Skip to main content

Verification Scenarios Index

Purpose

This page provides the canonical index of all verification scenarios defined in the Scheol Security Lab.

It ensures that scenarios are:

  • uniquely identified
  • linked to risks and controls
  • traceable over time
  • visible in terms of execution and effectiveness

Each scenario represents a practical validation activity used to test control behavior.


Scenario Index

Scenario IDTitleRelated RiskTarget Control(s)StatusLast ExecutionLink
V-001SSH Brute Force SimulationR-003C-005PlannedN/AVoir
V-002HTTP Exposure ProbingR-001C-001PlannedN/AVoir
V-003Web Authentication Abuse (Dolibarr)R-002C-003PlannedN/AVoir

Scenario Status Model

Each scenario is assigned one of the following statuses:

StatusDescription
PlannedScenario defined but not yet executed
TestedScenario executed at least once
ValidatedScenario consistently produces expected results
Needs ReviewScenario results inconsistent or outdated

Execution Tracking

For each scenario, the following should be tracked:

  • execution date
  • observed outcome
  • detection result
  • conclusion (effective / partial / ineffective)

This information is documented within each scenario file.


Relationship with Other Sections

Verification scenarios are directly linked to:

  • Risk Register → scenarios are derived from identified risks (R-001 to R-003)

  • Control Framework → scenarios validate control effectiveness (C-XXX)

  • Validation & Monitoring → scenarios test monitoring and detection capabilities

  • Residual Gaps → failed or incomplete scenarios highlight security gaps


Governance Rule

No scenario should exist without:

  • a linked risk
  • at least one target control

Current Scope

At the current stage, the scenario set is intentionally limited and focused:

  • only scenarios directly linked to existing risks
  • only scenarios that are realistically executable

This avoids:

  • artificial complexity
  • unused documentation
  • validation gaps

Current Maturity

Verification scenarios are considered early but structured.

Established

  • scenario identification aligned with risks
  • consistent scenario structure
  • initial scenario index

In Progress

  • execution of defined scenarios
  • documentation of results
  • linkage with monitoring signals

Planned / Next Phase

  • regular execution cycles
  • improved repeatability
  • integration with detection and alerting
  • expansion aligned with new risks

This index is intended to evolve alongside the lab’s validation maturity and control implementation.