Incident Containment and Recovery Lifecycle¶
Lifecycle¶
- Detect anomaly from monitoring or policy controls.
- Contain impacted runtime path.
- Revoke active capabilities where necessary.
- Preserve evidence bundle state.
- Escalate to authorized incident responder roles.
- Determine recovery path (resume under constraints, deny permanently, or rollback).
- Capture post-incident review outcomes.
Containment Objectives¶
- Stop unsafe execution
- Limit blast radius
- Preserve attributable evidence
- Maintain accountable decisions
Diagram¶
Source: diagrams/../diagrams/incident-containment-recovery.mmd
Related: