Handbook
Digital Citizenship, Privacy, and Cybersecurity Intelligence
Support safe and responsible digital participation through asset inventory, threat modeling, account and device protection, privacy, scam response, recovery, and digital identity management.
Updated
Definition
Support safe and responsible digital participation through asset inventory, threat modeling, account and device protection, privacy, scam response, recovery, and digital identity management.
Coverage role
Digital systems mediate communication, money, work, learning, government, health, and relationships, making failures broadly consequential.
Scope
Included
- digital asset inventory
- threat and risk assessment
- authentication
- updates and backups
- privacy and data minimization
- scam and phishing response
- incident recovery
- digital identity and reputation
Excluded and non-goals
- offensive cyber activity
- spyware or covert surveillance
- credential theft
- bypassing controls
- false guarantees of security
Boundary rules
- Route to life.digital-citizenship-privacy-cybersecurity when the requested outcome requires one or more declared capabilities and the output can be represented by its canonical artifacts.
- Route to an adjacent or specialist intelligence when domain-specific rules, tools, or professional authority dominate the problem.
- Use general.reasoning to coordinate multi-pack conflicts, hard constraints, uncertainty, and decision status.
- Return ask, defer, or escalate when required context, source authority, consent, or accountable ownership is missing.
Capability semantics
| Capability ID | Name | Semantic intent |
|---|---|---|
capability.life.digital-citizenship-privacy-cybersecurity.inventory_digital_assets |
Inventory Digital Assets | Map accounts devices data identities dependencies recovery methods and critical services without collecting secrets. |
capability.life.digital-citizenship-privacy-cybersecurity.assess_threat_risk |
Assess Threat Risk | Identify plausible attackers accidents vulnerabilities impacts and priority controls. |
capability.life.digital-citizenship-privacy-cybersecurity.protect_accounts_devices |
Protect Accounts Devices | Plan unique credentials password manager MFA updates encryption screen locks and least privilege. |
capability.life.digital-citizenship-privacy-cybersecurity.plan_backup_recovery |
Plan Backup Recovery | Define tested backups recovery codes trusted contacts and continuity for critical services. |
capability.life.digital-citizenship-privacy-cybersecurity.manage_privacy |
Manage Privacy | Review data collection sharing permissions tracking public exposure and retention. |
capability.life.digital-citizenship-privacy-cybersecurity.detect_respond_scam |
Detect Respond Scam | Analyze messages links payment requests impersonation urgency and compromise indicators safely. |
capability.life.digital-citizenship-privacy-cybersecurity.respond_to_incident |
Respond To Incident | Contain preserve evidence contact providers change access monitor and recover in the correct order. |
capability.life.digital-citizenship-privacy-cybersecurity.support_responsible_participation |
Support Responsible Participation | Address consent attribution harassment permanence and reputation in digital spaces. |
Canonical artifact concepts
| Artifact type | Structural category | Semantic purpose |
|---|---|---|
artifact.life.digital-citizenship-privacy-cybersecurity.digital_asset_inventory |
ledger | Digital Asset Inventory for Digital Citizenship, Privacy, and Cybersecurity Intelligence: A controlled collection of uniquely identified entries with ownership, provenance, status, and review state. It supports the pack purpose of support safe and responsible digital participation through asset inventory, threat modeling, account and device protection, privacy, scam response, recovery, and digital identity management. |
artifact.life.digital-citizenship-privacy-cybersecurity.personal_threat_model |
model | Personal Threat Model for Digital Citizenship, Privacy, and Cybersecurity Intelligence: A purpose-bounded representation of entities, relationships, assumptions, boundaries, and evidence of adequacy. It supports the pack purpose of support safe and responsible digital participation through asset inventory, threat modeling, account and device protection, privacy, scam response, recovery, and digital identity management. |
artifact.life.digital-citizenship-privacy-cybersecurity.protection_baseline |
checklist | Protection Baseline for Digital Citizenship, Privacy, and Cybersecurity Intelligence: An applicability-aware control list that records item status, evidence, gaps, ownership, remediation, and review. It supports the pack purpose of support safe and responsible digital participation through asset inventory, threat modeling, account and device protection, privacy, scam response, recovery, and digital identity management. |
artifact.life.digital-citizenship-privacy-cybersecurity.backup_and_recovery_plan |
plan | Backup And Recovery Plan for Digital Citizenship, Privacy, and Cybersecurity Intelligence: A governed action design that sequences work, ownership, dependencies, timing, contingencies, and review. It supports the pack purpose of support safe and responsible digital participation through asset inventory, threat modeling, account and device protection, privacy, scam response, recovery, and digital identity management. |
artifact.life.digital-citizenship-privacy-cybersecurity.privacy_review |
analysis | Privacy Review for Digital Citizenship, Privacy, and Cybersecurity Intelligence: An evidence-linked assessment that states criteria, findings, uncertainty, limitations, status, and action. It supports the pack purpose of support safe and responsible digital participation through asset inventory, threat modeling, account and device protection, privacy, scam response, recovery, and digital identity management. |
artifact.life.digital-citizenship-privacy-cybersecurity.scam_assessment |
analysis | Scam Assessment for Digital Citizenship, Privacy, and Cybersecurity Intelligence: An evidence-linked assessment that states criteria, findings, uncertainty, limitations, status, and action. It supports the pack purpose of support safe and responsible digital participation through asset inventory, threat modeling, account and device protection, privacy, scam response, recovery, and digital identity management. |
artifact.life.digital-citizenship-privacy-cybersecurity.incident_response_plan |
plan | Incident Response Plan for Digital Citizenship, Privacy, and Cybersecurity Intelligence: A governed action design that sequences work, ownership, dependencies, timing, contingencies, and review. It supports the pack purpose of support safe and responsible digital participation through asset inventory, threat modeling, account and device protection, privacy, scam response, recovery, and digital identity management. |
artifact.life.digital-citizenship-privacy-cybersecurity.digital_participation_checklist |
checklist | Digital Participation Checklist for Digital Citizenship, Privacy, and Cybersecurity Intelligence: An applicability-aware control list that records item status, evidence, gaps, ownership, remediation, and review. It supports the pack purpose of support safe and responsible digital participation through asset inventory, threat modeling, account and device protection, privacy, scam response, recovery, and digital identity management. |
Method families and limits
| Method ID | Method | Use when | Avoid when |
|---|---|---|---|
method.life.digital-citizenship-privacy-cybersecurity.nist_govern_identify_protect_detect_respond_recover_adaptation |
NIST govern-identify-protect-detect-respond-recover adaptation | Use when participation depends on interaction between a person, task, environment, interface, support, and changing context. | Avoid assuming one impairment profile, choosing assistive options without the person, or treating minimum compliance as evidence of usable participation. |
method.life.digital-citizenship-privacy-cybersecurity.least_privilege |
least privilege | Use when access, data, authentication, communication, or recovery risk can be reduced through layered, least-authority, verified controls. | Avoid asking for secrets, weakening recovery to improve convenience, testing without authorization, or making destructive changes before evidence and rollback are secured. |
method.life.digital-citizenship-privacy-cybersecurity.defense_in_depth |
defense in depth | Use when access, data, authentication, communication, or recovery risk can be reduced through layered, least-authority, verified controls. | Avoid asking for secrets, weakening recovery to improve convenience, testing without authorization, or making destructive changes before evidence and rollback are secured. |
method.life.digital-citizenship-privacy-cybersecurity.data_minimization |
data minimization | Use when access, data, authentication, communication, or recovery risk can be reduced through layered, least-authority, verified controls. | Avoid asking for secrets, weakening recovery to improve convenience, testing without authorization, or making destructive changes before evidence and rollback are secured. |
method.life.digital-citizenship-privacy-cybersecurity.verified_channel_checks |
verified-channel checks | Use when access, data, authentication, communication, or recovery risk can be reduced through layered, least-authority, verified controls. | Avoid asking for secrets, weakening recovery to improve convenience, testing without authorization, or making destructive changes before evidence and rollback are secured. |
method.life.digital-citizenship-privacy-cybersecurity.incident_containment_and_recovery |
incident containment and recovery | Use when potential harm must be detected, prioritized, contained, routed, and recorded without exceeding available authority. | Avoid delaying emergency or safeguarding routes, asking for unnecessary sensitive detail, or giving instructions that increase exposure, destroy evidence, or conflict with official guidance. |
Pack-specific invariants
The pack also inherits the core invariants in core/core_invariants.yaml.
| Invariant ID | Statement | Failure action |
|---|---|---|
invariant.life.digital-citizenship-privacy-cybersecurity.01_secrets_are_never_requested_or_logged |
Secrets are never requested or logged. | escalate |
invariant.life.digital-citizenship-privacy-cybersecurity.02_defensive_guidance_may_not_enable_offensive_misuse |
Defensive guidance may not enable offensive misuse. | escalate |
invariant.life.digital-citizenship-privacy-cybersecurity.03_current_platform_and_authority_instructions_are_verified |
Current platform and authority instructions are verified. | escalate |
invariant.life.digital-citizenship-privacy-cybersecurity.04_backups_and_recovery_methods_are_tested_rather_than_assume |
Backups and recovery methods are tested rather than assumed. | escalate |
Dependencies and relations
Operational general intelligences: None
Foundation concepts: general.strategic-adversarial, general.tool-computational, general.systems, general.epistemic-evidence, general.practical-procedural
Life intelligences: life.media-information-literacy, life.personal-finance-resilience, life.consumer-contracts-claims, life.safety-first-response-emergency-readiness
Source roles
| Source ID | Claim roles | Runtime resolution required |
|---|---|---|
nist.csf2 |
concept_definition, measurement_or_security_practice, risk_control | True |
ec.digcomp |
competence_framework, concept_definition, evaluation_dimension | True |
unesco.mil |
competence_framework, concept_definition, evaluation_dimension | True |
local.authority |
jurisdiction_rule, runtime_fact, service_or_community_context | True |
Risk and authority boundary
Risk class: critical
- Active account or financial compromise identity theft stalking extortion ransomware or child-safety risk.
- Workplace or regulated-data incident.
- Any request for offensive access surveillance or evasion.
Accountable people retain consent, value, regulated, irreversible, and residual-risk decisions. This semantic page does not claim a deployed implementation.
Maturity
semantic: S3_reviewable_definition
contract: C3_testable_contract
implementation: I0_not_included
evidence: E2_source_roles_mapped
governance: G2_controls_and_review_defined
overlay: O2_paired_seed_complete
Paired overlay
Runtime maturity
- Capabilities: 8
- Technical floor→ceiling:
I1_runtime→I1_runtime - Autonomy floor→ceiling:
A0_assisted→A0_assisted - I1_runtime count: 8
- Evidence class:
contract: 8 - Full hierarchy: MATURITY-HIERARCHY.md
Evaluation suite status
- CI status:
pass - Suite:
evaluation_suites/digital-citizenship-privacy-cybersecurity.yaml - Cases defined: 7
- Capabilities under test: 8