Volume 3 — Security Entities

Volume 3 shifts the encyclopedia from **how analysts think** (Volumes 1–2) to **what analysts think about**.

Volume 3 — Security Entities

Volume: VOL-003
Version: 1.1
Status:Complete — series frozen v1.0 · coherence PASS WITH OBSERVATIONS
Publishable level: V1 (curriculum) · V2 (coherence) · V3 bundle pending
Review: Every 6 months (next: 2027-01-03)
Prerequisite: Volume 1 — Analytical Foundations (minimum: KID-CON-0030); Volume 2 — Intelligence recommended


Overview

Volume 3 shifts the encyclopedia from how analysts think (Volumes 1–2) to what analysts think about.

Volumes 1 and 2 teach the analytical process and intelligence inputs. Volume 3 teaches the fundamental security entities analysts reason about when applying that process: assets, identities, applications, and services.

This volume is not asset management administration, identity governance policy, SDLC, or a database schema tour. It is practitioner curriculum on security entity semantics for better decisions.

Public title: Security Entities


Core ontology milestone

With Volume 3 complete, the encyclopedia's core ontology for Security Intelligence is established:

Volume Theme Question
VOL-001 Analytical Foundations How do analysts think?
VOL-002 Intelligence What knowledge do analysts use?
VOL-003 Security Entities What do analysts reason about?

Volumes 4–5 extend this foundation — they do not replace it.


Reader outcome

After Volume 3, a practitioner can:

  1. Explain what makes an asset meaningful for security decisions — not merely inventoried
  2. Explain why identities change scope, blast radius, and prioritization
  3. Explain how applications and services should be understood across investigations, risk, intelligence, and attack paths
  4. Connect entity understanding to Volume 1 analytical process and Volume 2 intelligence

Series (reading order)

Order Series Index Fundamental question Status
1 SER-008 Assets SERIES_008 What makes an asset meaningful for security decisions? ✅ frozen
2 SER-009 Identity SERIES_009 Why are identities central to modern security? ✅ frozen
3 SER-010 Applications & Services SERIES_010 How should applications and services be understood in security decisions? ✅ frozen

Total: 30 educational articles


Continuity with Volumes 1–2

Volume 1:  Evidence → Investigation → Risk → Attack Paths
Volume 2:  Threat Intel → Operational Intel → Security Intelligence
Volume 3:  Assets → Identity → Applications & Services

Cumulative mental model:

Evidence → Investigation → Risk → Attack Paths
    → Threat Intelligence → Operational Intelligence → Security Intelligence
        → Assets → Identities → Applications & Services

Every series asks: What decision does understanding this entity improve?

Volume 3 editorial pattern: Every article closes with Why this matters for security decisions.


Glossary (volume terms)

KID Term Status
KID-GLS-0009 Asset ✅ SER-008
KID-GLS-0010 Identity ✅ SER-009
KID-GLS-0029 Asset Criticality ✅ SER-008
KID-GLS-0030 Unknown Asset ✅ SER-008
KID-GLS-0031 Identity Privilege ✅ SER-009
KID-GLS-0032 Unknown Identity ✅ SER-009
KID-GLS-0033 Security Application ✅ SER-010
KID-GLS-0034 Security Service ✅ SER-010

Volume 3 completion criteria

Criterion Required for V1
SER-008 frozen v1.0
SER-009 frozen v1.0
SER-010 frozen v1.0
Volume coherence assessment (KACA-VOL3) ✅ PASS w/ obs
Publishable bundle debt — not blocking freeze

Assessment: KNOWLEDGE_ARCHITECTURE_COHERENCE_ASSESSMENT_VOLUME3.md


Foundation for

Volume 4 — Security Operations — how teams operationalize analysis, intelligence, and entity context (SOC workflows, hunting, exposure management, incident response). Begin after human review milestone on Volumes 1–3.



Related Articles