Knowledge Articles — Investigation Foundations Collection
First **Stream B** seed content for the Cybersecurity Encyclopedia. **Collection 001 is not the primary organizing unit** — use Knowledge Series and Editorial Seasons going forward. See editorial/EDITORIAL_MASTER_PLAN.md.
Knowledge Articles — Investigation Foundations Collection
Collection: 001 (legacy seed — remapped to Knowledge Series)
KIDs: KID-CON-0001 through KID-CON-0009
Learning path: LP-001 (formalize in SEA-001)
Status: D1 drafts
Editorial: Articles distributed across SER-001, SER-002, SER-003 — see editorial/KNOWLEDGE_SERIES_INDEX.md
Purpose
First Stream B seed content for the Cybersecurity Encyclopedia. Collection 001 is not the primary organizing unit — use Knowledge Series and Editorial Seasons going forward. See editorial/EDITORIAL_MASTER_PLAN.md.
Next production priority: SER-001 Evidence-Based Security — not Collection 002.
Reading order
| Order | KID | Article |
|---|---|---|
| 1 | KID-CON-0001 | Evidence-Based Investigation |
| 2 | KID-CON-0002 | What Makes Security Evidence Trustworthy |
| 3 | KID-CON-0005 | Security Investigation vs Incident Response |
| 4 | KID-CON-0006 | Understanding Security Context |
| 5 | KID-CON-0003 | Context Matters More Than Severity |
| 6 | KID-CON-0004 | Why Security Tools Generate Too Many Findings |
| 7 | KID-CON-0007 | How Security Knowledge Reduces Analyst Fatigue |
| 8 | KID-CON-0008 | From Alerts to Decisions |
| 9 | KID-CON-0009 | Why Correlation Matters |
Authority anchors
| KID | Role |
|---|---|
| KID-INV-0001 | Investigation capability |
| KID-OIN-0001 | Operational prioritization |
| KID-ARC-0001 | Canonical entities |
| KID-PLT-0002 | AI / autonomy boundaries |
Glossary used
KID-GLS-0001 through KID-GLS-0013 (first glossary collection)