Containment limits the damage of an incident and keeps it from spreading, buying time for eradication and recovery. The right strategy depends on what the attacker is doing, how critical the affected systems are and how much you still need to learn. NIST suggests weighing potential damage and theft of resources, the need to preserve evidence, service availability, the time and resources needed, the effectiveness of the strategy and how long the solution must last, for example a temporary block for hours versus a permanent change.
Keep reading for free
Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 6 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.