StudyToCert

All certifications / CISM / Lessons

ISACA Certified Information Security Manager (CISM) 2026 exam content outline · Domain 4: Incident management

Incident containment, eradication and recovery

▶ Watch the overview video

Last reviewed September 30, 2026 · Leer en español

Containment limits the damage an incident can do. It is usually the first priority once an incident is confirmed, especially for fast-spreading threats such as ransomware or worms. Short-term containment actions include isolating infected hosts from the network (many endpoint detection and response tools can do this with one action), disabling compromised accounts, revoking active sessions and tokens, blocking malicious domains and IP addresses, and segmenting affected networks. Longer-term containment may involve temporary fixes, such as extra filtering or monitoring, that let the business keep running while a permanent solution is built.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 6 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study CISM for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the CISM study plan