Advertisement

Containment

Limiting the spread or impact of an active incident.

Containment is the third NIST incident phase and aims to stop the bleeding before eradication. Short-term containment isolates the affected host or segment immediately; long-term containment applies temporary fixes that let business continue while preserving evidence for forensics. Common moves include network isolation, account disablement, and credential rotation — balanced against tipping off an attacker who may then destroy data.

Advertisement

Related terms

Back to Security Operations

Advertisement