← CISM: manage security, risk, and incidents
08 / 8 · 30 MIN

Contain, recover, and learn

Coordinate evidence, communication, and return-to-service criteria.

Concept and mechanism

During response, containment reduces harm and exposure; it does not itself establish eradication or recovery. An isolated host may leave a credential valid elsewhere. Assess reach without concluding that all systems were compromised. When no harm is ongoing and the host is isolated, preserve relevant evidence with authorization before rebuilding destroys it. Document handling and access. To correlate logs from different clocks, retain originals and record the offset used in the timeline. Editing original timestamps to match removes traceability. These activities may run alongside other measures according to the plan and impact.

Guided application

Communicate known impact, actions, uncertainties, and the next update. Engage legal and privacy early when notification obligations may exist; do not invent universal deadlines or automatically wait for technical closure. Recovery requires service and data validated against agreed criteria. Working login without reconciliation proves neither integrity nor completion of business RTO. In post-incident review, examine causes and conditions that enabled the event. If certificate renewal lacked an owner, renewing one certificate restores service, but inventory, alerts, procedure, and ownership address the process failure. Track actions until closure evidence exists and test the behavior that previously failed.

IN PRACTICE

At 35 minutes of a 45-minute RTO, login works but acceptance is missing: report progress without prematurely declaring success or failure.

Common pitfalls

Containment as closure; hypothesis as cause; green backup as recovery; assigned action as completed action.

Related topics: Governance, strategy, and authority · Policies, investment, and reporting

Take this idea with you

Close with demonstrated criteria, preserved evidence, and tracked improvement.

Create account

Reference: Incident Response Recommendations and Considerations · CISM current outline before November 3, 2026