Part V: Security evaluation and response
Release tests measure behavior under specific conditions, while live monitoring and incident investigation check controls during use and recovery.
A blocked attack in a test leaves two questions: what else was tested, and will the same control work after deployment? Chapter 14 defines the tested configuration, attack conditions, metrics, and uncertainty. Chapter 15 connects those claims to observations from the running system. When a failure occurs, Chapter 16 uses the linked records to support containment, restoration, and a decision about returning the system to service.
Chapters in this part
- Evidence for release decisions: Release evidence ties each security claim to the tested cases, the stated attacker effort, and the measured uncertainty behind each number.
- Live monitoring and operating limits: Release evidence describes one tested configuration, while live requests, data, suppliers, and components keep changing around it.
- AI incidents: containment and recovery: Incident response distinguishes model error, policy failure, hostile content, account compromise, and infrastructure compromise while preserving evidence and testing recovery.