Skip to content

Incident Containment and Recovery Lifecycle

Lifecycle

  1. Detect anomaly from monitoring or policy controls.
  2. Contain impacted runtime path.
  3. Revoke active capabilities where necessary.
  4. Preserve evidence bundle state.
  5. Escalate to authorized incident responder roles.
  6. Determine recovery path (resume under constraints, deny permanently, or rollback).
  7. Capture post-incident review outcomes.

Containment Objectives

  • Stop unsafe execution
  • Limit blast radius
  • Preserve attributable evidence
  • Maintain accountable decisions

Diagram

Source: diagrams/../diagrams/incident-containment-recovery.mmd

Related: