Volume 1 — Analytical Foundations
Volume 1 is the **core analytical reasoning chain** of a security analyst. It teaches how to establish trustworthy evidence, investigate with discipline, prioritize risk with context, and use attack paths as decision support.
Volume 1 — Analytical Foundations
Volume: VOL-001
Version: 1.0
Status: ✅ Complete — series frozen v1.0 · coherence PASS WITH OBSERVATIONS
Publishable level: V1 (curriculum) · V2 (coherence) · V3 bundle pending
Review: Every 6 months (next: 2027-01-03)
Overview
Volume 1 is the core analytical reasoning chain of a security analyst. It teaches how to establish trustworthy evidence, investigate with discipline, prioritize risk with context, and use attack paths as decision support.
This is the first independently validated volume of the SentriScope Cybersecurity Encyclopedia.
Reader outcome
After Volume 1, a practitioner can:
- Distinguish evidence from alerts, scores, and opinions
- Conduct investigations using hypothesis-driven discipline
- Prioritize cyber risk using context — not severity alone
- Interpret attack paths as decision-support models, not findings or CVE replacements
Series (reading order)
| Order | Series | Index | Articles |
|---|---|---|---|
| 1 | SER-001 Evidence-Based Security | SERIES_001 | 15 |
| 2 | SER-002 Investigation | SERIES_002 | 12 |
| 3 | SER-003 Risk Intelligence | SERIES_003 | 10 |
| 4 | SER-004 Attack Paths | SERIES_004 | 10 |
Total: 47 educational articles
Curriculum arc
What is trustworthy evidence? (SER-001)
↓
How should analysts investigate? (SER-002)
↓
How should organizations prioritize cyber risk? (SER-003)
↓
How should organizations use attack paths to make better security decisions? (SER-004)
Fundamental questions: KNOWLEDGE_QUALITY_RULE.md
Reading guide
| Reader profile | Suggested path |
|---|---|
| New analyst | Sequential — all four series in order |
| Experienced analyst — risk focus | SER-001 skim → SER-003 → SER-004 |
| Investigation lead | SER-001 → SER-002 → SER-004 (investigation article) |
| Reference use | Glossary + FAQ; series indices for depth |
Estimated time: ~6–8 hours sequential reading (excluding glossary/FAQ).
Glossary (volume terms)
| KID | Term |
|---|---|
| KID-GLS-0001 | Evidence |
| KID-GLS-0002 | Investigation |
| KID-GLS-0003 | Security Context |
| KID-GLS-0004 | Risk |
| KID-GLS-0011 | Attack Path |
| KID-GLS-0013 | Correlation |
| KID-GLS-0014–0019 | Evidence quality terms |
| KID-GLS-0020–0021 | Risk Intelligence, Residual Risk |
| KID-GLS-0022–0023 | Blast Radius, Decision Support |
Full index: GLOSSARY_INDEX.md
Coherence assessment
Knowledge Architecture Coherence Assessment — 2026-07-03
Result: PASS WITH OBSERVATIONS
Report: KNOWLEDGE_ARCHITECTURE_COHERENCE_ASSESSMENT_VOLUME1.md
Publishable bundle (debt)
| Component | Status |
|---|---|
| LP-VOL-001 learning path | ⏳ DEBT-G-012 |
| WP-VOL-001 whitepaper | ⏳ |
| MAP-VOL-001 concept map | ⏳ |
| TUT-VOL-001 tutorial | ⏳ |
| Reading guide (formal) | ⏳ partial — this hub |
| D2 human review batch | ⏳ |
Standard: VOLUME_PUBLISHING_STANDARD.md
Foundation for
Volume 2 — Intelligence (VOLUME_002_INTELLIGENCE.md)