Actions to limit the spread and impact of a security incident while investigation continues.
Containment is the incident response phase focused on limiting damage and preventing incident spread. Containment actions might include isolating affected systems, blocking malicious IPs, disabling compromised accounts, or segmenting networks. Containment must balance limiting damage against preserving evidence and maintaining business operations. Short-term containment provides immediate protection; long-term containment enables continued operations while preparing eradication.
Why It Matters
The DSC Perspective:
Fast containment limits damage. Have pre-defined containment actions ready—don't figure out how to isolate systems during an active incident. Balance speed with evidence preservation needs.
