Knowledge Articles — Investigation Foundations Collection

First **Stream B** seed content for the Cybersecurity Encyclopedia. **Collection 001 is not the primary organizing unit** — use Knowledge Series and Editorial Seasons going forward. See editorial/EDITORIAL_MASTER_PLAN.md.

Knowledge Articles — Investigation Foundations Collection

Collection: 001 (legacy seed — remapped to Knowledge Series)
KIDs: KID-CON-0001 through KID-CON-0009
Learning path: LP-001 (formalize in SEA-001)
Status: D1 drafts
Editorial: Articles distributed across SER-001, SER-002, SER-003 — see editorial/KNOWLEDGE_SERIES_INDEX.md


Purpose

First Stream B seed content for the Cybersecurity Encyclopedia. Collection 001 is not the primary organizing unit — use Knowledge Series and Editorial Seasons going forward. See editorial/EDITORIAL_MASTER_PLAN.md.

Next production priority: SER-001 Evidence-Based Security — not Collection 002.

Reading order

Order KID Article
1 KID-CON-0001 Evidence-Based Investigation
2 KID-CON-0002 What Makes Security Evidence Trustworthy
3 KID-CON-0005 Security Investigation vs Incident Response
4 KID-CON-0006 Understanding Security Context
5 KID-CON-0003 Context Matters More Than Severity
6 KID-CON-0004 Why Security Tools Generate Too Many Findings
7 KID-CON-0007 How Security Knowledge Reduces Analyst Fatigue
8 KID-CON-0008 From Alerts to Decisions
9 KID-CON-0009 Why Correlation Matters

Authority anchors

KID Role
KID-INV-0001 Investigation capability
KID-OIN-0001 Operational prioritization
KID-ARC-0001 Canonical entities
KID-PLT-0002 AI / autonomy boundaries

Glossary used

KID-GLS-0001 through KID-GLS-0013 (first glossary collection)


Related Articles