From a claim to a checkable artifact
An artifact can support a decision when its meaning, acquisition source and transformations can be explained. Separate observation, interpretation and hypothesis. A file contains a line referring to an export; that differs from establishing that the export completed, what it contained and who controlled the identity. Link each conclusion to the fields and sources supporting it, including gaps. Do not attribute properties to a log that its configuration does not provide. The exercise creates `synthetic-original.log` itself with two fictional lines. Its manifest declares origin `fictional-gateway-A`, collector, teaching authorization, acquisition time, size and SHA-256. This description supports reproducible comparisons but does not authenticate the declared origin. The program demonstrates that limitation by changing only the origin name: the bytes still match the digest. Workplace provenance needs mechanisms and records appropriate to acquisition context. A well-formatted sequence of fields cannot replace that evidence.
Preserve the original and document derived copies
Analyze working copies when the procedure permits, retaining the acquired original and comparison reference. A change can be intentional and useful: converting line endings, extracting a time window or replacing data for controlled sharing. Identify the derivation and avoid presenting it as a byte-for-byte original copy. Retain the relationship between input, operation, tool and output. Extraction also needs explicit criteria; excluding lines outside a window must not hide that the window was chosen. The laboratory copies bytes and confirms equality, then converts CRLF to LF in the copy. Decoded lines remain equal while the digest changes. Another change replaces `action=export` with `action=read`; comparison with the original reference also fails. Recomputing the copy's digest permits checking that new version but does not establish equivalence to the earlier acquisition. Before interpreting an integrity alert, identify the expected reference and any authorized, documented transformation. Detecting a difference does not automatically establish malicious intent.
Transfers with identity, time and purpose
When a procedure requires custody traceability, record the artifact, releasing person, receiving person, time, purpose and required acknowledgement. Artifact identity must persist through transfers even if its local filename changes. If the stated previous holder differs from the record, investigate the gap. Do not retrospectively invent an unknown transfer to produce a visually continuous chain. The local model rejects a transfer without acknowledgement, with a different artifact identifier, from someone other than the recorded holder or with bytes differing from the reference. It also requires an explicit timezone and compares instants in UTC. Thus 10:04+01:00 follows 09:03Z; comparing strings alone can produce incorrect conclusions in other cases. Exercise names and acknowledgements are synthetic inputs, not real people's signatures. Someone with access can modify the JSON file. Actual access, authentication, retention and any admissibility requirements must follow the applicable procedure and competent guidance.
Search quality and the scope of a conclusion
Search results depend on available data and how they are interpreted. Record systems, time interval, fields, filters, parser version and known collection conditions. A negative result may exclude a hypothesis within that scope, but not every possible behavior. Before widening scope, identify the link justifying expansion: a shared identity, configuration, integration or discovered artifact. This makes investigation explainable and helps prioritize resources. Suppose an old parser ignores events where `principal` was renamed `subject`. No results for an account do not establish inactivity on that service version. Run the query against a known positive record and check that it reaches the expected result. Then reprocess affected data using the correct schema and retain the analysis version. If two tools disagree, compare inputs, transformations and criteria before choosing the newer tool. Management needs a conclusion with explicit boundaries and an action addressing uncertainty that can still change the decision.
A containment matrix with explicit constraints
The exercise represents paths with simple identifiers: `session-A` and `token-B`. Each option declares blocked paths, essential-service availability, recovery access, authorization and a teaching disruption level. First exclude options failing mandatory conditions. Only then compare disruption and reversibility among eligible candidates. A favorable average must not compensate for an open path when the objective requires blocking it. Call the function with only `session-A` relevant and observe the specific restriction selected. Add `token-B`: the earlier option becomes insufficient despite retaining the lowest disruption value. Remove authorization from the broader restriction while preserving the essential-service requirement; the result becomes no eligible option. That result calls for a new alternative or an explicit decision about constraints. It does not authorize executing the least unsuitable candidate. In an actual environment, each matrix value needs evidence and corresponding authority; the program does not measure rule effectiveness or know omitted dependencies.
Guided case: an export and a shared service
At a fictional institution, a gateway records export requests by a service account. The team has confirmed activity through one session and found an additional token awaiting assessment. The same service supports validations needed for fund close. Isolating only the session restricts one known path; stopping the entire gateway also interrupts validation. The authorized objective is to contain confirmed paths, investigate the token and preserve a safe recovery route. Preserve relevant records under the procedure and identify links between session, token, resource and outcome. Do not wait for human attribution before addressing ongoing harm. Compare restricting the principal with complete suspension, checking whether the former covers the paths while retaining essential service. If evidence shows that the token belongs to another mechanism unaffected by that restriction, the decision changes. Record the invalidated assumption and next action. Before returning, confirm correction of the unauthorized-access source and the required acceptance and denial behaviors. Case details and limits are educational, not any bank's internal procedure.
Run, change and explain the laboratory
Run `python3 run.py --evidence learner-run.json --demo-dir learner-demo` from the laboratory directory, choosing paths that do not exist. The program creates fictional data, runs checks and retains a demonstration directory only when requested. Inspect the manifest, both files and the transfer register. Before calculating, predict which comparisons will pass: the working copy was deliberately changed while the original retains its initially created bytes. In another manifest copy, change only the declared origin and compare the original again. Explain why byte equality cannot validate that claim. Then import `choose_containment` and use the options file to compare the session alone with session plus token. Change one assumption at a time: authorization, blocked path or recovery access. Record your predicted decision and the observed result. Do not edit retained execution reports to make an answer pass; use new output names for every experiment. The objective is explaining the mechanism and consequence of a change, not obtaining a green counter.
Summary: keep conclusions within the evidence
This practice performs actual operations on synthetic files: creation, copying, mutation, SHA-256 calculation and register-field validation. Both recorded executions passed 29 checks. The result supports repeating comparisons and examining how a changed assumption affects a decision. It does not establish real-host acquisition, authentic origin, immutable custody, human acceptance or production containment effectiveness. Use the same discipline in an incident report: describe the observation, reference, scope and supported conclusion. For a digest difference, first identify expected bytes and version. For a sequence of records, distinguish internal consistency from external confirmation. For containment, specify the paths and consequences assessed. For recovery, verify both legitimate service and denial of the behavior that enabled the incident. Link uncertainties to actions capable of resolving them, with ownership and priority. The summary should let another team continue investigating without inheriting certainty that was never established.
Choose data that discriminate between hypotheses
An observation distinguishes hypotheses only if they predict different results in it. A four-hundred-MB encrypted connection to a supplier may fit either an approved backup or a customer report. A capture without decrypted content does not choose between them. Seek authorized records linking process, job, objects and interval, and state what the network actually observed. Normal supplier use and a matching size also do not identify this transfer’s content. Before adding confirmations, check their origin. Two suppliers may repeat the same feed. The information remains useful, but distribution through two channels does not create two independent observations. A contact included in the same message requesting a new destination is likewise not an independent reference for authenticating the change. The procedure should use the previously validated channel and confirm permitted scope. Technical counts need a defined unit. If an event sequence jumps from one hundred and twenty to one hundred and twenty-six, five positions are missing. If an instruction can generate an attempt, rejection and confirmation, this does not prove five distinct instructions were lost. Reconcile the sequence and business identifiers. Exercise: write two hypotheses still compatible with each datum and identify a source capable of distinguishing them. Avoid concluding limited evidence has no value; the aim is to use it at the precision it supports.
Record intervention and manage source lifetime
Investigation itself may change what is observed afterward. In this example, opening a file on the original system updates last-access. The analyst’s session record establishes that opening at 14:00, but no earlier copy of the field exists. The current value fits the intervention; it neither proves attacker access at that time nor excludes earlier access whose value was overwritten. Do not invent the former timestamp. Retain the action record, limitation and additional sources that may reconstruct the period. Acquisition order matters too. With one operator, an extract expiring in eight minutes and taking three to export should be considered before a fifteen-minute image when the disk remains preserved for sixty. Exporting first permits completion at minutes three and eighteen. Imaging first loses the extract opportunity. This choice assumes necessary containment is already secured and both actions are authorized; it does not create a rule to delay response for evidence retention. Finally, distinguish changed facts from changed classification. Applying a ten-minute rather than thirty-minute threshold to the same incidents may increase severe counts without changing observed durations. Retain matrix version and, when comparing periods, present a common basis and the effect of the change. A useful record lets a reader follow observation, intervention, interpretation and applied rule without turning an editorial convention into a property of events.
cd content/labs/cism-incident-evidence
python3 run.py --evidence learner-run.json --demo-dir learner-demoA gateway supports exports and essential validations. A session restriction is sufficient only if it covers relevant paths; a matching digest confirms only the byte reference used.
Common pitfalls
Treating a hash as proof of origin; analyzing a changed copy without identifying its derivation; inventing missing transfers; selecting the least disruptive action without checking effectiveness; confusing silence with investigated scope.
Related topics: Incident readiness and continuity · Business impact analysis · Containment and recovery · Control assessment
Each conclusion needs a scope, a reference and evidence appropriate to the mechanism it claims.
References
- Guide to Integrating Forensic Techniques into Incident Response · SP 800-86, August 2006; historical handling principles
- CISM Exam Content Outline · Current outline through 2026-11-02; 2026-11-03 transition remains separate
- SP 800-61r3 publication record · Final April 2025
- Incident Response Recommendations and Considerations for Cybersecurity Risk Management · SP 800-61r3, April 2025
- SP 800-86 publication record · August 2006
- SP 800-84 publication record · September 2006
- Guide to Test, Training, and Exercise Programs for IT Plans and Capabilities · SP 800-84, September 2006
- SP 800-34r1 publication record · May 2010, updated November 11, 2010
- Contingency Planning Guide for Federal Information Systems · SP 800-34r1, May 2010 with November 2010 update