Containment

Containment is the act of limiting an incident's spread and impact by isolating affected systems and cutting off the adversary's ability to expand. Its purpose is to stop the bleeding: to keep a problem from growing while the organization works to understand and remove it.

Within the Response phase, containment follows triage and runs alongside investigation. Once an incident is confirmed and its early scope understood, responders move to prevent further damage before attempting full eradication. Timing and judgment matter, because containing too narrowly can leave the adversary room to move, while containing too aggressively can disrupt the business or alert the attacker prematurely.

In practice, containment ranges from short-term measures that buy time to longer-term isolation that holds while recovery is planned. Responders may disconnect or segment affected hosts, disable compromised accounts, block malicious network paths, or restrict access to sensitive systems. Decisions weigh the need to stop spread against preserving evidence and maintaining essential operations. A well-chosen containment strategy depends on investigation to define scope, and it sets the stage for eradication by freezing the adversary's position so that their presence can be removed cleanly.

References#

  • NIST SP 800-61, Computer Security Incident Handling Guide
  • SANS, Incident Handler's Handbook

Cookie Consent

We use cookies to enhance your experience. Learn more