Incident Containment Methods
Containment includes all activities and procedures undertaken to reduce the impact of an incident. The objective of containment is to stop the spread of the incident. It does not necessarily identify or correct the root cause of the incident. The following are some examples of containment:
- Removing the infected device from the network
- Escalation to relevant stakeholders
- Updating the firewall rules to block/deny/drop traffic
Because each incident is different, the methods used for containment must be tailoreThe responsibility for initiating a containment action should reside with a senior officer as it is critical to consider the benefits and drawbacks before initiating any action.
Practice Question Set 3
- As an information security manager, you note that your organization is at risk of a ransomware attack. What is the most effective method to minimize the impact of a successful ransomware attack?
- Increase the number of information...