Build a review packet, not a security operation.
Information Security Analysts plan, implement, upgrade, or monitor measures that protect networks and information; the occupation may include vulnerability assessment and response to security breaches.1 Those consequential activities require authorized evidence, policy, human judgment, and system control. A safe AI workflow organizes fictional or organization-approved minimum-necessary labels and hands the unknowns to named authorities.
needs_review.Set a strict scope before any AI work.
Give the packet a fictional or approved scenario label, stated purpose, and named authority owner. Exclude all live alert/log content, hostnames, IP addresses, identities, credentials, ticket text, security-console output, customer data, and system identifiers.
Register supplied labels without drawing a conclusion.
For each supplied label, record the reference, owner, time/version, stated purpose, and status:
approved,unknown, orconflicting. Never ask the model whether an alert is real or what it means.Let AI organize, not access or investigate.
AI may format supplied labels, flag blank fields, group duplicate labels, and draft neutral questions. It must not connect to a system, retrieve evidence, interpret telemetry, validate an alert, correlate events, or infer an incident.
Turn missing facts into reviewer questions.
For every missing owner, time, source, policy, data-handling condition, or approval, preserve the gap as
unknown. Ask the authorized security or incident-response owner which current process governs it.Route authority to the right owner.
Security/incident response owns technical assessment and response; legal and privacy own obligations; communications owns messaging; business/data/system owners control impact, access, and implementation; records owners control evidence retention.
Stop at the review handoff.
Issue a local
needs_reviewreceipt. Do not open a console, update a ticket, create an alert, change a control, investigate, notify, report, or communicate.
Three bounded roles. One human control point.
unknown or conflicting. No technical or risk conclusion.The NIST AI RMF is voluntary guidance for incorporating trustworthiness considerations into AI systems.3 Use it as a governance lens, not as a security control or an approval to put security data into a model.
Let AI prepare labels. Let authorized people control security work.
| AI may prepare | Named human approval is required |
|---|---|
| Format supplied fictional or approved minimum-necessary labels. | Access, query, upload, retrieve, or analyze data from any security system, ticket, or environment. |
| Preserve supplied reference, owner, time/version, stated purpose, and unknown/conflict labels. | Validate an alert; investigate; or determine incident, severity, priority, scope, impact, materiality, risk, or evidence meaning. |
| Draft neutral questions about missing authority or contradictory labels. | Contain, eradicate, recover, remediate, notify, disclose, report, communicate, or change any control, credential, configuration, system, ticket, or record. |
| Produce a local review-only receipt. | Approve a vendor/tool, make legal/privacy/compliance conclusions, or take any external action. |
Five ways evidence prep quietly becomes unauthorized security work.
| Mistake | Why it fails | Repair |
|---|---|---|
| “Tell me if this is a real alert.” | Validation is a security judgment that can set an incident path. | Preserve only the supplied label and route validation to an authorized analyst in an approved environment. |
| “Summarize these logs.” | Logs can be sensitive and interpretation can become investigation. | Do not enter logs. Use a label register and request a separately authorized evidence-handling path. |
| “Rate this critical.” | Severity and priority may drive actions, commitments, and notifications. | Mark the rating as unknown and route the question to the current authorized rubric and owner. |
| “Open a ticket for the team.” | Creating or updating a ticket is a system write and may trigger workflow or disclosure. | Generate only a local receipt; an authorized human decides whether and where to record it. |
| “Send the incident summary.” | Communication can create legal, privacy, contractual, and reputational effects. | Stop at reviewer questions; human owners approve content, audience, channel, and timing. |
Security Signal Evidence Desk
Enter only fictional or organization-approved, minimum-necessary labels. This form stays in the browser and creates a review-only receipt; it does not send, save, query, or connect to anything.
What this manual is built on.
- O*NET OnLine: Information Security AnalystsOccupational context; profile marked updated 2026. [1]
- NIST SP 800-61 Rev. 3Current incident-response context; final published April 2025. [2]
- NIST AI Risk Management FrameworkVoluntary guidance for incorporating trustworthiness considerations into AI systems. [3]
- NIST AI 600-1: Generative AI ProfileGenerative-AI risk-management context. [4]
Sources are evidence context, not permission to use private material, assess a security event, or take security/system action. Recheck them and the controlling organization rules before any non-fictional use.
Where this guide fits.
Proposed links: the Computer Network Architect Change Evidence Desk for controlled network changes, the Computer Systems Engineers and Architects Evidence Desk for architecture decisions, the Web Administrator Operations Manual for site operations, and the Occupation AI Workflow Guide Directory for the broader shelf. Use these related guides to keep each workflow's authority boundary clear.