to test",
          "Supplied input IDs",
          "Supported entry",
          "Not-supplied gap or learner proposal",
          "Authorized owner or reviewer",
          "Status"
        ],
        "rows": [
          {
            "id": "M03-A01",
            "component": "Payment-hold decision record",
            "criterion": "Requires independently retrieved, previously approved supplier contact information and explicitly records that the contact details are not included in the packet | Separates identity confirmation, change approval, and payment release as pending authorized decisions | Defines message-and-attachment preservation and no-further-interaction rules without claiming evidence was collected | Cites the supplied input IDs for material statements and marks omitted operational records or results “not supplied” rather than fabricating them",
            "suppliedInputIds": [
              "M03-I01",
              "M03-I02",
              "M03-I03"
            ]
          },
          {
            "id": "M03-A02",
            "component": "Out-of-band verification plan",
            "criterion": "Separates identity confirmation, change approval, and payment release as pending authorized decisions",
            "suppliedInputIds": [
              "M03-I02"
            ]
          }
        ]
      },
      "workbookPlan": {
        "id": "M03-WP01",
        "version": "2026.09.01-workbook-plan-2",
        "contextInputIds": [
          "M03-B01",
          "M03-S01"
        ],
        "criterionCatalog": [
          {
            "id": "M03-EC01",
            "text": "Requires independently retrieved, previously approved supplier contact information and explicitly records that the contact details are not included in the packet"
          },
          {
            "id": "M03-EC02",
            "text": "Separates identity confirmation, change approval, and payment release as pending authorized decisions"
          },
          {
            "id": "M03-EC03",
            "text": "Defines message-and-attachment preservation and no-further-interaction rules without claiming evidence was collected"
          },
          {
            "id": "M03-EC04",
            "text": "Cites the supplied input IDs for material statements and marks omitted operational records or results “not supplied” rather than fabricating them"
          }
        ],
        "artifacts": [
          {
            "id": "M03-A01",
            "title": "Payment-hold decision record",
            "type": "decision",
            "purpose": "Produce a bounded, reviewable payment-hold decision record from cited packet evidence while exposing unsupported fields and required approvals.",
            "instructions": "Use only the scoped case-fact inputs below. Cite an input ID for each supported statement; label proposed structures “learner proposal” and unavailable evidence “not supplied.”",
            "columns": [
              "Decision",
              "Evidence for",
              "Evidence against",
              "Verification source",
              "Verified contact",
              "Purchase/order match",
              "Bank-change evidence",
              "Options and tradeoffs",
              "Decision owner",
              "Dual-authorizer roles",
              "Required approval",
              "Decision timestamp",
              "Status"
            ],
            "rowPlan": {
              "count": 1,
              "prefix": "03A01R",
              "blankState": "Not supplied / learner to complete"
            },
            "reviewedMappingId": "cybersecurity-fundamentals:M03:A01",
            "criterionIds": [
              "M03-EC01",
              "M03-EC02",
              "M03-EC03",
              "M03-EC04"
            ],
            "inputIds": [
              "M03-I01",
              "M03-I02",
              "M03-I03"
            ],
            "completionChecks": [
              "Every supported entry identifies and cites at least one applicable scoped case-fact input (M03-I01, M03-I02, M03-I03).",
              "Every mapped rubric criterion (M03-EC01, M03-EC02, M03-EC03, M03-EC04) is addressed in the artifact or a named evidence gap.",
              "Unsupported fields remain “not supplied” or are explicitly labeled as a learner proposal.",
              "The Authorized system owner or qualified security specialist is named for decisions or review; no approval or execution is implied."
            ]
          },
          {
            "id": "M03-A02",
            "title": "Out-of-band verification plan",
            "type": "plan",
            "purpose": "Produce a bounded, reviewable out-of-band verification plan from cited packet evidence while exposing unsupported fields and required approvals.",
            "instructions": "Use only the scoped case-fact inputs below. Cite an input ID for each supported statement; label proposed structures “learner proposal” and unavailable evidence “not supplied.”",
            "columns": [
              "Step or milestone",
              "Trigger or date",
              "Evidence and source ID",
              "Owner",
              "Gate or threshold",
              "Dependency or gap",
              "Status"
            ],
            "rowPlan": {
              "count": 2,
              "prefix": "03A02R",
              "blankState": "Not supplied / learner to complete"
            },
            "reviewedMappingId": "cybersecurity-fundamentals:M03:A02",
            "criterionIds": [
              "M03-EC02"
            ],
            "inputIds": [
              "M03-I02"
            ],
            "completionChecks": [
              "Every supported entry identifies and cites at least one applicable scoped case-fact input (M03-I02).",
              "Every mapped rubric criterion (M03-EC02) is addressed in the artifact or a named evidence gap.",
              "Unsupported fields remain “not supplied” or are explicitly labeled as a learner proposal.",
              "The Authorized system owner or qualified security specialist is named for decisions or review; no approval or execution is implied."
            ]
          }
        ],
        "quantityContracts": [
          {
            "artifactId": "M03-A02",
            "rowCount": 2,
            "rowPrefix": "03A02R"
          }
        ],
        "workedStarter": {
          "artifactId": "M03-A01",
          "criterionId": "M03-EC01",
          "inputId": "M03-I01",
          "supportedValue": "A supplier-thread email requests an $84,600 payment to a new bank.",
          "application": "List the supplied condition as decision evidence and keep the decision, authority, and approval status open. Cite M03-I01 (F01) in the row.",
          "boundary": "This is one evidence-backed starter entry, not a completed payment-hold decision record or an operational result."
        },
        "knownGap": {
          "artifactId": "M03-A02",
          "criterionId": "M03-EC02",
          "missingEvidence": "The packet does not supply the complete live records, approvals, or execution results needed to finish the out-of-band verification plan.",
          "whyItMatters": "Without that evidence, the learner cannot truthfully satisfy M03-EC02 or represent this artifact as complete.",
          "ownerRole": "Authorized system owner or qualified security specialist",
          "boundedNextStep": "Record the missing evidence in M03-A02, name the authorized reviewer, and leave the outcome pending; do not obtain or simulate the live record in this exercise.",
          "status": "Open — not supplied"
        },
        "decisionPrompt": {
          "inputId": "M03-I03",
          "prompt": "What bounded decision can the Authorized system owner or qualified security specialist make from M03-I03, and what must remain pending until the missing evidence or approval is supplied?"
        },
        "instructionalGuide": {
          "version": "2026.09.01-academy-workbook-instruction-bank-1",
          "principalArtifactId": "M03-A01",
          "prerequisiteCheck": [
            "Confirm F01, F02, and F12; record that the approved supplier contact, original contract/order, banking-change request, call-back result, authority matrix, fraud review, and payment decision are not supplied.",
            "STOP. If the approved supplier contact, original order, bank-change evidence, call-back result, authority matrix, or fraud review is missing or conflicts with F01/F02/F12, route the request to authorized finance, security, and procurement leadership; do not claim verification or approval, execute a bank-detail change, release payment, or declare fraud."
          ],
          "operatingSteps": [
            "State the bounded decision as whether to keep the payment unreleased pending verification.",
            "List the new-bank request and mismatched phone as evidence supporting a hold.",
            "List uncertainty and operational tradeoffs without treating the email as proven fraud.",
            "Compare hold-and-verify, reject, and release options; prohibit using contact details from the suspicious thread for verification.",
            "Define an out-of-band verification plan using the approved supplier master and dual authorization.",
            "Name the finance decision owner and security/procurement reviewers; keep approval pending.",
            "Final-QC amount, evidence, options, verification source, owner authority, status, and no fraud conclusion."
          ],
          "fieldGuidance": {
            "Decision": "State one bounded proposed decision; never imply payment release, supplier verification, or fraud determination.",
            "Evidence for": "List exact facts supporting the proposal with input/fact IDs.",
            "Evidence against": "List uncertainty and contrary or missing evidence; do not infer fraud.",
            "Verification source": "Name the independently retrieved approved source required; use Not supplied until evidenced.",
            "Verified contact": "Record the approved contact only when supplied; otherwise Not supplied.",
            "Purchase/order match": "Record the underlying order/invoice match or Not supplied.",
            "Bank-change evidence": "Record authorized change evidence or Not supplied.",
            "Options and tradeoffs": "Compare at least hold/verify, authorized reject, and unsupported release routes.",
            "Decision owner": "Name the role with payment authority.",
            "Dual-authorizer roles": "Name required roles, not invented people; leave authorization pending.",
            "Required approval": "List procurement/security/payment approvals and preserve pending state.",
            "Decision timestamp": "Use an exact supplied time or Not supplied; do not invent action time.",
            "Status": "Use Proposed hold, Blocked, or Pending verification."
          },
          "completedExampleRow": {
            "Decision": "Propose continued non-release pending independent verification.",
            "Evidence for": "M03-I01 (F01): $84,600 request to a new bank; M03-I02 (F02): phone differs; M03-I03 (F12): no payment released.",
            "Evidence against": "The packet does not prove fraud or supply an approved supplier response.",
            "Verification source": "Previously approved supplier record retrieved independently — record itself not supplied.",
            "Verified contact": "Not supplied",
            "Purchase/order match": "Not supplied",
            "Bank-change evidence": "Not supplied",
            "Options and tradeoffs": "Hold and verify preserves funds; authorized rejection awaits evidence; release carries unverified-bank risk and is unsupported.",
            "Decision owner": "Authorized finance/payment owner",
            "Dual-authorizer roles": "Two authorized payment roles — identities not supplied",
            "Required approval": "Dual authorization plus security/procurement review pending",
            "Decision timestamp": "Not supplied",
            "Status": "Proposed hold — verification pending"
          },
          "completedKnownGapRow": {
            "Decision": "Do not release based on the email thread alone.",
            "Evidence for": "No payment has been released — M03-I03 (F12).",
            "Evidence against": "Approved call-back contact, purchase/order match, bank-change approval, supplier response, and operative decision rules are absent.",
            "Verification source": "Approved supplier record — not included in packet",
            "Verified contact": "Not supplied",
            "Purchase/order match": "Not supplied",
            "Bank-change evidence": "Not supplied",
            "Options and tradeoffs": "Request verification through the approved supplier record; preserve the mismatch and response without contacting anyone in this exercise.",
            "Decision owner": "Finance/payment owner",
            "Dual-authorizer roles": "Not supplied",
            "Required approval": "Verification and dual-authorization evidence",
            "Decision timestamp": "Not supplied",
            "Status": "Blocked — evidence not supplied"
          },
          "supportingArtifacts": [],
          "decisionRule": {
            "stop": "Stop release and any bank-detail change when independent verification and required authorization are absent or conflict.",
            "go": "Proceed only after out-of-band verification through an approved record and documented dual authorization.",
            "escalate": "Escalate suspected payment diversion, supplier-record mismatch, or pressure to bypass controls to finance/security/procurement leadership."
          },
          "completionTest": [
            "Decision, evidence for/against, options, owner, approval, and verification path are explicit.",
            "The record says suspicious/unverified rather than proven fraud.",
            "No payment, contact, or approval is fabricated."
          ],
          "criterionSatisfiability": [
            {
              "criterionId": "M03-EC01",
              "criterionOrdinal": 1,
              "criterionText": "Requires independently retrieved, previously approved supplier contact information and explicitly records that the contact details are not included in the packet",
              "currentSatisfiable": true,
              "afterProposedRepairsSatisfiable": true,
              "finding": "The criterion is teachable through the bounded instructions and artifact row, but operational evidence, execution, and reviewer acceptance remain pending."
            },
            {
              "criterionId": "M03-EC02",
              "criterionOrdinal": 2,
              "criterionText": "Separates identity confirmation, change approval, and payment release as pending authorized decisions",
              "currentSatisfiable": true,
              "afterProposedRepairsSatisfiable": true,
              "finding": "The criterion is teachable through the bounded instructions and artifact row, but operational evidence, execution, and reviewer acceptance remain pending."
            },
            {
              "criterionId": "M03-EC03",
              "criterionOrdinal": 3,
              "criterionText": "Defines message-and-attachment preservation and no-further-interaction rules without claiming evidence was collected",
              "currentSatisfiable": true,
              "afterProposedRepairsSatisfiable": true,
              "finding": "The criterion is teachable through the bounded instructions and artifact row, but operational evidence, execution, and reviewer acceptance remain pending."
            },
            {
              "criterionId": "M03-EC04",
              "criterionOrdinal": 4,
              "criterionText": "Cites the supplied input IDs for material statements and marks omitted operational records or results “not supplied” rather than fabricating them",
              "currentSatisfiable": true,
              "afterProposedRepairsSatisfiable": true,
              "finding": "The criterion is teachable through the bounded instructions and artifact row, but operational evidence, execution, and reviewer acceptance remain pending."
            }
          ]
        }
      }
    },
    {
      "module": 4,
      "title": "Coordinate device action",
      "prompt": "Replace improvised password changes with an authorized device and software response path.",
      "deliverable": "A device triage decision tree and approved-software baseline exception.",
      "evidenceCriteria": [
        "Preserves evidence before reimaging, deleting, or altering the affected device",
        "Routes containment and forensic choices to qualified responders",
        "Addresses delayed endpoint status without claiming the product prevented compromise",
        "Cites the supplied input IDs for material statements and marks omitted operational records or results “not supplied” rather than fabricating them"
      ],
      "taskMode": "bounded-case-starter",
      "providedInputs": [
        {
          "id": "M04-I01",
          "kind": "case-fact",
          "sourceFactIds": [
            "F03"
          ],
          "confidence": "confirmed",
          "record": "An employee entered a cloud password after opening the attachment."
        },
        {
          "id": "M04-I02",
          "kind": "case-fact",
          "sourceFactIds": [
            "F06"
          ],
          "confidence": "confirmed",
          "record": "The manager advised a password change from the same possibly affected laptop."
        },
        {
          "id": "M04-I03",
          "kind": "case-fact",
          "sourceFactIds": [
            "F07"
          ],
          "confidence": "confirmed",
          "record": "Endpoint protection on the laptop last checked in eleven days ago."
        },
        {
          "id": "M04-B01",
          "kind": "case-brief",
          "sourceFactIds": [],
          "sourceRecordIds": [
            "CB01"
          ],
          "confidence": "mixed",
          "record": "Use CB01, the full versioned case brief printed once at the start of this packet, as a citable narrative source for details not normalized into F01–F12. Preserve its uncertainty language and do not treat narrative detail as approval, complete operational records, or professional judgment."
        },
        {
          "id": "M04-S01",
          "kind": "assignment-scope",
          "sourceFactIds": [
            "F03",
            "F06",
            "F07"
          ],
          "confidence": "instruction",
          "record": "Build a starter version of “A device triage decision tree and approved-software baseline exception.” from the listed case facts. Treat requested structures, controls, questions, calculations, and templates as learner-designed proposals. Where an operational record or result is absent, add a gap entry naming the missing evidence and authorized owner instead of fabricating it."
        }
      ],
      "completionBoundary": "Complete a bounded starter and gap analysis using only CB01, F03, F06, F07, and the assignment-scope record below. Populate supported fields, label every unavailable field “not supplied,” and cite the input ID for each material statement. You may design a proposed template, control, question, or decision rule, but must label it as a learner proposal rather than observed case evidence. Do not contact people, access live systems, run tests, sign records, claim approval, or invent names, dates, quotations, transactions, results, or source documents.",
      "starterSchema": {
        "id": "M04-W02",
        "title": "Coordinate device action guided artifact-build sheet",
        "columns": [
          "Component ID",
          "Requested artifact component",
          "Evidence criterion to test",
          "Supplied input IDs",
          "Supported entry",
          "Not-supplied gap or learner proposal",
          "Authorized owner or reviewer",
          "Status"
        ],
        "rows": [
          {
            "id": "M04-A01",
            "component": "Device-triage decision tree",
            "criterion": "Preserves evidence before reimaging, deleting, or altering the affected device | Addresses delayed endpoint status without claiming the product prevented compromise | Cites the supplied input IDs for material statements and marks omitted operational records or results “not supplied” rather than fabricating them | Routes containment and forensic choices to qualified responders",
            "suppliedInputIds": [
              "M04-I01",
              "M04-I02",
              "M04-I03"
            ]
          },
          {
            "id": "M04-A02",
            "component": "Exception record against the approved-software baseline",
            "criterion": "Routes containment and forensic choices to qualified responders",
            "suppliedInputIds": [
              "M04-I02"
            ]
          }
        ]
      },
      "workbookPlan": {
        "id": "M04-WP01",
        "version": "2026.09.01-workbook-plan-2",
        "contextInputIds": [
          "M04-B01",
          "M04-S01"
        ],
        "criterionCatalog": [
          {
            "id": "M04-EC01",
            "text": "Preserves evidence before reimaging, deleting, or altering the affected device"
          },
          {
            "id": "M04-EC02",
            "text": "Routes containment and forensic choices to qualified responders"
          },
          {
            "id": "M04-EC03",
            "text": "Addresses delayed endpoint status without claiming the product prevented compromise"
          },
          {
            "id": "M04-EC04",
            "text": "Cites the supplied input IDs for material statements and marks omitted operational records or results “not supplied” rather than fabricating them"
          }
        ],
        "artifacts": [
          {
            "id": "M04-A01",
            "title": "Device-triage decision tree",
            "type": "map",
            "purpose": "Produce a bounded, reviewable device-triage decision tree from cited packet evidence while exposing unsupported fields and required approvals.",
            "instructions": "Use only the scoped case-fact inputs below. Cite an input ID for each supported statement; label proposed structures “learner proposal” and unavailable evidence “not supplied.”",
            "columns": [
              "Element",
              "From or trigger",
              "To or outcome",
              "Evidence and source ID",
              "Owner",
              "Open question",
              "Status"
            ],
            "rowPlan": {
              "count": 10,
              "prefix": "04A01R",
              "blankState": "Not supplied / learner to complete"
            },
            "reviewedMappingId": "cybersecurity-fundamentals:M04:A01",
            "criterionIds": [
              "M04-EC01",
              "M04-EC03",
              "M04-EC04",
              "M04-EC02"
            ],
            "inputIds": [
              "M04-I01",
              "M04-I02",
              "M04-I03"
            ],
            "completionChecks": [
              "Every supported entry identifies and cites at least one applicable scoped case-fact input (M04-I01, M04-I02, M04-I03).",
              "Every mapped rubric criterion (M04-EC01, M04-EC03, M04-EC04) is addressed in the artifact or a named evidence gap.",
              "Unsupported fields remain “not supplied” or are explicitly labeled as a learner proposal.",
              "The Authorized system owner or qualified security specialist is named for decisions or review; no approval or execution is implied."
            ]
          },
          {
            "id": "M04-A02",
            "title": "Exception record against the approved-software baseline",
            "type": "record",
            "purpose": "Produce a bounded, reviewable exception record against the approved-software baseline from cited packet evidence while exposing unsupported fields and required approvals.",
            "instructions": "Use only the scoped case-fact inputs below. Cite an input ID for each supported statement; label proposed structures “learner proposal” and unavailable evidence “not supplied.”",
            "columns": [
              "Record ID",
              "Supported facts",
              "Source input ID",
              "Decision or action pending",
              "Owner or reviewer",
              "Evidence needed",
              "Status"
            ],
            "rowPlan": {
              "count": 1,
              "prefix": "04A02R",
              "blankState": "Not supplied / learner to complete"
            },
            "reviewedMappingId": "cybersecurity-fundamentals:M04:A02",
            "criterionIds": [
              "M04-EC02"
            ],
            "inputIds": [
              "M04-I02"
            ],
            "completionChecks": [
              "Every supported entry identifies and cites at least one applicable scoped case-fact input (M04-I02).",
              "Every mapped rubric criterion (M04-EC02) is addressed in the artifact or a named evidence gap.",
              "Unsupported fields remain “not supplied” or are explicitly labeled as a learner proposal.",
              "The Authorized system owner or qualified security specialist is named for decisions or review; no approval or execution is implied."
            ]
          }
        ],
        "quantityContracts": [
          {
            "artifactId": "M04-A01",
            "rowCount": 10,
            "rowPrefix": "04A01R"
          }
        ],
        "workedStarter": {
          "artifactId": "M04-A01",
          "criterionId": "M04-EC01",
          "inputId": "M04-I01",
          "supportedValue": "An employee entered a cloud password after opening the attachment.",
          "application": "Anchor one element of the map to the supplied condition and label any inferred transition as a learner proposal. Cite M04-I01 (F03) in the row.",
          "boundary": "This is one evidence-backed starter entry, not a completed device-triage decision tree or an operational result."
        },
        "knownGap": {
          "artifactId": "M04-A01",
          "criterionId": "M04-EC01",
          "missingEvidence": "The packet does not supply the complete live records, approvals, or execution results needed to finish the device-triage decision tree.",
          "whyItMatters": "Without that evidence, the learner cannot truthfully satisfy M04-EC01 or represent this artifact as complete.",
          "ownerRole": "Authorized system owner or qualified security specialist",
          "boundedNextStep": "Record the missing evidence in M04-A01, name the authorized reviewer, and leave the outcome pending; do not obtain or simulate the live record in this exercise.",
          "status": "Open — not supplied"
        },
        "decisionPrompt": {
          "inputId": "M04-I03",
          "prompt": "What bounded decision can the Authorized system owner or qualified security specialist make from M04-I03, and what must remain pending until the missing evidence or approval is supplied?"
        },
        "instructionalGuide": {
          "version": "2026.09.01-academy-workbook-instruction-bank-1",
          "principalArtifactId": "M04-A01",
          "prerequisiteCheck": [
            "Confirm F03, F06, and F07; record that the device identifier, network location, endpoint telemetry, approved forensic playbook, clean device, evidence image, isolation status, and recovery authorization are not supplied.",
            "STOP. If device identity, network location, telemetry, forensic playbook, trusted tooling, evidence image, or isolation status is missing or conflicts with F03/F06/F07, route the branch to authorized incident leadership and the forensic/endpoint owner; do not claim recovery approval or execute isolation, cleanup, rebuild, or return to service."
          ],
          "operatingSteps": [
            "Start from the observed credential-entry event and the possibly affected laptop.",
            "Branch first on qualified incident-owner direction and evidence-preservation requirements.",
            "Replace same-laptop credential change with a trusted-path decision gate.",
            "Branch on endpoint connectivity/check-in and availability of current telemetry.",
            "Define proposed preserve, isolate, collect, analyze, rebuild, or return-to-service paths as authorized decisions, not completed actions.",
            "Add exceptions for business criticality, remote device, unavailable tooling, and safety.",
            "Final-QC source IDs, sequence, owner, evidence needed, exception path, and pending result."
          ],
          "fieldGuidance": {
            "Element": "Name the process node, asset, state, or transition. Module use: Use the tree to coordinate safe device decisions without destroying evidence or treating stale endpoint data as a clean bill of health.",
            "From or trigger": "State the observable event that activates the path. Module use: Use the tree to coordinate safe device decisions without destroying evidence or treating stale endpoint data as a clean bill of health.",
            "To or outcome": "State the proposed next state without implying execution. Module use: Use the tree to coordinate safe device decisions without destroying evidence or treating stale endpoint data as a clean bill of health.",
            "Evidence and source ID": "Pair the observation with its exact supplied source ID. Module use: Use the tree to coordinate safe device decisions without destroying evidence or treating stale endpoint data as a clean bill of health.",
            "Owner": "Name the authorized operating or specialist role. Module use: Use the tree to coordinate safe device decisions without destroying evidence or treating stale endpoint data as a clean bill of health.",
            "Open question": "Record the unanswered question that prevents a final decision. Module use: Use the tree to coordinate safe device decisions without destroying evidence or treating stale endpoint data as a clean bill of health.",
            "Status": "Use a truthful state such as draft, open—not supplied, review pending, or blocked. Module use: Use the tree to coordinate safe device decisions without destroying evidence or treating stale endpoint data as a clean bill of health."
          },
          "completedExampleRow": {
            "Element": "Possibly affected laptop",
            "From or trigger": "Credential was entered after opening the attachment.",
            "To or outcome": "Preserve state and obtain qualified triage direction before containment or credential action.",
            "Evidence and source ID": "F03, F06",
            "Owner": "Security incident/device owner",
            "Open question": "Approved playbook, device identifier, trusted administrative path, and evidence-preservation method are not supplied.",
            "Status": "Blocked - direction pending"
          },
          "completedKnownGapRow": {
            "Element": "Endpoint-telemetry branch",
            "From or trigger": "Endpoint protection last checked in eleven days ago.",
            "To or outcome": "Treat health as unknown; determine connectivity and approved evidence-collection path.",
            "Evidence and source ID": "F07",
            "Owner": "Endpoint/security owner",
            "Open question": "Current telemetry, agent state, isolation record, and forensic evidence are not supplied.",
            "Status": "Open - device state unknown"
          },
          "supportingArtifacts": [],
          "decisionRule": {
            "stop": "Stop same-device credential changes, destructive cleanup, rebuild, or return-to-service without qualified direction and preserved evidence.",
            "go": "Proceed through the approved branch only when device identity, trusted tooling, owner, and evidence method are confirmed.",
            "escalate": "Escalate unavailable telemetry, critical business dependencies, or suspected widespread compromise to incident leadership."
          },
          "completionTest": [
            "Trusted-path, evidence-preservation, connectivity, telemetry, isolation, analysis, recovery, and exception branches are explicit.",
            "The endpoint result remains unknown.",
            "No device action or forensic conclusion is fabricated."
          ],
          "criterionSatisfiability": [
            {
              "criterionId": "M04-EC01",
              "criterionOrdinal": 1,
              "criterionText": "Preserves evidence before reimaging, deleting, or altering the affected device",
              "currentSatisfiable": true,
              "afterProposedRepairsSatisfiable": true,
              "finding": "The criterion is teachable through the bounded instructions and artifact row, but operational evidence, execution, and reviewer acceptance remain pending."
            },
            {
              "criterionId": "M04-EC02",
              "criterionOrdinal": 2,
              "criterionText": "Routes containment and forensic choices to qualified responders",
              "currentSatisfiable": false,
              "afterProposedRepairsSatisfiable": true,
              "finding": "The current canonical principal-artifact route or schema cannot visibly satisfy this criterion without the listed fact-routing and/or artifact-spec repair; the learner must record the gap rather than claim completion."
            },
            {
              "criterionId": "M04-EC03",
              "criterionOrdinal": 3,
              "criterionText": "Addresses delayed endpoint status without claiming the product prevented compromise",
              "currentSatisfiable": true,
              "afterProposedRepairsSatisfiable": true,
              "finding": "The criterion is teachable through the bounded instructions and artifact row, but operational evidence, execution, and reviewer acceptance remain pending."
            },
            {
              "criterionId": "M04-EC04",
              "criterionOrdinal": 4,
              "criterionText": "Cites the supplied input IDs for material statements and marks omitted operational records or results “not supplied” rather than fabricating them",
              "currentSatisfiable": true,
              "afterProposedRepairsSatisfiable": true,
              "finding": "The criterion is teachable through the bounded instructions and artifact row, but operational evidence, execution, and reviewer acceptance remain pending."
            }
          ]
        }
      }
    },
    {
      "module": 5,
      "title": "Assess data, vendor, and recovery",
      "prompt": "Map the data, vendor, and backup questions and design a representative restore test; do not access systems or perform restoration.",
      "deliverable": "A data-flow and vendor-register starter plus a restore-test plan with test execution and recovery results pending.",
      "evidenceCriteria": [
        "Provides fields for data categories, access, retention, vendor contact, and contract questions while marking unavailable values not supplied",
        "Defines representative restoration evidence against proposed time and data expectations without claiming a test occurred",
        "Separates the reported green job status from verified recoverability"
      ],
      "taskMode": "bounded-case-starter",
      "providedInputs": [
        {
          "id": "M05-I01",
          "kind": "case-fact",
          "sourceFactIds": [
            "F05"
          ],
          "confidence": "confirmed",
          "record": "A new forwarding rule and unfamiliar-region login appear in administrative logs."
        },
        {
          "id": "M05-I02",
          "kind": "case-fact",
          "sourceFactIds": [
            "F10"
          ],
          "confidence": "confirmed",
          "record": "Nightly backups write to a connected network share."
        },
        {
          "id": "M05-I03",
          "kind": "case-fact",
          "sourceFactIds": [
            "F11"
          ],
          "confidence": "confirmed",
          "record": "The last recorded restore test was fourteen months ago and covered one folder."
        },
        {
          "id": "M05-B01",
          "kind": "case-brief",
          "sourceFactIds": [],
          "sourceRecordIds": [
            "CB01"
          ],
          "confidence": "mixed",
          "record": "Use CB01, the full versioned case brief printed once at the start of this packet, as a citable narrative source for details not normalized into F01–F12. Preserve its uncertainty language and do not treat narrative detail as approval, complete operational records, or professional judgment."
        },
        {
          "id": "M05-S01",
          "kind": "assignment-scope",
          "sourceFactIds": [
            "F05",
            "F10",
            "F11"
          ],
          "confidence": "instruction",
          "record": "Build a starter version of “A data-flow and vendor-register starter plus a restore-test plan with test execution and recovery results pending.” from the listed case facts. Treat requested structures, controls, questions, calculations, and templates as learner-designed proposals. Where an operational record or result is absent, add a gap entry naming the missing evidence and authorized owner instead of fabricating it."
        }
      ],
      "completionBoundary": "Complete a bounded starter and gap analysis using only CB01, F05, F10, F11, and the assignment-scope record below. Populate supported fields, label every unavailable field “not supplied,” and cite the input ID for each material statement. You may design a proposed template, control, question, or decision rule, but must label it as a learner proposal rather than observed case evidence. Do not contact people, access live systems, run tests, sign records, claim approval, or invent names, dates, quotations, transactions, results, or source documents.",
      "starterSchema": {
        "id": "M05-W02",
        "title": "Assess data, vendor, and recovery guided artifact-build sheet",
        "columns": [
          "Component ID",
          "Requested artifact component",
          "Evidence criterion to test",
          "Supplied input IDs",
          "Supported entry",
          "Not-supplied gap or learner proposal",
          "Authorized owner or reviewer",
          "Status"
        ],
        "rows": [
          {
            "id": "M05-A01",
            "component": "Data-flow and vendor register",
            "criterion": "Provides fields for data categories, access, retention, vendor contact, and contract questions while marking unavailable values not supplied | Separates the reported green job status from verified recoverability",
            "suppliedInputIds": [
              "M05-I01",
              "M05-I02",
              "M05-I03"
            ]
          },
          {
            "id": "M05-A02",
            "component": "Restore-test plan",
            "criterion": "Defines representative restoration evidence against proposed time and data expectations without claiming a test occurred",
            "suppliedInputIds": [
              "M05-I02",
              "M05-I03"
            ]
          }
        ]
      },
      "workbookPlan": {
        "id": "M05-WP01",
        "version": "2026.09.01-workbook-plan-2",
        "contextInputIds": [
          "M05-B01",
          "M05-S01"
        ],
        "criterionCatalog": [
          {
            "id": "M05-EC01",
            "text": "Provides fields for data categories, access, retention, vendor contact, and contract questions while marking unavailable values not supplied"
          },
          {
            "id": "M05-EC02",
            "text": "Defines representative restoration evidence against proposed time and data expectations without claiming a test occurred"
          },
          {
            "id": "M05-EC03",
            "text": "Separates the reported green job status from verified recoverability"
          }
        ],
        "artifacts": [
          {
            "id": "M05-A01",
            "title": "Data-flow and vendor register",
            "type": "register",
            "purpose": "Produce a bounded, reviewable data-flow and vendor register from cited packet evidence while exposing unsupported fields and required approvals.",
            "instructions": "Use only the scoped case-fact inputs below. Cite an input ID for each supported statement; label proposed structures “learner proposal” and unavailable evidence “not supplied.”",
            "columns": [
              "Flow ID",
              "Source system",
              "Destination/vendor",
              "Data category",
              "Purpose",
              "Access roles",
              "Retention/deletion",
              "Contract/control evidence",
              "Backup/recovery dependency",
              "Source IDs",
              "Owner/reviewer",
              "Gap",
              "Status"
            ],
            "rowPlan": {
              "count": 6,
              "prefix": "05A01R",
              "blankState": "Not supplied / learner to complete"
            },
            "reviewedMappingId": "cybersecurity-fundamentals:M05:A01",
            "criterionIds": [
              "M05-EC01",
              "M05-EC03"
            ],
            "inputIds": [
              "M05-I01",
              "M05-I02",
              "M05-I03"
            ],
            "completionChecks": [
              "Every supported entry identifies and cites at least one applicable scoped case-fact input (M05-I01).",
              "Every mapped rubric criterion (M05-EC01, M05-EC03) is addressed in the artifact or a named evidence gap.",
              "Unsupported fields remain “not supplied” or are explicitly labeled as a learner proposal.",
              "The Authorized system owner or qualified security specialist is named for decisions or review; no approval or execution is implied."
            ]
          },
          {
            "id": "M05-A02",
            "title": "Restore-test plan",
            "type": "plan",
            "purpose": "Produce a bounded, reviewable restore-test plan from cited packet evidence while exposing unsupported fields and required approvals.",
            "instructions": "Use only the scoped case-fact inputs below. Cite an input ID for each supported statement; label proposed structures “learner proposal” and unavailable evidence “not supplied.”",
            "columns": [
              "Step or milestone",
              "Trigger or date",
              "Evidence and source ID",
              "Owner",
              "Gate or threshold",
              "Dependency or gap",
              "Status"
            ],
            "rowPlan": {
              "count": 2,
              "prefix": "05A02R",
              "blankState": "Not supplied / learner to complete"
            },
            "reviewedMappingId": "cybersecurity-fundamentals:M05:A02",
            "criterionIds": [
              "M05-EC02"
            ],
            "inputIds": [
              "M05-I02",
              "M05-I03"
            ],
            "completionChecks": [
              "Every supported entry identifies and cites at least one applicable scoped case-fact input (M05-I02, M05-I03).",
              "Every mapped rubric criterion (M05-EC02) is addressed in the artifact or a named evidence gap.",
              "Unsupported fields remain “not supplied” or are explicitly labeled as a learner proposal.",
              "The Authorized system owner or qualified security specialist is named for decisions or review; no approval or execution is implied."
            ]
          }
        ],
        "quantityContracts": [
          {
            "artifactId": "M05-A01",
            "rowCount": 6,
            "rowPrefix": "05A01R"
          },
          {
            "artifactId": "M05-A02",
            "rowCount": 2,
            "rowPrefix": "05A02R"
          }
        ],
        "workedStarter": {
          "artifactId": "M05-A01",
          "criterionId": "M05-EC01",
          "inputId": "M05-I01",
          "supportedValue": "A new forwarding rule and unfamiliar-region login appear in administrative logs.",
          "application": "Open a traceable register entry for the supplied condition and route the unresolved decision to the named authorized role. Cite M05-I01 (F05) in the row.",
          "boundary": "This is one evidence-backed starter entry, not a completed data-flow and vendor register or an operational result."
        },
        "knownGap": {
          "artifactId": "M05-A01",
          "criterionId": "M05-EC01",
          "missingEvidence": "The packet does not supply the complete live records, approvals, or execution results needed to finish the data-flow and vendor register.",
          "whyItMatters": "Without that evidence, the learner cannot truthfully satisfy M05-EC01 or represent this artifact as complete.",
          "ownerRole": "Authorized system owner or qualified security specialist",
          "boundedNextStep": "Record the missing evidence in M05-A01, name the authorized reviewer, and leave the outcome pending; do not obtain or simulate the live record in this exercise.",
          "status": "Open — not supplied"
        },
        "decisionPrompt": {
          "inputId": "M05-I03",
          "prompt": "What bounded decision can the Authorized system owner or qualified security specialist make from M05-I03, and what must remain pending until the missing evidence or approval is supplied?"
        },
        "instructionalGuide": {
          "version": "2026.09.01-academy-workbook-instruction-bank-1",
          "principalArtifactId": "M05-A01",
          "prerequisiteCheck": [
            "Confirm F05, F10, and F11; record that data categories, systems, vendors, contracts, administrators, retention, encryption, backup isolation, recovery objectives, and current restore results are not supplied.",
            "STOP. If data scope, vendor access, contract terms, retention/encryption, backup isolation, recovery objectives, or restore evidence is missing or conflicts with F05/F10/F11, route the register to authorized security, privacy, vendor, and IT/recovery reviewers; do not claim compliance or recovery approval, execute notification, or assert recoverability."
          ],
          "operatingSteps": [
            "Register administrative-log, email, supplier/payment, identity, endpoint, and backup data flows separately.",
            "For each flow, state source, destination, data category, access role, retention/deletion state, and evidence ID.",
            "Record the unfamiliar login and forwarding-rule observations without declaring a breach scope.",
            "Map the connected network-share backup as a potential shared failure path, not a recovery guarantee.",
            "Use the fourteen-month-old one-folder restore record to require a broader approved restore test.",
            "Add vendor/contract, privacy, security, and recovery review gates where evidence is absent.",
            "Final-QC flow completeness, owners, source citations, retention/access gaps, recovery dependence, and no compliance claim."
          ],
          "fieldGuidance": {
            "Flow ID": "Assign a stable training flow/register ID.",
            "Source system": "Name only the supplied system or mark it Not supplied.",
            "Destination/vendor": "Name the supplied destination/vendor or Not supplied; do not infer one.",
            "Data category": "Classify the relevant data at a bounded level; label a proposed classification.",
            "Purpose": "State the supplied or proposed processing/recovery purpose.",
            "Access roles": "Record supplied access facts or Not supplied; do not invent identities.",
            "Retention/deletion": "Record the evidenced rule or Not supplied.",
            "Contract/control evidence": "Cite control/contract evidence or mark it Not supplied.",
            "Backup/recovery dependency": "State the supplied recovery dependency and distinguish job status from verified restore.",
            "Source IDs": "Cite exact module input and fact IDs.",
            "Owner/reviewer": "Name the authorized system, privacy, vendor, recovery, or security role.",
            "Gap": "Name the exact missing flow, contract, access, retention, or recovery evidence.",
            "Status": "Use Open, Blocked, or Draft — review pending."
          },
          "completedExampleRow": {
            "Flow ID": "FLOW-EMAIL-01",
            "Source system": "Administrative email logs",
            "Destination/vendor": "Forwarding destination not supplied",
            "Data category": "Potential message content and account metadata — proposed classification",
            "Purpose": "Forwarding-rule purpose not supplied",
            "Access roles": "Internal administrator has logs; broader access not supplied",
            "Retention/deletion": "Not supplied",
            "Contract/control evidence": "Not supplied",
            "Backup/recovery dependency": "Not established for this flow",
            "Source IDs": "M05-I01 (F05)",
            "Owner/reviewer": "Security/email owner",
            "Gap": "Rule creator, destination, authorization, affected data, timestamps, and preserved-log location are not supplied.",
            "Status": "Open — scope not supplied"
          },
          "completedKnownGapRow": {
            "Flow ID": "FLOW-BACKUP-02",
            "Source system": "Production data source not supplied",
            "Destination/vendor": "Connected network share — M05-I02 (F10)",
            "Data category": "Backup contents not supplied",
            "Purpose": "Nightly backup",
            "Access roles": "Not supplied",
            "Retention/deletion": "Not supplied",
            "Contract/control evidence": "Not supplied",
            "Backup/recovery dependency": "Last recorded restore test was 14 months ago and covered one folder — M05-I03 (F11).",
            "Source IDs": "M05-I02 (F10); M05-I03 (F11)",
            "Owner/reviewer": "IT/recovery owner and security reviewer",
            "Gap": "Isolation, representative coverage, recovery objectives, restore evidence, and current control status are not supplied.",
            "Status": "Blocked — recoverability not verified"
          },
          "supportingArtifacts": [],
          "decisionRule": {
            "stop": "Stop vendor, privacy, or recovery assurance when flow, access, contract, retention, isolation, or restore evidence is missing.",
            "go": "Proceed to review when every material flow and dependency has an owner, cited source, and bounded evidence request.",
            "escalate": "Escalate suspected data forwarding, connected-backup exposure, and stale restore testing to security, privacy, IT/recovery, and management owners."
          },
          "completionTest": [
            "Material sources, destinations, categories, access, retention, vendor, backup, and restore dependencies are represented.",
            "F05/F10/F11 are all in the principal register.",
            "No breach scope, compliance, or recoverability outcome is asserted."
          ],
          "criterionSatisfiability": [
            {
              "criterionId": "M05-EC01",
              "criterionOrdinal": 1,
              "criterionText": "Provides fields for data categories, access, retention, vendor contact, and contract questions while marking unavailable values not supplied",
              "currentSatisfiable": false,
              "afterProposedRepairsSatisfiable": true,
              "finding": "The current canonical principal-artifact route or schema cannot visibly satisfy this criterion without the listed fact-routing and/or artifact-spec repair; the learner must record the gap rather than claim completion."
            },
            {
              "criterionId": "M05-EC02",
              "criterionOrdinal": 2,
              "criterionText": "Defines representative restoration evidence against proposed time and data expectations without claiming a test occurred",
              "currentSatisfiable": true,
              "afterProposedRepairsSatisfiable": true,
              "finding": "The criterion is teachable through the bounded instructions and artifact row, but operational evidence, execution, and reviewer acceptance remain pending."
            },
            {
              "criterionId": "M05-EC03",
              "criterionOrdinal": 3,
              "criterionText": "Separates the reported green job status from verified recoverability",
              "currentSatisfiable": false,
              "afterProposedRepairsSatisfiable": true,
              "finding": "The current canonical principal-artifact route or schema cannot visibly satisfy this criterion without the listed fact-routing and/or artifact-spec repair; the learner must record the gap rather than claim completion."
            }
          ]
        }
      }
    },
    {
      "module": 6,
      "title": "Run the incident",
      "prompt": "Construct an incident-timeline starter and tabletop design from the supplied events; do not exercise response, contact external parties, or claim containment or recovery.",
      "deliverable": "An incident-record starter, tabletop-inject plan, decision-register template, and after-action template with simulation and outcome fields pending.",
      "evidenceCriteria": [
        "Uses the exact event times in citable CB01 and the F01 through F12 records while leaving action times, owners, and preserved-evidence results pending",
        "Lists legal, insurer, law-enforcement, customer, regulator, and supplier decision points without contacting them or predetermining outcomes",
        "Defines proposed recovery verification, monitoring, credential-reset, and control-improvement owners without claiming execution",
        "Cites the supplied input IDs for material statements and marks omitted operational records or results “not supplied” rather than fabricating them"
      ],
      "taskMode": "bounded-case-starter",
      "providedInputs": [
        {
          "id": "M06-I01",
          "kind": "case-fact",
          "sourceFactIds": [
            "F01"
          ],
          "confidence": "confirmed",
          "record": "A supplier-thread email requests an $84,600 payment to a new bank."
        },
        {
          "id": "M06-I02",
          "kind": "case-fact",
          "sourceFactIds": [
            "F02"
          ],
          "confidence": "confirmed",
          "record": "The letter's phone number differs from the approved supplier record."
        },
        {
          "id": "M06-I03",
          "kind": "case-fact",
          "sourceFactIds": [
            "F03"
          ],
          "confidence": "confirmed",
          "record": "An employee entered a cloud password after opening the attachment."
        },
        {
          "id": "M06-I04",
          "kind": "case-fact",
          "sourceFactIds": [
            "F04"
          ],
          "confidence": "confirmed",
          "record": "The employee denied an unexpected push notification and reported to the office manager."
        },
        {
          "id": "M06-I05",
          "kind": "case-fact",
          "sourceFactIds": [
            "F05"
          ],
          "confidence": "confirmed",
          "record": "A new forwarding rule and unfamiliar-region login appear in administrative logs."
        },
        {
          "id": "M06-I06",
          "kind": "case-fact",
          "sourceFactIds": [
            "F06"
          ],
          "confidence": "confirmed",
          "record": "The manager advised a password change from the same possibly affected laptop."
        },
        {
          "id": "M06-I07",
          "kind": "case-fact",
          "sourceFactIds": [
            "F07"
          ],
          "confidence": "confirmed",
          "record": "Endpoint protection on the laptop last checked in eleven days ago."
        },
        {
          "id": "M06-I08",
          "kind": "case-fact",
          "sourceFactIds": [
            "F08"
          ],
          "confidence": "confirmed",
          "record": "Three accounts can change supplier banking details."
        },
        {
          "id": "M06-I09",
          "kind": "case-fact",
          "sourceFactIds": [
            "F09"
          ],
          "confidence": "confirmed",
          "record": "One privileged account belongs to a former contractor and lacks recorded multi-factor authentication."
        },
        {
          "id": "M06-I10",
          "kind": "case-fact",
          "sourceFactIds": [
            "F10"
          ],
          "confidence": "confirmed",
          "record": "Nightly backups write to a connected network share."
        },
        {
          "id": "M06-I11",
          "kind": "case-fact",
          "sourceFactIds": [
            "F11"
          ],
          "confidence": "confirmed",
          "record": "The last recorded restore test was fourteen months ago and covered one folder."
        },
        {
          "id": "M06-I12",
          "kind": "case-fact",
          "sourceFactIds": [
            "F12"
          ],
          "confidence": "confirmed",
          "record": "No payment has been released and the incident sheet lacks operative decision rules."
        },
        {
          "id": "M06-B01",
          "kind": "case-brief",
          "sourceFactIds": [],
          "sourceRecordIds": [
            "CB01"
          ],
          "confidence": "mixed",
          "record": "Use CB01, the full versioned case brief printed once at the start of this packet, as a citable narrative source for details not normalized into F01–F12. Preserve its uncertainty language and do not treat narrative detail as approval, complete operational records, or professional judgment."
        },
        {
          "id": "M06-S01",
          "kind": "assignment-scope",
          "sourceFactIds": [
            "F01",
            "F02",
            "F03",
            "F04",
            "F05",
            "F06",
            "F07",
            "F08",
            "F09",
            "F10",
            "F11",
            "F12"
          ],
          "confidence": "instruction",
          "record": "Build a starter version of “An incident-record starter, tabletop-inject plan, decision-register template, and after-action template with simulation and outcome fields pending.” from the listed case facts. Treat requested structures, controls, questions, calculations, and templates as learner-designed proposals. Where an operational record or result is absent, add a gap entry naming the missing evidence and authorized owner instead of fabricating it."
        }
      ],
      "completionBoundary": "Complete a bounded starter and gap analysis using only CB01, F01, F02, F03, F04, F05, F06, F07, F08, F09, F10, F11, F12, and the assignment-scope record below. Populate supported fields, label every unavailable field “not supplied,” and cite the input ID for each material statement. You may design a proposed template, control, question, or decision rule, but must label it as a learner proposal rather than observed case evidence. Do not contact people, access live systems, run tests, sign records, claim approval, or invent names, dates, quotations, transactions, results, or source documents.",
      "starterSchema": {
        "id": "M06-W02",
        "title": "Run the incident guided artifact-build sheet",
        "columns": [
          "Component ID",
          "Requested artifact component",
          "Evidence criterion to test",
          "Supplied input IDs",
          "Supported entry",
          "Not-supplied gap or learner proposal",
          "Authorized owner or reviewer",
          "Status"
        ],
        "rows": [
          {
            "id": "M06-A01",
            "component": "Incident-record starter",
            "criterion": "Uses the exact event times in citable CB01 and the F01 through F12 records while leaving action times, owners, and preserved-evidence results pending",
            "suppliedInputIds": [
              "M06-I05",
              "M06-I06",
              "M06-I07",
              "M06-B01",
              "M06-I01",
              "M06-I02",
              "M06-I03",
              "M06-I04",
              "M06-I08",
              "M06-I09",
              "M06-I10",
              "M06-I11",
              "M06-I12"
            ]
          },
          {
            "id": "M06-A02",
            "component": "Tabletop inject plan",
            "criterion": "Lists legal, insurer, law-enforcement, customer, regulator, and supplier decision points without contacting them or predetermining outcomes",
            "suppliedInputIds": [
              "M06-I01",
              "M06-I02",
              "M06-I08",
              "M06-I09"
            ]
          },
          {
            "id": "M06-A03",
            "component": "Incident decision register",
            "criterion": "Lists legal, insurer, law-enforcement, customer, regulator, and supplier decision points without contacting them or predetermining outcomes | Defines proposed recovery verification, monitoring, credential-reset, and control-improvement owners without claiming execution",
            "suppliedInputIds": [
              "M06-I03",
              "M06-I10",
              "M06-I12"
            ]
          },
          {
            "id": "M06-A04",
            "component": "After-action template",
            "criterion": "Uses the exact event times in citable CB01 and the F01 through F12 records while leaving action times, owners, and preserved-evidence results pending | Cites the supplied input IDs for material statements and marks omitted operational records or results “not supplied” rather than fabricating them",
            "suppliedInputIds": [
              "M06-I04",
              "M06-I11"
            ]
          }
        ]
      },
      "workbookPlan": {
        "id": "M06-WP01",
        "version": "2026.09.01-workbook-plan-2",
        "contextInputIds": [
          "M06-B01",
          "M06-S01"
        ],
        "criterionCatalog": [
          {
            "id": "M06-EC01",
            "text": "Uses the exact event times in citable CB01 and the F01 through F12 records while leaving action times, owners, and preserved-evidence results pending"
          },
          {
            "id": "M06-EC02",
            "text": "Lists legal, insurer, law-enforcement, customer, regulator, and supplier decision points without contacting them or predetermining outcomes"
          },
          {
            "id": "M06-EC03",
            "text": "Defines proposed recovery verification, monitoring, credential-reset, and control-improvement owners without claiming execution"
          },
          {
            "id": "M06-EC04",
            "text": "Cites the supplied input IDs for material statements and marks omitted operational records or results “not supplied” rather than fabricating them"
          }
        ],
        "artifacts": [
          {
            "id": "M06-A01",
            "title": "Incident-record starter",
            "type": "record",
            "purpose": "Produce a bounded, reviewable incident-record starter from cited packet evidence while exposing unsupported fields and required approvals.",
            "instructions": "Use only the scoped case-fact inputs below. Cite an input ID for each supported statement; label proposed structures “learner proposal” and unavailable evidence “not supplied.”",
            "columns": [
              "Event ID",
              "Date/time or not supplied",
              "Observed fact",
              "Source ID",
              "Confidence",
              "Evidence location/status",
              "Decision/action pending",
              "Owner/reviewer",
              "Dependency",
              "Status"
            ],
            "rowPlan": {
              "count": 12,
              "prefix": "06A01R",
              "blankState": "Not supplied / learner to complete"
            },
            "reviewedMappingId": "cybersecurity-fundamentals:M06:A01",
            "criterionIds": [
              "M06-EC01"
            ],
            "inputIds": [
              "M06-I05",
              "M06-I06",
              "M06-I07",
              "M06-B01",
              "M06-I01",
              "M06-I02",
              "M06-I03",
              "M06-I04",
              "M06-I08",
              "M06-I09",
              "M06-I10",
              "M06-I11",
              "M06-I12"
            ],
            "completionChecks": [
              "Every supported entry identifies and cites at least one applicable scoped case-fact input (M06-I05, M06-I06, M06-I07).",
              "Every mapped rubric criterion (M06-EC01) is addressed in the artifact or a named evidence gap.",
              "Unsupported fields remain “not supplied” or are explicitly labeled as a learner proposal.",
              "The Authorized system owner or qualified security specialist is named for decisions or review; no approval or execution is implied."
            ]
          },
          {
            "id": "M06-A02",
            "title": "Tabletop inject plan",
            "type": "plan",
            "purpose": "Produce a bounded, reviewable tabletop inject plan from cited packet evidence while exposing unsupported fields and required approvals.",
            "instructions": "Use only the scoped case-fact inputs below. Cite an input ID for each supported statement; label proposed structures “learner proposal” and unavailable evidence “not supplied.”",
            "columns": [
              "Step or milestone",
              "Trigger or date",
              "Evidence and source ID",
              "Owner",
              "Gate or threshold",
              "Dependency or gap",
              "Status"
            ],
            "rowPlan": {
              "count": 2,
              "prefix": "06A02R",
              "blankState": "Not supplied / learner to complete"
            },
            "reviewedMappingId": "cybersecurity-fundamentals:M06:A02",
            "criterionIds": [
              "M06-EC02"
            ],
            "inputIds": [
              "M06-I01",
              "M06-I02",
              "M06-I08",
              "M06-I09"
            ],
            "completionChecks": [
              "Every supported entry identifies and cites at least one applicable scoped case-fact input (M06-I01, M06-I02, M06-I08, M06-I09).",
              "Every mapped rubric criterion (M06-EC02) is addressed in the artifact or a named evidence gap.",
              "Unsupported fields remain “not supplied” or are explicitly labeled as a learner proposal.",
              "The Authorized system owner or qualified security specialist is named for decisions or review; no approval or execution is implied."
            ]
          },
          {
            "id": "M06-A03",
            "title": "Incident decision register",
            "type": "register",
            "purpose": "Produce a bounded, reviewable incident decision register from cited packet evidence while exposing unsupported fields and required approvals.",
            "instructions": "Use only the scoped case-fact inputs below. Cite an input ID for each supported statement; label proposed structures “learner proposal” and unavailable evidence “not supplied.”",
            "columns": [
              "Entry ID",
              "Issue or event",
              "Evidence and source ID",
              "Risk or impact",
              "Owner",
              "Bounded next step",
              "Review point",
              "Status"
            ],
            "rowPlan": {
              "count": 2,
              "prefix": "06A03R",
              "blankState": "Not supplied / learner to complete"
            },
            "reviewedMappingId": "cybersecurity-fundamentals:M06:A03",
            "criterionIds": [
              "M06-EC02",
              "M06-EC03"
            ],
            "inputIds": [
              "M06-I03",
              "M06-I10",
              "M06-I12"
            ],
            "completionChecks": [
              "Every supported entry identifies and cites at least one applicable scoped case-fact input (M06-I03, M06-I10, M06-I12).",
              "Every mapped rubric criterion (M06-EC02, M06-EC03) is addressed in the artifact or a named evidence gap.",
              "Unsupported fields remain “not supplied” or are explicitly labeled as a learner proposal.",
              "The Authorized system owner or qualified security specialist is named for decisions or review; no approval or execution is implied."
            ]
          },
          {
            "id": "M06-A04",
            "title": "After-action template",
            "type": "template",
            "purpose": "Produce a bounded, reviewable after-action template from cited packet evidence while exposing unsupported fields and required approvals.",
            "instructions": "Use only the scoped case-fact inputs below. Cite an input ID for each supported statement; label proposed structures “learner proposal” and unavailable evidence “not supplied.”",
            "columns": [
              "Section or field",
              "Purpose",
              "Supported entry",
              "Source input ID",
              "Gap or learner proposal",
              "Owner or reviewer",
              "Status"
            ],
            "rowPlan": {
              "count": 2,
              "prefix": "06A04R",
              "blankState": "Not supplied / learner to complete"
            },
            "reviewedMappingId": "cybersecurity-fundamentals:M06:A04",
            "criterionIds": [
              "M06-EC01",
              "M06-EC04"
            ],
            "inputIds": [
              "M06-I04",
              "M06-I11"
            ],
            "completionChecks": [
              "Every supported entry identifies and cites at least one applicable scoped case-fact input (M06-I04, M06-I11).",
              "Every mapped rubric criterion (M06-EC01, M06-EC04) is addressed in the artifact or a named evidence gap.",
              "Unsupported fields remain “not supplied” or are explicitly labeled as a learner proposal.",
              "The Authorized system owner or qualified security specialist is named for decisions or review; no approval or execution is implied."
            ]
          }
        ],
        "quantityContracts": [
          {
            "artifactId": "M06-A01",
            "rowCount": 12,
            "rowPrefix": "06A01R"
          },
          {
            "artifactId": "M06-A02",
            "rowCount": 2,
            "rowPrefix": "06A02R"
          },
          {
            "artifactId": "M06-A03",
            "rowCount": 2,
            "rowPrefix": "06A03R"
          },
          {
            "artifactId": "M06-A04",
            "rowCount": 2,
            "rowPrefix": "06A04R"
          }
        ],
        "workedStarter": {
          "artifactId": "M06-A01",
          "criterionId": "M06-EC01",
          "inputId": "M06-I05",
          "supportedValue": "A new forwarding rule and unfamiliar-region login appear in administrative logs.",
          "application": "Enter the supplied condition as the factual basis of the record and preserve the pending decision or evidence gap. Cite M06-I05 (F05) in the row.",
          "boundary": "This is one evidence-backed starter entry, not a completed incident-record starter or an operational result."
        },
        "knownGap": {
          "artifactId": "M06-A02",
          "criterionId": "M06-EC02",
          "missingEvidence": "The packet does not supply the complete live records, approvals, or execution results needed to finish the tabletop inject plan.",
          "whyItMatters": "Without that evidence, the learner cannot truthfully satisfy M06-EC02 or represent this artifact as complete.",
          "ownerRole": "Authorized system owner or qualified security specialist",
          "boundedNextStep": "Record the missing evidence in M06-A02, name the authorized reviewer, and leave the outcome pending; do not obtain or simulate the live record in this exercise.",
          "status": "Open — not supplied"
        },
        "decisionPrompt": {
          "inputId": "M06-I12",
          "prompt": "What bounded decision can the Authorized system owner or qualified security specialist make from M06-I12, and what must remain pending until the missing evidence or approval is supplied?"
        },
        "instructionalGuide": {
          "version": "2026.09.01-academy-workbook-instruction-bank-1",
          "principalArtifactId": "M06-A01",
          "prerequisiteCheck": [
            "Confirm F01-F12 and CB01; record that exact timestamps/order, reporter/device/account identifiers, preserved artifacts, response actions, communications, decisions, approvals, recovery validation, and closure evidence are not supplied.",
            "STOP. If the event order, identifiers, preserved artifacts, response record, communication decision, recovery validation, or closure evidence is missing or conflicts with F01–F12/CB01, route the incident record to the authorized incident commander and security, finance, and recovery reviewers; do not claim approval or execute attribution, notification, recovery, or closure."
          ],
          "operatingSteps": [
            "Open one incident record with a training identifier and mark status open.",
            "Enter each supplied event/condition as a separate timeline item with its source ID; never invent a timestamp.",
            "Separate observed facts from hypotheses and decisions pending.",
            "Link payment, identity, email, endpoint, privilege, backup, and recovery workstreams.",
            "For each item, name evidence needed and the role authorized to decide or act.",
            "Add communication, legal/privacy, insurer, supplier, and leadership decision gates without claiming notification.",
            "Final-QC chronology uncertainty, evidence preservation, decisions, owner authority, recovery/closure criteria, and no executed-response claim."
          ],
          "fieldGuidance": {
            "Event ID": "Assign a stable event/condition ID; it is not a live incident number.",
            "Date/time or not supplied": "Use exact CB01 time when present; otherwise write Not supplied.",
            "Observed fact": "Record one supplied event or condition without adding cause, scope, or outcome.",
            "Source ID": "Cite exact module input/fact IDs and CB01 through M06-B01 where used.",
            "Confidence": "Preserve the supplied confidence and distinguish observation from conclusion.",
            "Evidence location/status": "Name the supplied location or exact evidence still not supplied; do not claim preservation.",
            "Decision/action pending": "State the authorized decision or action that remains pending.",
            "Owner/reviewer": "Name an authorized role, not an invented person.",
            "Dependency": "Name the prerequisite evidence, specialist review, communication decision, or recovery gate.",
            "Status": "Use Open, Blocked, Observed — unverified, or Pending decision."
          },
          "completedExampleRow": {
            "Event ID": "INC-EVT-01",
            "Date/time or not supplied": "9:12 a.m. (CB01)",
            "Observed fact": "Supplier-thread email requests $84,600 to a new bank; the letter phone differs from the approved supplier record; no payment has been released.",
            "Source ID": "M06-B01 (CB01); M06-I01 (F01); M06-I02 (F02); M06-I12 (F12)",
            "Confidence": "Confirmed observations; sender legitimacy and fraud determination not established",
            "Evidence location/status": "Original message, headers, attachment, and approved supplier record are not supplied/preserved in this exercise.",
            "Decision/action pending": "Authorized finance/security owner must decide verification, payment hold, and incident linkage.",
            "Owner/reviewer": "Finance/payment owner with security and procurement reviewers",
            "Dependency": "Approved supplier contact, purchase/order record, bank-change evidence, and decision log",
            "Status": "Open — decisions pending"
          },
          "completedKnownGapRow": {
            "Event ID": "INC-EVT-02",
            "Date/time or not supplied": "9:26 a.m. (CB01)",
            "Observed fact": "Employee entered a cloud password after opening the attachment.",
            "Source ID": "M06-B01 (CB01); M06-I03 (F03)",
            "Confidence": "Confirmed observation; page ownership, credential use, and incident scope not established",
            "Evidence location/status": "Original browser, identity, device, and page evidence are not supplied; no preservation result is claimed.",
            "Decision/action pending": "Qualified incident owner must establish an authorized containment and evidence-preservation sequence.",
            "Owner/reviewer": "Security incident owner",
            "Dependency": "Trusted administrative path, identity logs, endpoint telemetry, device identifier, and action log",
            "Status": "Blocked — evidence and action chronology pending"
          },
          "supportingArtifacts": [],
          "decisionRule": {
            "stop": "Stop closure, attribution, recovery, notification, or assurance claims while critical evidence, authority, or validation is absent.",
            "go": "Proceed to coordinated incident review when every supplied observation is source-linked and each missing action/evidence item has an owner.",
            "escalate": "Escalate payment risk, privileged access, suspected account compromise, evidence loss, or recovery failure immediately under the approved incident process."
          },
          "completionTest": [
            "All twelve facts are represented across separate source-linked items or explicit context links.",
            "Payment, identity, endpoint, access, backup, communication, recovery, and after-action gates are present.",
            "No timestamp, action, root cause, notification, recovery, or closure is invented."
          ],
          "criterionSatisfiability": [
            {
              "criterionId": "M06-EC01",
              "criterionOrdinal": 1,
              "criterionText": "Uses the exact event times in citable CB01 and the F01 through F12 records while leaving action times, owners, and preserved-evidence results pending",
              "currentSatisfiable": false,
              "afterProposedRepairsSatisfiable": true,
              "finding": "The current canonical principal-artifact route or schema cannot visibly satisfy this criterion without the listed fact-routing and/or artifact-spec repair; the learner must record the gap rather than claim completion."
            },
            {
              "criterionId": "M06-EC02",
              "criterionOrdinal": 2,
              "criterionText": "Lists legal, insurer, law-enforcement, customer, regulator, and supplier decision points without contacting them or predetermining outcomes",
              "currentSatisfiable": true,
              "afterProposedRepairsSatisfiable": true,
              "finding": "The criterion is teachable through the bounded instructions and artifact row, but operational evidence, execution, and reviewer acceptance remain pending."
            },
            {
              "criterionId": "M06-EC03",
              "criterionOrdinal": 3,
              "criterionText": "Defines proposed recovery verification, monitoring, credential-reset, and control-improvement owners without claiming execution",
              "currentSatisfiable": true,
              "afterProposedRepairsSatisfiable": true,
              "finding": "The criterion is teachable through the bounded instructions and artifact row, but operational evidence, execution, and reviewer acceptance remain pending."
            },
            {
              "criterionId": "M06-EC04",
              "criterionOrdinal": 4,
              "criterionText": "Cites the supplied input IDs for material statements and marks omitted operational records or results “not supplied” rather than fabricating them",
              "currentSatisfiable": true,
              "afterProposedRepairsSatisfiable": true,
              "finding": "The criterion is teachable through the bounded instructions and artifact row, but operational evidence, execution, and reviewer acceptance remain pending."
            }
          ]
        }
      }
    }
  ],
  "ambiguities": [
    {
      "issue": "The supplier thread may be compromised at the supplier, at SilverPine, or through another route.",
      "judgmentRequired": "Contain immediate risks and preserve evidence while qualified responders determine scope.",
      "doNotAssume": "Do not assign blame or declare the incident source from display name, thread position, or one login alone."
    },
    {
      "issue": "The backup dashboard is green, yet usable recovery evidence is old and narrow.",
      "judgmentRequired": "Define a safe representative restore test and interim resilience measures based on business needs.",
      "doNotAssume": "Do not call backups reliable solely because scheduled jobs report success."
    }
  ],
  "debrief": {
    "principle": "There is no universal containment sequence for every incident. Strong work protects people and operations, preserves evidence, uses authority, and escalates legal and forensic conclusions.",
    "moduleGuides": [
      {
        "module": 1,
        "reasoning": "The incident is a business-process problem involving identity, payment, supplier, device, and recovery controls. Prioritization should reflect consequence and decision authority, not product inventory alone.",
        "strongEvidence": [
          "Process-centered asset map",
          "Named authority and escalation paths"
        ]
      },
      {
        "module": 2,
        "reasoning": "Changing a password from the same device may not end active sessions or address recovery paths. Qualified identity containment should use a trusted channel and preserve logs.",
        "strongEvidence": [
          "Session and recovery-factor review",
          "Privileged-access correction record"
        ]
      },
      {
        "module": 3,
        "reasoning": "The safest verification does not use contact details in the suspect message. Payment change and payment release should require independent, documented approvals.",
        "strongEvidence": [
          "Known-contact verification",
          "Separation-of-duties payment record"
        ]
      },
      {
        "module": 4,
        "reasoning": "Uncoordinated deletion or reimaging can destroy evidence. The learner should identify safe first actions and defer forensic acquisition and eradication to authorized specialists.",
        "strongEvidence": [
          "Evidence-preserving triage",
          "Authorized endpoint action log"
        ]
      },
      {
        "module": 5,
        "reasoning": "Backup success means little without representative restoration against business requirements. Data and vendor review should also identify notification questions without answering them prematurely.",
        "strongEvidence": [
          "Timed restore evidence",
          "Data and vendor decision register"
        ]
      },
      {
        "module": 6,
        "reasoning": "An incident record should separate observations from hypotheses and preserve every material decision. After-action work addresses both technical and payment-process weaknesses.",
        "strongEvidence": [
          "Source-based timeline",
          "Owned corrective actions and effectiveness checks"
        ]
      }
    ],
    "specialistEscalations": [
      {
        "trigger": "Suspected compromise, malware, evidence collection, containment, eradication, or recovery",
        "specialist": "Authorized incident-response, identity, endpoint, email, and forensic professionals",
        "boundary": "The learner reports and preserves facts but does not conduct unauthorized investigation or destructive response."
      },
      {
        "trigger": "Breach scope, notification, law enforcement, insurer, customer, regulator, banking, or contractual decisions",
        "specialist": "Qualified counsel, insurer, financial institution, executive incident lead, and applicable authorities",
        "boundary": "Training cannot determine legal duties, coverage, attribution, or notification obligations."
      }
    ]
  },
  "caseBriefId": "CB01"
}
