Terminology Index

Glossary

1801 terms

Open concept maps

Showing 417-448 of 1801 terms

C
32

Containment Actions

The steps responders take to stop an incident from spreading or causing further harm, such as isolating a host, disabling an account, blocking a network connection, or revoking credentials, while preserving evidence for investigation.

Containment is the phase between detecting an incident and eradicating it, aimed at limiting damage and buying time. Actions are chosen to cut off the attacker (isolate endpoints, disable accounts, block traffic) without alerting them prematurely or destroying evidence. The right action depends on the incident and is weighed against business disruption, then confirmed effective through validation.

Introduced in: Incident Response Operations

Examples

  • Isolating an infected endpoint from the network to stop spread.
  • Disabling a compromised account to cut off attacker access.
  • Blocking a malicious outbound connection at the firewall.

No related terms linked yet.