Organizational Documents, Policies, and Network Documentation

CompTIA Network+ • Chapter 15

Organizational Documents, Policies, and Network Documentation

Reliable networks depend on more than hardware and protocols. Learn how governance documents, change controls, recovery plans, asset records, diagrams, baselines, IPAM, and business agreements turn technical knowledge into consistent organizational practice.

Policies & ProceduresChange ManagementIRP, DRP & BCPAsset Life CycleNetwork DiagramsIPAM & Agreements
RULESpolicies • SOPsNETWORKdevices • links • IPsconfigurationsRECORDSdiagrams • inventory
15.1 • Governance Foundations

Policies, Procedures, and Plans

Modern networks operate within an organizational framework. Documents define how technology may be used, who has authority, how work must be performed, and what should happen when normal operations are disrupted.

§

Policy

A management-approved rule that states what is permitted, required, or prohibited. Examples include acceptable use, password, and remote-access policies.

☑

Procedure

Step-by-step instructions explaining how to perform a task, such as installing software, responding to malware, or disabling a departing employee's account.

⌁

Plan

A coordinated approach for a broader event or objective, such as incident response, disaster recovery, business continuity, or system retirement.

Policies require management endorsement, communication, enforcement, and consequences. Procedures make those expectations repeatable. Plans coordinate people, priorities, resources, and decisions across a larger event.

Exam distinction: “Software must be approved” is a policy. “Follow these seven steps to install approved software” is a procedure.
15.2 • Controlled Change

Change Management

Uncontrolled changes can cause outages, security gaps, and configurations that nobody can explain. A formal change-management process ensures that proposed work is justified, reviewed, tested, scheduled, reversible, and documented.

REQUESTreason + impactREVIEWapprove + testSCHEDULEwindow + noticeIMPLEMENTwith rollbackVALIDATErecord results

Before implementation

Record the change request, business or technical reason, scope, affected systems, risk, dependencies, test results, approvals, communication plan, and maintenance window.

During and after

Follow exact implementation steps, validate success, activate the rollback plan if acceptance criteria fail, and update configurations, diagrams, inventory, and support records.

Maintenance window: The approved period in which disruptive work may occur. It is not the same as a rollback plan, which explains how to reverse the change.
15.3 • Organizational Resilience

Incident Response, Disaster Recovery, and Business Continuity

DocumentPrimary focusTypical content
Incident Response Plan (IRP)Contain and handle a security incidentClassification, escalation, response times, communications, evidence preservation
Disaster Recovery Plan (DRP)Restore IT systems after a major disruptionRecovery teams, backups, alternate facilities, restoration sequence, testing
Business Continuity Plan (BCP)Keep critical business functions operatingWorkarounds, alternate processes, essential staff, suppliers, communications
Business Impact Analysis (BIA)Determine impact and recovery prioritiesCritical processes, dependencies, acceptable interruption, financial and operational effects

An outage caused by a denial-of-service attack invokes the IRP while the attack is active. If a disaster destroys infrastructure, the DRP guides restoration. The BCP sustains essential operations during that recovery, and the BIA provides the priorities that shape both plans.

Evidence matters: An IRP must protect logs, captures, disk images, and chain-of-custody information so investigation and legal action remain possible.
15.4 • Asset Governance

Inventory Management and the System Life Cycle

An asset inventory records what the organization owns, where it is, who is responsible for it, how it is configured, and when its support or license expires. Hardware, software, virtual resources, cloud services, licenses, warranties, serial numbers, and ownership records all matter.

1

Purchase: Select an approved product, supplier, warranty, license, and support arrangement.

2

Deployment: Record identifiers, ownership, location, configuration, and relationships before production use.

3

Operation: Patch, monitor, maintain, audit, renew, and reconcile the asset against inventory.

4

Retirement: Remove dependencies, revoke access, archive required records, and update diagrams and inventory.

5

Disposal: Sanitize or destroy data-bearing media and use environmentally responsible disposal channels.

End-of-Life (EOL)

The vendor stops selling or developing the product. It may still receive limited support for a period.

End-of-Support (EOS)

Vendor security fixes, bug fixes, or technical support end. Continued operation creates growing risk.

15.5–15.6 • Repeatability and Security

SOPs, Hardening, and Common Policies

A Standard Operating Procedure (SOP) converts requirements and experience into a repeatable method. SOPs improve consistency, accountability, auditability, knowledge transfer, and continuity during staff turnover.

Hardening

Remove unnecessary applications, disable unused services, block unneeded ports, restrict removable media, change defaults, apply patches, and enforce least privilege.

Identity and access

Password, authentication-period, remote-access, onboarding, and offboarding policies govern account creation, use, session duration, and timely removal.

Devices and data

BYOD, patch management, DLP, clean-desk, and recording-equipment policies protect endpoints, information, and physical work areas.

PolicyWhat it governsExample control
AUPPermitted use of organizational systemsProhibit personal sales through company email
BYODPersonally owned devices used for workMinimum OS, encryption, screen lock, and management requirements
Remote accessConnections from outside the organizationApproved VPN, MFA, managed devices, logging
DLPMovement of sensitive informationBlock confidential documents from unauthorized recipients
Clean deskVisible physical informationRemove papers and media before leaving
Patch managementTesting and deployment of updatesRisk-based schedules with emergency exceptions
15.7 • Technical Records

Network Documentation

Accurate documentation reduces troubleshooting time, supports audits and capacity planning, and makes the network understandable to people who did not build it. Every approved change should trigger the relevant documentation update.

Physical

Device models and locations, cabling routes, port and cable identifiers, floor plans, rack elevations, patch panels, power connections, and MDF/IDF relationships.

Logical

VLANs, subnets, IP addressing, routing, security zones, WAN links, service flows, and Layer 2/Layer 3 relationships independent of exact physical placement.

Wireless

Site survey scope, supported device types, AP locations, channels, signal and noise measurements, coverage gaps, interference, and post-installation heat maps.

PHYSICAL VIEWLOGICAL VIEWSWITCH R1/U12PATCH PANELSERVER R2/U20VLAN 10VLAN 20ROUTED RELATIONSHIP
Currency rule: An outdated diagram can misdirect troubleshooting and change decisions. Include an owner, version, date, and review process.
15.8 • Known-Good State

Performance Baselines and Golden Configurations

Performance baseline

A historical representation of normal CPU, memory, storage, latency, errors, and utilization. Long-term collection reveals patterns, helps identify anomalies, supports capacity planning, and validates whether a repair restored normal behavior.

Golden configuration

An approved, known-good configuration used as the comparison standard. Differences can reveal configuration drift, unauthorized changes, missing hardening, or the cause of a new fault.

A baseline describes expected behavior; a golden configuration describes expected settings. Both must be versioned and updated after legitimate environmental changes.

15.9 • Address Records

IP Address Management (IPAM)

IPAM maintains an authoritative view of address space. It tracks subnets, assigned and available addresses, reservations, device ownership, DNS names, DHCP scopes, gateways, VLAN relationships, and address history.

Plan

Allocate appropriately sized subnets and avoid overlap before deployment.

Operate

Prevent duplicate assignments, identify unused space, and coordinate DHCP, DNS, and static addresses.

Audit

Trace an address to a device, user, location, or time and demonstrate control over the address estate.

A spreadsheet may be sufficient for a small stable environment. Larger or frequently changing networks benefit from dedicated IPAM platforms and automation.

15.10 • Organizational Agreements

NDA, SLA, and MOU

AgreementPurposeKey idea
Nondisclosure Agreement (NDA)Protect confidential informationDefines protected material, permitted disclosure, duration, and consequences
Service-Level Agreement (SLA)Define measurable service commitmentsAvailability, response and resolution targets, exclusions, measurement, reporting, and remedies
Memorandum of Understanding (MOU)Describe cooperation between partiesRoles, responsibilities, scope, and shared intentions; may supplement other agreements
Availability math: 99.99% annual uptime permits about 52.56 minutes of downtime in a 365-day year: 525,600 minutes × 0.0001.
15.11 • Interactive Practice

Choose the Correct Document

Select a scenario to reveal the best primary document or control.

Select a scenario.
The recommended document will appear here.
15.12 • Knowledge Check

Test Your Understanding

1. Which document explains the proper steps to install or remove software?
2. What should explain how to reverse an unsuccessful network change?
3. Which document should guide the organization during an active denial-of-service attack?
4. Which diagram best presents a high-level view of information flow?
5. Where should post-installation wireless heat maps be recorded?
15.13 • Chapter Summary

Essential Takeaways

Policies state rules; procedures state steps; plans coordinate broader responses.
Management endorsement, communication, enforcement, and review make policies effective.
Change management requires justification, impact analysis, testing, approval, scheduling, rollback, validation, and documentation.
The IRP handles incidents; the DRP restores technology; the BCP sustains critical operations; the BIA sets priorities.
Asset records follow hardware, software, licenses, warranties, ownership, EOL, EOS, retirement, and secure disposal.
SOPs create consistent, auditable actions and preserve organizational knowledge.
Hardening reduces attack surface by removing, disabling, blocking, patching, and restricting.
Physical diagrams show real equipment and cabling; logical diagrams show addressing and data relationships.
Site survey reports record wireless coverage, interference, AP placement, and heat maps.
Performance baselines define normal behavior; golden configurations define approved settings.
IPAM tracks subnets, assignments, availability, and relationships among address services.
NDA protects confidentiality, SLA defines measurable service commitments, and MOU outlines cooperation.