The prerequisites and process of incident containment
Originally, the incident handling stage was divided into three parts: containment, eradication, and recovery (see Figure 12.1). However, applying them one by one may result in excessive action items, hence making the road to the final goal longer and less optimized.
Figure 12.1 – IR and handling phases
One should remember that the IR team is a mix of a hardcore technical team with a strong background in cybersecurity, system engineering, and maintenance on the one hand, and management and business owners on the other hand. Given the nature of the intrusion, such as the incident type, severity, and status (active, finished), the approach might vary.
Prerequisites of incident containment
Overall, a business will demand immediate actions to get back to regular operations, hence, containing the incident on the newly discovered affected host. Containment’s main goal is to keep the situation...