TRAINING SCENARIO — FICTIONAL · NOT A REAL DOCUMENT
← Back to the Scenario Lab
BY-G6 · Cyber Resilience & Critical Infrastructure · Advanced · 60 min
The unrecorded replica
A governed response in the ai.heart canon · printable worksheet + reveal · 20 min
1 · The situation
Your entity runs a case-management system holding information classified up to SECRET. It was authorised to operate eighteen months ago and the authorisation record is complete. During a routine review you find two things. First, a disaster-recovery replica of the system's data sits on a second hosting service that was added by the delivery team during a migration and never recorded against the original hosting decision; nobody has checked its certification status. Second, an identity-aware access proxy now brokers staff access to the system. It was bought as part of a broader platform subscription by a different team, it is not in the gateway register, and no assessment evidence has been retained.
2 · Your decision
Take a position — or defer with reasons — before you reveal the governed response.
A · Raise both findings to security governance now — with the facts as they stand and no proposed remedy, so the accountable forum decides what happens to a live SECRET system.
B · Treat the two findings differently — escalate the uncertified replica immediately because classified information is at rest on unverified hosting, and handle the access proxy through the normal register and assessment process.
C · Spend the three weeks before the forum re-deriving the hosting and gateway registers — across the whole estate, then present the complete picture rather than two isolated findings.
D · Request certification and assessment evidence from both providers first — and escalate only if the evidence comes back missing, out of scope, or outside the 24-month window.
Your decision and one-line reason:
AI governanceThe DR replica also holds an AI model snapshot on the unverified hosting. Classified model weights at rest on uncertified infrastructure is the urgent limb of the finding.
3 · Governed response — reveal after deciding
AIHEART · NESTED CONTAINMENT GEOMETRY · GOVERNED RESPONSE BLOCK
Input under review: Two findings: a disaster-recovery replica of a SECRET-classified system on unrecorded hosting, and an identity-aware gateway capability with no assessment on file.
Classification of the event: A systemic discovery requiring triage and a governed release to security governance — one limb urgent, one parallel, neither buried in re-derivation.
| L | Layer | Check on this case | Verdict |
| L1 · Input validation | Both findings verified against the hosting decision record and the gateway register — they are absent from both. | PASS |
| L2 · Context analysis | The replica is classified data at rest on unverified hosting — the urgent limb; the gateway capability needs assessment in parallel. | HOLD |
| L3 · Harm / loss | SECRET data at rest where certification was never checked is the highest loss; the gateway is a boundary with no evidence. | PASS |
| L4 · Equity weighting | The delivery team acted in good faith during migration — the record gap is the finding, not the people. | PASS |
| L5 · Coherence check | Hosting certification and gateway assessment obligations apply; evidence requests are the next move, not re-deriving registers. | VERIFY |
| L6 · Integration gate | Cross-layer consistent: escalate the replica now, assess the gateway in parallel, correct the registers after. | PASS |
| L7 · Audit generation | Findings logged with timestamps and owners — append-only; the corrected registers follow. | PASS |
| L8 · Output certification | The governance notice is certified before release to the accountable forum. | PASS |
OVERALL VERDICT · HOLD → VERIFY → CERTIFIED RELEASE
HOLD → CERTIFIED RELEASE — differentiate, escalate, and let governance decide what happens next.
PERMISSION GATE · NODE 9 — RELEASE AUTHORITY
Security governance owns the acceptance of residual risk. The delivery team does not self-certify and does not re-derive the estate before acting.
[00:00:00.000] L1 findings verified · absent from hosting record + register
[00:00:01.000] L2 triage applied · replica urgent · gateway parallel
[00:00:02.000] L3 harm weighed · SECRET at rest on unverified hosting
[00:00:03.000] L4 equity held · good faith · record gap is the finding
[00:00:04.000] L5 obligations checked · certification + assessment · evidence next
[00:00:05.000] L6 integration passed · escalate / assess / correct
[00:00:06.000] L7 audit appended · findings + owners · registers to follow
[00:00:07.000] L8 notice certified to governance · EXIT = CERTIFIED ONLY
Governed answer
Raise both findings to security governance now, with the facts as they stand: escalate the unrecorded replica immediately because classified information is at rest on hosting whose certification was never verified, and commission the gateway assessment in parallel. Request certification and assessment evidence from both providers rather than spending weeks re-deriving registers — evidence first, registers corrected after. The delivery team acted in good faith; the record gap is the finding, and governance owns the acceptance.
Cited controls: PSPF Sec 13–15 (TECH) · Hosting Certification · Gateway assessment
Provenance. This governed response was drafted with AI assistance and gated against the
cited source documents. It is a training artefact of the BestYou·AI scenario layer and carries no endorsement;
the governed verification pipeline status of the source course (BY-G6) applies as stated on its course page.
Nothing here is legal advice.