Volume 1 — Analytical Foundations

Volume 1 is the **core analytical reasoning chain** of a security analyst. It teaches how to establish trustworthy evidence, investigate with discipline, prioritize risk with context, and use attack paths as decision support.

Volume 1 — Analytical Foundations

Volume: VOL-001
Version: 1.0
Status:Complete — series frozen v1.0 · coherence PASS WITH OBSERVATIONS
Publishable level: V1 (curriculum) · V2 (coherence) · V3 bundle pending
Review: Every 6 months (next: 2027-01-03)


Overview

Volume 1 is the core analytical reasoning chain of a security analyst. It teaches how to establish trustworthy evidence, investigate with discipline, prioritize risk with context, and use attack paths as decision support.

This is the first independently validated volume of the SentriScope Cybersecurity Encyclopedia.


Reader outcome

After Volume 1, a practitioner can:

  1. Distinguish evidence from alerts, scores, and opinions
  2. Conduct investigations using hypothesis-driven discipline
  3. Prioritize cyber risk using context — not severity alone
  4. Interpret attack paths as decision-support models, not findings or CVE replacements

Series (reading order)

Order Series Index Articles
1 SER-001 Evidence-Based Security SERIES_001 15
2 SER-002 Investigation SERIES_002 12
3 SER-003 Risk Intelligence SERIES_003 10
4 SER-004 Attack Paths SERIES_004 10

Total: 47 educational articles


Curriculum arc

What is trustworthy evidence?     (SER-001)
        ↓
How should analysts investigate? (SER-002)
        ↓
How should organizations prioritize cyber risk? (SER-003)
        ↓
How should organizations use attack paths to make better security decisions? (SER-004)

Fundamental questions: KNOWLEDGE_QUALITY_RULE.md


Reading guide

Reader profile Suggested path
New analyst Sequential — all four series in order
Experienced analyst — risk focus SER-001 skim → SER-003 → SER-004
Investigation lead SER-001 → SER-002 → SER-004 (investigation article)
Reference use Glossary + FAQ; series indices for depth

Estimated time: ~6–8 hours sequential reading (excluding glossary/FAQ).


Glossary (volume terms)

KID Term
KID-GLS-0001 Evidence
KID-GLS-0002 Investigation
KID-GLS-0003 Security Context
KID-GLS-0004 Risk
KID-GLS-0011 Attack Path
KID-GLS-0013 Correlation
KID-GLS-0014–0019 Evidence quality terms
KID-GLS-0020–0021 Risk Intelligence, Residual Risk
KID-GLS-0022–0023 Blast Radius, Decision Support

Full index: GLOSSARY_INDEX.md


Coherence assessment

Knowledge Architecture Coherence Assessment — 2026-07-03
Result: PASS WITH OBSERVATIONS
Report: KNOWLEDGE_ARCHITECTURE_COHERENCE_ASSESSMENT_VOLUME1.md


Publishable bundle (debt)

Component Status
LP-VOL-001 learning path ⏳ DEBT-G-012
WP-VOL-001 whitepaper
MAP-VOL-001 concept map
TUT-VOL-001 tutorial
Reading guide (formal) ⏳ partial — this hub
D2 human review batch

Standard: VOLUME_PUBLISHING_STANDARD.md


Foundation for

Volume 2 — Intelligence (VOLUME_002_INTELLIGENCE.md)



Related Articles