GRC › Module 8 › Lesson 3
No Forged Artifacts
Anti-fraud literacy — forged policy, backdated log, fake certificate, altered screenshot, synthetic audit letter — refused artifact categories on YOUR `$GRC_LAB` ethics card.
Visual · t37_no_forged_artifacts
No forged artifacts = refused fraud rows. $GRC_LAB. Original Cyberlium.
Opening
Forged audit artifacts enable certification fraud — name refused categories and write the refusal habit before creating fake ISO certificates or backdated policies.
No forged artifacts literacy names: forged policy PDF category, backdated system log category, fake ISO/SOC certificate category, altered screenshot category, and synthetic external auditor letter category. Analyst documents anti-fraud ethics card on `$GRC_LAB` — five refused categories with detection stub each — without creating any refused artifact even 'for lab demo,' without teaching fraud techniques as 'awareness,' without submitting forged packs for certification. Cyberlium refuses forged audit artifacts for fraud — YOUR ethics card states refusal explicitly. Refused: all five categories plus any variant used for compliance fraud. Lab row: anti-fraud ethics card (five refused categories, detection stub, NEVER create line).
1. Refused artifact categories
Forged policy, backdated log, fake certificate, altered screenshot, synthetic auditor letter — five refused rows.
Each category cites why fraud enables harm — not 'how to forge' recipes.
Command guide
Try these commands — Refused artifact categories
═══ TOOLS & WEBSITES ═══ Browse / read these (authorized learning only — stay in YOUR lab / program scope)
ISACA ethics — https://www.isaca.org/resources/glossary ISO 27001 — https://www.iso.org/isoiec-27001-information-security.html PCI DSS — https://www.pcisecuritystandards.org/
═══ INSTALL ═══
Linux (Debian/Ubuntu):
Command — copy this
sudo apt install python3
macOS:
Command — copy this
brew install python3
Windows: Download https://python.org/downloads/
═══ LINUX / macOS ═══
Command — copy this
export GRC_LAB=${GRC_LAB:-$HOME/cyberlium-lab/t37-grc}
cat > "$GRC_LAB/notes/no-forged-artifacts.txt" <<'EOF'
HARD BAN — forged compliance artifacts:
NEVER forge ISO 27001 certificates or fake CB audit letters
NEVER fabricate SOC2 Type II reports for customers, sales, or RFPs
NEVER create counterfeit PCI AOC/ROC documents
NEVER backdate evidence to pass a real audit
NEVER instruct illegal GDPR/data processing evasion
ALLOWED in lab:
Templates clearly marked LAB SAMPLE — NOT FOR PRODUCTION AUDIT CLAIMS
Fictional finding IDs, fictional evidence IDs, literacy markdown/CSV
curl public framework pages for literacy — not impersonating auditors
If mentor asks for fake cert: refuse and document gap instead
EOFCommand — copy this
grep -E 'NEVER|LAB SAMPLE|HARD BAN' "$GRC_LAB/notes/no-forged-artifacts.txt"
grep NEVER "$GRC_LAB/notes/not-legal-advice.txt" "$GRC_LAB/notes/external-audit-prep.md"
python3 -c "print('Refusal: forged certs/SOC2 = fraud — use labeled lab stubs only')"Primary tools to practice this lesson: grep, python3. Reference sites: ISACA ethics (https://www.isaca.org/resources/glossary); ISO 27001 (https://www.iso.org/isoiec-27001-information-security.html); PCI DSS (https://www.pcisecuritystandards.org/). Run every command in the box — install first, then the usage lines — only on YOUR lab / program scope.
2. Detection literacy
Detection stub names metadata checks, date consistency, source verification literacy.
Honest LAB evidence from Modules 6–8 — contrast with refused categories.
3. Course boundary
Cyberlium teaches refusal and detection literacy — not forgery techniques.
Educational GRC — not legal advice; never submit forged artifacts anywhere.
4. What you ship: anti-fraud ethics card
Five refused categories + detection stub + NEVER create forged artifact line.
5. What you record before the next lesson
Anti-fraud ethics card path.
6. Wrong vs right: fraudulent certs vs YOUR lab templates
Worked failure — same MSF word, opposite target. Right never needs a café Wi-Fi or classmate laptop.
Wrong
Create fake ISO 27001 certificate PDF 'to practice evidence hygiene' and include in lab pack.
Right
Anti-fraud ethics card on `$GRC_LAB`. Next: Gap Lab.
Mission: anti-fraud ethics card
1) Name five refused forged artifact categories. 2) Detection stub per category. 3) Contrast with honest LAB evidence habit. 4) Write NEVER create forged artifact line.
Stuck? Ask Cyberlium AI Mentor
Ask Mentor: “Detection stub — metadata check literacy?”
Knowledge Check
APPLY: Cyberlium refuses:
Multiple choice
Knowledge Check
APPLY: True or False: Fake ISO certificates are acceptable lab deliverables.
True or False
Knowledge Check
APPLY: Anti-fraud card includes:
Multiple choice