Closing the loop

What you have, across all seven chapters

Across seven chapters, the methodology gave you four things.

🔤 A vocabulary

Seven letters, each answering one question. A shared language that travels across teams and across cases, and that survives team turnover.

🏗️ A structure

Three phases that group the seven letters into a logical flow: preparation, investigation, resolution. The structure does the orienting; attention goes to the evidence.

🧭 A discipline

Each phase has a deliverable. Each deliverable is the input to the next phase. Skipping a phase shows up downstream. The discipline holds even when the case is small or the analyst is junior.

🪜 A scaffold

New analysts have a map. Experienced analysts have a checklist. Both find the methodology useful for their own reasons, and the methodology improves as cases reveal where it bends.


What ASSURED is, and is not

ASSURED is a triage methodology. Seven phases, Alert, Subject, Scope, Uncover, Risk, Escalation, Documentation, that take an analyst from “an alert fired” to “the case is closed or handed off, and the record survives.” It is not an incident-response framework. It is not a SOAR playbook. It is the work an analyst does before either of those starts.

The methodology's four commitments

Decisions are based on named inputs, not feelings. Two analysts working the same alert produce comparable outputs because the inputs are explicit: which detection mechanism fired, which dimensions of Subject came back clean or dirty, which entities are in or out of scope, which ATT&CK techniques the chain maps to, which RATM dimensions score high.

Roles and handoffs are explicit. The triage analyst owns the verdict and the handoff packet. The incident responder owns the lifecycle. The SOC manager owns the closure review. When the handoff is structured, no role does the other’s work.

False-positives are first-class cases. A documented close at triage carries the same evidentiary weight as a documented escalation. The methodology refuses the false-positive shrug: a full-arc investigation gets the nine-section event report whichever way the verdict lands, and even a Level 0 pattern close gets its five-field record (the fast path). Depth follows the case; the discipline of writing it down does not.

The loop is real. Scope → Uncover → Risk iterates as new evidence surfaces. Refining a scope mid-case is the methodology working, not the methodology failing.

What ASSURED is, plainly

Structured but not rigid. Thorough but not exhaustive. The methodology gives an analyst a place to stand on every alert that fires, and a record the team can read months later.


Where to go from here

🎯 Apply it to your next alert

The methodology is not a textbook; it is a practice. Use the structure on your next investigation and notice where you would otherwise have skipped a step. The patterns reveal themselves through use.

🧑‍🏫 Teach it

The methodology was designed to be taught. Mentoring a newer analyst through their first ASSURED-structured case is one of the fastest ways to refine your own use of it; the teaching guide and exercise packets carry the materials. The act of explaining sharpens application.

📈 Bring your team

Taking a whole SOC onto the methodology is a different project from adopting it yourself: it has a rollout sequence, a set of quality metrics, and a short list of duties only the team lead can carry. The adoption guide maps all three.

🤝 Contribute

The methodology lives at github.com/block/assured-methodology. Feedback, corrections, and contributions are welcome: releases follow the repo’s versioning policy and are recorded in the changelog. The next version of ASSURED is shaped by the people who use it.

📚 Keep the glossaries close

The three glossaries are built as ongoing references, not one-time reads: B.A.D. for adversary behaviors and tradecraft, C.A.T. for the tools and platforms of security operations, and C.L.E.A.R. for the shared vocabulary of triage itself.

Key Takeaway

The methodology is a shared way of working. The picture you assembled across seven chapters is the framework. The cases you apply it to are the practice. And the documentation you produce becomes the feedback loop that improves the next case.