Concept and mechanism
An incident plan needs decisions, authority, and access that work during the actual shift. Before a crisis, rehearse evidence collection, communication, and containment with accountable people. During analysis, correlate principal, calls, resources, timing, and authorized changes. Finding severity helps prioritization but does not alone identify every affected datum. Record hypotheses and facts separately. For collected artifacts, retain provenance, timestamps, integrity, and controlled transfers. An incomplete timeline or evidence modified to fit a narrative harms investigation and cross-team handover.
Guided application
Containment should be confirmed on the observed path. Replacing a security group can block new connections without interrupting an already tracked connection. If that connection continues creating risk, assess authorized additional control and effects on shared resources. Stopping an instance can lose in-memory processes and connections; balance volatile collection with the urgency of preventing harm without imposing a blind sequence on every incident. Revoking older role sessions also does not close the path to new sessions if the source identity remains compromised. Address both aspects. After containment, confirm eradication, recovery, and service reconciliation before closure.
The connection persists after attaching the Quarantine group. A control’s name does not replace observation of its effect.
Common pitfalls
Nominal isolation; stopping without assessing evidence; time-based revocation as permanent blocking; containment as closure.
Related topics: Networking and administrative access · WAF and GenAI application protection
Confirm effects, retain proportionate evidence, and close each stage against criteria.
Reference: SCS-C03 domain 2 · SCS-C03