ArcanaIncident-response documentationBrowse the feedTemplates
Back to feed
Runbook · Contain
RB-CONTAIN-014

Vulnerability Exposure Reduction

1. Prerequisites

  • Completion of Vulnerability Validation
  • Completion of Vulnerability Exposure Assessment
  • Inventory of affected assets available
  • Access to firewall administration platforms
  • Access to cloud administration platforms
  • Access to endpoint management platforms
  • Access to network administration platforms
  • Access to vulnerability management platform
  • Access to affected systems and applications
  • Incident or tracking ticket created
  • Approval for emergency containment actions (if required)

2. Step-by-Step Instructions

  1. Review Exposure Assessment

    • Review:
      • Vulnerability details
      • Affected assets
      • Exposure pathways
      • Existing mitigations
      • Business impact
    • Confirm containment priorities.
  2. Identify High-Risk Assets

    • Prioritise:
      • Internet-facing assets
      • Production systems
      • Critical business services
      • Privileged infrastructure
    • Document containment scope.
  3. Restrict External Access

    • Reduce exposure by:
      • Restricting public access
      • Limiting network exposure
      • Removing unnecessary internet access
      • Restricting management interfaces
    • Validate restrictions.
  4. Implement Temporary Security Controls

    • Deploy temporary controls such as:
      • Firewall rules
      • WAF rules
      • IDS/IPS protections
      • Access control restrictions
      • Network segmentation
    • Document all controls implemented.
  5. Disable Vulnerable Services

    • Disable or restrict:
      • Vulnerable applications
      • Vulnerable services
      • Unnecessary features
      • Exposed interfaces
    • Validate service status after changes.
  6. Restrict Privileged Access

    • Review and restrict:
      • Administrative access
      • Service account access
      • Third-party access
      • Remote access pathways
    • Document changes made.
  7. Increase Monitoring Coverage

    • Enable or enhance:
      • Logging
      • Alerting
      • Threat detection rules
      • Network monitoring
    • Ensure monitoring covers affected assets.
  8. Validate Exposure Reduction

    • Confirm:
      • Exposure pathways have been reduced
      • Security controls are functioning
      • Vulnerable services are restricted
      • Monitoring is active
    • Document validation results.
  9. Document Containment Actions

    • Record:
      • Systems affected
      • Controls implemented
      • Access restrictions applied
      • Validation results
      • Business impact of containment actions
    • Preserve supporting evidence.
  10. Escalate and Hand Off

    • Provide containment status to the Incident Commander and Technical Lead.
    • Coordinate with:
      • Remediation teams
      • System owners
      • Infrastructure teams
    • Update the incident record with all actions performed.

3. Post-Action

  • Ensure all containment actions are documented.
  • Preserve evidence supporting exposure reduction activities.
  • Record all temporary controls implemented.
  • Track outstanding remediation activities.
  • Attach validation results to the incident record.
  • Continue monitoring affected assets until remediation is complete.

Contributor

Vishal Thakur GitHub: https://github.com/malienist

Contributed to the Arcana Incident Response Documentation Framework.