DOC_ID: SCN-DOC-006|CLASSIFICATION: UNRESTRICTED
    LAST REVISED: JULY 29, 2026|PLATFORM: v2.7.0
    SECTION 01

    General Operating Directive

    SecNav simulation ranges replicate live security incidents. As an operator, your mission is to investigate anomalies, interrogate suspect personnel, correlate technical evidence, and execute operational containment within designated turn and time budgets.

    TACTICAL DIRECTIVE

    Simulations evaluate operator performance using objective forensic criteria rather than static multiple-choice questions. Every prompt sent to a target persona or system interface is evaluated dynamically against operational milestones.

    SECTION 02

    Engine Interface & Telemetry

    The simulation engine interface consists of three primary interaction components:

    1. The Evidence Dossier (Left Sidebar)

    Contains scenario artifacts (PCAPs, EDR process trees, badge swipe logs, runbooks). Highlight any line of text within an artifact to open the context menu and click "Add to Input". Citing exact log entries (timestamps, IPs, process names) is required to trigger confessions from defensive actors.

    2. Personnel Roster & Behavioral Traits

    Review active personnel profiles (SOC Lead, SysAdmin, Vendor Liaison) and their behavioral traits (e.g. evasive, defensive, panicked). Vague questions increase actor resistance; presenting unrefutable log evidence forces phase transitions.

    3. Tactical Terminal (Command Input)

    Enter conversation prompts or technical directives directly into the terminal (e.g., "Isolate host ENG-WS-12 via EDR" or "Derek Chen, explain why the SIEM proxy alert was ignored").

    SECTION 03

    Turn Budget & Intel Probes

    Turn Economy

    Every submitted prompt or command consumes 1 turn from your session budget. Each difficulty tier specifies a maximum turn limit (15 turns in Entry, 25 turns in Pro, 35 turns in Hardcore). Making concise, evidence-backed inputs conserves turns and boosts your forensic score.

    Intel Probes & Cooldowns

    If blocked or uncertain, click the "Intel Probe" button in the HUD header. Probes deduct 1 credit and issue an overwatch tactical hint in the activity log. A 120-second cooldown timer is enforced between probes.

    SECTION 04

    Domain Category Playbooks

    SecNav evaluates 6 domain categories. Filter by category to review specific operational directives and standards mappings:

    Cyber Security Operations

    NIST NICE SP 800-181 ALIGNED

    Triage live cyber threats, ingest IoCs into SIEM dashboards, correlate EDR logs, and execute containment directives.

    Operational Directives:
    • Formulate targeted SIEM queries for malicious IP addresses, domain hashes, and unusual port traffic.
    • Inspect EDR process trees to identify parent-child execution anomalies (e.g. WINWORD.EXE spawning powershell.exe).
    • Deobfuscate Base64 PowerShell or JavaScript strings retrieved from helpdesk attachments.
    • Issue explicit host containment orders (e.g., "Isolate host ENG-WS-12 via EDR Network Isolation").
    MAPPED FRAMEWORKS:└ NIST NICE Task T0028 (Incident Triage)└ O*NET 15-1212.00 (Information Security Analyst)

    Physical Security & Access Control

    ASIS CPP & PSP ALIGNED

    Audit perimeter access breaches, verify badge swipe timestamps, inspect transit timelines, and resolve physical security incidents.

    Operational Directives:
    • Cross-examine badge swipe logs against CCTV camera timelines to identify tailgating vectors.
    • Analyze physical transit timelines for unmonitored zones or VIP exposure windows.
    • Interrogate duty officers and access control leads regarding badge policy exceptions.
    • Issue physical perimeter lockdowns or dispatch guard details to specific facility sectors.
    MAPPED FRAMEWORKS:└ ASIS CPP Domain 2 (Physical Security)└ ISO/IEC 27001 Annex A.7.4 (Physical Security Monitoring)

    Converged Security Threats

    ISO 27001 & CISA CONVERGED ALIGNED

    Correlate physical access events with network intrusion telemetry to stop hybrid supply-chain and insider threats.

    Operational Directives:
    • Link physical badge swipes in public or unmonitored lounges with outbound wireless C2 beacons.
    • Confront rogue insiders or contractors using correlated physical and digital audit trails.
    • Audit third-party vendor access logs against physical maintenance sign-in sheets.
    • Enforce unified physical and network isolation protocols during high-severity incidents.
    MAPPED FRAMEWORKS:└ ISO/IEC 27001 Annex A.7.1 & A.12.1└ CISA Converged Security Guidelines

    Safety & Emergency Response

    ISO 45001 & OSHA ALIGNED

    Navigate operational emergencies, industrial control runbooks, hazard isolation, and field safety protocols under strict time limits.

    Operational Directives:
    • Review OT/SCADA telemetry dashboards to pinpoint failing sensor nodes or over-pressurized valves.
    • Execute Emergency Response Runbook procedures step-by-step to prevent environmental hazards.
    • Direct plant operators and safety marshals during facility evacuation procedures.
    • Verify TECC (Tactical Emergency Casualty Care) readiness and hazard control compliance.
    MAPPED FRAMEWORKS:└ ISO 45001 Clause 8.1.2 (Operational Controls)└ OSHA 1910.120 (HAZWOPER Guidelines)

    GRC & Governance Compliance

    ISO 31000 & COBIT 2019 ALIGNED

    Audit third-party SLAs, verify regulatory compliance controls, and present unrefutable evidence to reluctant corporate vendors.

    Operational Directives:
    • Inspect vendor contract memos and SLA documentation to identify contractual non-compliance.
    • Confront third-party liaisons with unrefutable log evidence to force emergency patch deployment.
    • Map incident findings against COBIT 2019 and NIST CSF v2.0 governance controls.
    • Compile audit-ready compliance packages for board and statutory regulatory handoffs.
    MAPPED FRAMEWORKS:└ ISO 31000 (Risk Management Guidelines)└ COBIT 2019 DSS05 & APO12 (ISACA)

    Executive Leadership & Crisis Control

    SHRM BASK & C-SUITE ALIGNED

    Manage executive stakeholders, legal notifications, PR crisis containment, and cross-departmental incident handoffs.

    Operational Directives:
    • Deliver concise, non-jargon executive briefings to CISOs, General Counsel, and Board members.
    • Manage communication channels between IT, Legal, HR, and External Media relations.
    • De-escalate inter-departmental panic and resolve operational friction during active crisis scenarios.
    • Authorize strategic trade-offs (e.g. system downtime vs. data exfiltration risk) under high pressure.
    MAPPED FRAMEWORKS:└ SHRM BASK Leadership Competency└ C-Suite Crisis Management Framework
    SECTION 05

    Difficulty Escalation Matrix

    ENTRY TIER
    1 ACTOR (PRIMARY LEAD)
    15 Turns | 45 Mins Window

    Pre-parsed logs and alerts. 1 cooperative mentor/lead persona. Focused on foundational triage and primary IoC identification.

    PRO TIER
    2 ACTORS (LEAD + SYSADMIN)
    25 Turns | 65 Mins Window

    Multi-source logs and process trees. 2 personnel actors including defensive staff. Requires log correlation and evidence presentation.

    HARDCORE TIER
    3–4 ACTORS (LEAD + STAFF + VENDORS + INSIDERS)
    35 Turns | 80 Mins Window

    Fragmented and obfuscated artifacts. 3–4 actors across CISO, Legal, and Vendors. Full attack chain reconstruction under friction.

    SECTION 06

    Standards Framework Alignment

    SecNav tactical evaluation rubrics map directly to official workforce registries:

    NIST NICE SP 800-181 (CYBER)
    Task T0028 (Triage), T0161 (Log Analysis), Ability A0012
    ASIS INTERNATIONAL (PHYSICAL)
    CPP Domain 2 Physical Asset Security, PSP Access Control
    ISO/IEC 27001 & ISO 31000 (GRC & CONVERGED)
    Annex A.7.4 Physical Security Monitoring, COBIT 2019 DSS05
    ISO 45001 & OSHA (SAFETY)
    Clause 8.1.2 Operational Controls, OSHA 1910.120 HAZWOPER
    SECTION 07

    Signed Decision Action Report (DAR)

    Upon scenario completion, your session telemetry, turn budget efficiency, and completed rubrics are compiled into a cryptographically signed **Decision Action Report (DAR)** certificate (`KMS_signature`). Employers and certifiers can verify your DAR credentials at secnavpro.com/verify.

    SECTION 08

    Operational FAQ

    How do I cite evidence in my dialogue?

    Highlight any line of text within an artifact inside the Evidence Dossier sidebar to open the context menu, then click 'Add to Input'. Citing exact timestamps, IPs, or process names is required to trigger confessions from defensive personnel.

    What happens if an actor stops responding or demands proof?

    Automated Threat Actors respond dynamically based on their behavioral traits. If an actor becomes defensive (e.g. a sysadmin hiding a misconfiguration), quote exact evidence from the Evidence Dossier to force a cognitive phase transition.

    What happens if I run out of turns?

    If your turn budget reaches 0 before completing primary objectives, the session terminates and issues an incomplete DAR report reflecting turns used.