{
  "uid": "cogitave.learn.respond-to-incidents",
  "kind": "module",
  "href": "/modules/respond-to-incidents/",
  "title": "Respond to incidents",
  "summary": "Walk the incident-response flow end to end - detection, severity declaration, single-commander roles, containment through a runbook, communication, recovery, and the blameless postmortem - and see how business continuity and disaster recovery extend the same discipline to a region loss or a destructive event.",
  "type": null,
  "products": [
    "cogitave-core"
  ],
  "roles": [
    "developer"
  ],
  "levels": [
    "intermediate"
  ],
  "subjects": [
    "it-management"
  ],
  "headings": [],
  "source": "By the end of this module, you'll be able to:\n- Walk the incident lifecycle from detection through declaration, response, recovery, and the blameless postmortem, and name what enforces each step.\n- Apply the single severity scale and the declare-high-downgrade-later principle, and explain why a security-relevant signal always overrides the apparent severity.\n- Name the single-commander incident roles and the one rule that never bends: the Incident Commander never debugs hands-on and is never the same person as a responder.\n- Explain how the BIA, service tiers, backup strategy, and DR plan chain together to meet an RTO/RPO, and in what order the estate recovers when multiple services are down.\n- Read ops/README.md as the entry point to the incident-response and business-continuity trees and follow it to the owning document for the detail.\n",
  "units": [
    "cogitave.learn.respond-to-incidents.introduction",
    "cogitave.learn.respond-to-incidents.the-incident-response-model",
    "cogitave.learn.respond-to-incidents.business-continuity",
    "cogitave.learn.respond-to-incidents.knowledge-check",
    "cogitave.learn.respond-to-incidents.summary"
  ],
  "durationInMinutes": 29,
  "badge": "cogitave.learn.respond-to-incidents.badge",
  "partOf": "cogitave.learn.paths.operate-the-estate"
}