Zero Trust Engineering — Incident detection and case correlation

securityv1

/01 Views

Capability definition and hierarchyarchimate
Operational activity sequencesecurity
Exception and recovery activity sequencesecurity
Conformant decision branchsecurity
Denied, conditional or degraded branchsecurity
Identity-scoped information exchangec4
Context and decision inputsecurity
Policy authority and evaluationsecurity
Decision distribution and resource mediationsecurity
Enforcement decision evidencesecurity
Policy ownershiparchimate
Security control and protected resourcesecurity
Control and failure risksecurity
Conformance obligationarchimate
Capability assurancearchimate
Resource trust boundarysecurity
Activity-to-capability realizationarchimate
Logical service capability realizationarchimate
Assurance evidence collectionsecurity
Independent finding verificationsecurity
Finding-to-response processsecurity

/02 About

Visibility and analytics engineering reference for incident detection and case correlation, including policy, logical interfaces, recovery and assurance.

Purpose: Incident detection and case correlation. Domain: Visibility and analytics. Family: assurance. Scenario trigger: Promote security detection to incident investigation. Input assurance: Correlated alert context, asset criticality and threat evidence. Evaluation: Assess common incident scope, confidence and severity. Governing policy: Incident case creation, escalation and response policy. Resource-side obligation: Open evidence-linked incident with controlled response owners. Protected concern: Enterprise security case management service. Logical interface: Detection IDs asset graph analyst finding severity and case timeline. Evidence: Incident linkage triage status and chain of custody. Failure: Alert storm, duplicate case or misattributed incident. Required recovery: Merge or split cases through audited analyst decision. Architectural invariant: Incident severity and scope must be justified by traceable evidence Adoption: replace reference roles with concrete owner-controlled services. Specify exact provider/consumer identities, schema fields and classifications, signal provenance and freshness, idempotency, authorization lifetime, timeout/retry limits, observation and tamper evidence. A denied or failed operation must not silently become a permitted one. Scope: original vendor-neutral, implementation-agnostic technical reference model. Illustrative logical components and behaviors are neither a deployed system nor evidence of regulatory compliance. Package identities remain stable within the package; cross-package semantic reconciliation requires separate explicit registry support.

Curated · other · unspecified · Published by Lattix · 29 elements · 33 relationships · validated on publish

/03 Contents

Capability
Visibility and analytics, Incident detection and case correlation
Role
Visibility and analytics owner
Business Actor
Security telemetry or evidence producer
Activity
Promote security detection to incident investigation, Verify: Correlated alert context, asset criticality and threat evidence, Assess: Assess common incident scope, confidence and severity, Execute: Open evidence-linked incident with controlled response owners, Exception: Alert storm, duplicate case or misattributed incident, Recover: Merge or split cases through audited analyst decision, Verify and disposition finding
Application Component
Correlated alert context, asset criticality and threat evidence, Assess common incident scope, confidence and severity, Open evidence-linked incident with controlled response owners, Authenticated observation source, Detection and evidence correlation
Application
Enterprise security case management service
Policy
Incident case creation, escalation and response policy
API
Incident detection and case correlation logical interface
Message/Event Schema
Detection IDs asset graph analyst finding severity and case timeline
Data Store
Incident linkage triage status and chain of custody, Versioned technical finding
Control
Incident detection and case correlation enforcement assurance
Risk
Alert storm, duplicate case or misattributed incident risk
Requirement
Incident severity and scope must be justified by traceable evidence
Measure
Incident detection and case correlation assurance completeness
Trust Boundary
Incident detection and case correlation authority boundary
State
Control condition verified, Control gap or untrusted signal