SER-002 — Investigation
Complete educational series on conducting security investigations using evidence—from lifecycle and hypothesis through quality, bias, decisions, documentation, and handoff.
SER-002 — Investigation
Series: SER-002
Version: 1.0
Fundamental question: How should analysts conduct investigations?
Pillar: PIL-INVESTIGATION
Season: SEA-001
Status: ✅ Complete — FROZEN (D1 drafts)
Review: Every 6 months (next: 2027-01-03)
Expansion: SER-002 v2.0 only — no new articles in v1.0
Learning path: LP-002
Prerequisite: SER-001 Evidence-Based Security (minimum: KID-CON-0001, KID-CON-0010)
Purpose
Complete educational series on conducting security investigations using evidence—from lifecycle and hypothesis through quality, bias, decisions, documentation, and handoff.
Educational flow: What is evidence? → How do I evaluate it? → How do I investigate with it?
Authority anchors: KID-GLS-0002, KID-INV-0001
Reading order
| Order | KID | Article | Difficulty | Time |
|---|---|---|---|---|
| — | — | Prerequisite: SER-001 | — | — |
| 1 | KID-GLS-0002 | Investigation (term) | — | 3 min |
| 2 | KID-CON-0005 | Security Investigation vs Incident Response | Introductory | 8 min |
| 3 | KID-CON-0019 | Investigation Lifecycle | Introductory | 9 min |
| 4 | KID-GLS-0018 | Hypothesis (term) | — | 3 min |
| 5 | KID-CON-0020 | Investigation Hypothesis | Intermediate | 8 min |
| 6 | KID-CON-0021 | Investigation Quality | Intermediate | 9 min |
| 7 | KID-CON-0022 | Investigation Bias | Intermediate | 8 min |
| 8 | KID-CON-0024 | Investigation Prioritization | Intermediate | 8 min |
| 9 | KID-CON-0023 | Investigation Decisions | Intermediate | 9 min |
| 10 | KID-GLS-0019 | Disposition (term) | — | 3 min |
| 11 | KID-CON-0026 | Investigation Documentation | Intermediate | 9 min |
| 12 | KID-CON-0008 | From Alerts to Decisions | Intermediate | 8 min |
| 13 | KID-CON-0025 | Investigation Handoff and Continuity | Intermediate | 8 min |
| 14 | KID-CON-0004 | Why Security Tools Generate Too Many Findings | Introductory | 7 min |
| 15 | KID-CON-0007 | How Security Knowledge Reduces Analyst Fatigue | Introductory | 7 min |
Glossary (series terms)
| KID | Term | Status |
|---|---|---|
| KID-GLS-0002 | Investigation | ✅ |
| KID-GLS-0018 | Hypothesis | ✅ |
| KID-GLS-0019 | Disposition | ✅ |
FAQs (attached)
| KID | Question | Primary parent |
|---|---|---|
| KID-FAQ-0011 | What is the investigation lifecycle? | KID-CON-0019 |
| KID-FAQ-0012 | Investigation vs incident response? | KID-CON-0005 |
| KID-FAQ-0013 | What is an investigation hypothesis? | KID-CON-0020 |
| KID-FAQ-0014 | How do you document an investigation? | KID-CON-0026 |
| KID-FAQ-0015 | When should an investigation be escalated? | KID-CON-0023 |
Publishable bundle (debt — not blocking v1.0)
| ID | Component | Status |
|---|---|---|
| DEBT-S2-001 | Pillar hub PIL-INVESTIGATION | ⏳ |
| DEBT-S2-002 | Concept map MAP-003 | ⏳ |
| DEBT-S2-003 | Learning path LP-002 formal INDEX | ⏳ |
| DEBT-S2-004 | Tutorial TUT-001 (shared with SEA-001) | ⏳ |
| DEBT-S2-005 | D2 human review batch — 15 new assets | ⏳ |
See SERIES_COMPLETION_STANDARD.md.
Collection statistics
| Asset type | Count |
|---|---|
| Educational articles (series) | 12 |
| Glossary terms (series) | 3 |
| FAQ attachments | 5 |
| New KIDs this collection | 15 |
| Cumulative registered KIDs | 73 |