1. Prerequisites
- Completion of Vulnerability Validation
- Completion of Vulnerability Exposure Assessment
- Inventory of affected assets available
- Access to firewall administration platforms
- Access to cloud administration platforms
- Access to endpoint management platforms
- Access to network administration platforms
- Access to vulnerability management platform
- Access to affected systems and applications
- Incident or tracking ticket created
- Approval for emergency containment actions (if required)
2. Step-by-Step Instructions
-
Review Exposure Assessment
- Review:
- Vulnerability details
- Affected assets
- Exposure pathways
- Existing mitigations
- Business impact
- Confirm containment priorities.
- Review:
-
Identify High-Risk Assets
- Prioritise:
- Internet-facing assets
- Production systems
- Critical business services
- Privileged infrastructure
- Document containment scope.
- Prioritise:
-
Restrict External Access
- Reduce exposure by:
- Restricting public access
- Limiting network exposure
- Removing unnecessary internet access
- Restricting management interfaces
- Validate restrictions.
- Reduce exposure by:
-
Implement Temporary Security Controls
- Deploy temporary controls such as:
- Firewall rules
- WAF rules
- IDS/IPS protections
- Access control restrictions
- Network segmentation
- Document all controls implemented.
- Deploy temporary controls such as:
-
Disable Vulnerable Services
- Disable or restrict:
- Vulnerable applications
- Vulnerable services
- Unnecessary features
- Exposed interfaces
- Validate service status after changes.
- Disable or restrict:
-
Restrict Privileged Access
- Review and restrict:
- Administrative access
- Service account access
- Third-party access
- Remote access pathways
- Document changes made.
- Review and restrict:
-
Increase Monitoring Coverage
- Enable or enhance:
- Logging
- Alerting
- Threat detection rules
- Network monitoring
- Ensure monitoring covers affected assets.
- Enable or enhance:
-
Validate Exposure Reduction
- Confirm:
- Exposure pathways have been reduced
- Security controls are functioning
- Vulnerable services are restricted
- Monitoring is active
- Document validation results.
- Confirm:
-
Document Containment Actions
- Record:
- Systems affected
- Controls implemented
- Access restrictions applied
- Validation results
- Business impact of containment actions
- Preserve supporting evidence.
- Record:
-
Escalate and Hand Off
- Provide containment status to the Incident Commander and Technical Lead.
- Coordinate with:
- Remediation teams
- System owners
- Infrastructure teams
- Update the incident record with all actions performed.
3. Post-Action
- Ensure all containment actions are documented.
- Preserve evidence supporting exposure reduction activities.
- Record all temporary controls implemented.
- Track outstanding remediation activities.
- Attach validation results to the incident record.
- Continue monitoring affected assets until remediation is complete.
Contributor
Vishal Thakur GitHub: https://github.com/malienist
Contributed to the Arcana Incident Response Documentation Framework.
