# Lab 13.1: Incident Response Policies & Procedures > CompTIA Security+ Module 13 case study by Johnathan Belcher. ## Overview This lab strengthened my understanding of how organizations prepare for, respond to, and recover from security incidents. I learned how incident response, disaster recovery, business continuity, and record retention work together to reduce downtime, preserve evidence, and support resilient operations. ## What I Learned - **Incident Response**: The lifecycle from preparation through lessons learned, including containment, eradication, recovery, and post-incident improvements. - **Recovery Planning**: How hot sites, warm sites, backups, snapshots, and geographic diversity support resilient restoration after disruption. - **Business Continuity**: The role of COOP, IT contingency planning, crisis communication, and alternate business practices in keeping operations running. - **Retention Policies**: Why data and record retention matter for investigations, compliance, audits, and long-term security visibility. ## Core Topics I Can Explain Confidently **Incident Response & Threat Analysis** - Preparation, identification, containment, eradication, recovery, and lessons learned - Attack frameworks including MITRE ATT&CK, the Cyber Kill Chain, and the Diamond Model - Indicators of Attack and Indicators of Compromise for detection and response - Role of stakeholder communication during an incident **Continuity, Recovery, and Retention** - Hot sites, warm sites, off-site backups, and failover planning - Full, incremental, differential backups, and snapshots - Business continuity plans, disaster recovery plans, and COOP - Data taxonomy, classification, normalization, indexing, and retention timelines ## Exercise Summary - **IR Process and Frameworks**: How structured incident response phases reduce confusion during an event and how frameworks like MITRE ATT&CK and the Cyber Kill Chain help teams understand attacker behavior. - **DR, BCP, and COOP**: Recovery sites, backup methods, and continuity planning to explain how organizations keep essential services available during disruption. - **Teams and Retention**: How incident response teams coordinate technical and business functions and why retention policies matter for legal, operational, and forensic needs. ## Professional Value - Better incident communication to both technical and non-technical stakeholders. - Stronger resilience mindset connecting incident response with disaster recovery and business continuity. - Improved evidence awareness — preserving evidence before recovery begins so future analysis is reliable. - Compliance awareness of why retention policies are shaped by legal, operational, and security requirements. ## Security+ Alignment Supports Security+ Objective 4.2 by reinforcing the policies, processes, and procedures that guide incident response, continuity planning, and retention & governance.