RS.MI-01.340

Does your incident response process allow responders to manually select and execute containment actions during security incidents?

Explanation

Effective incident response requires the ability for responders to make real-time decisions about how to contain threats based on the specific nature of each incident. Manual containment options might include isolating affected systems from the network, suspending compromised accounts, blocking specific IP addresses, or shutting down vulnerable services. These capabilities are essential because automated responses may not be appropriate for all scenarios and could potentially cause business disruption if not carefully managed. Evidence could include incident response playbooks that outline available containment options, screenshots of security tools that provide manual containment capabilities, documentation of access controls showing that incident responders have appropriate permissions to execute containment actions, or post-incident reports demonstrating where manual containment was performed.

Implementation Example

Allow incident responders to manually select and perform containment actions

ID: RS.MI-01.340

Context

Function
RS: RESPOND
Category
RS.MI: Incident Mitigation
Sub-Category
Incidents are contained

ResponseHub is the product I wish I had when I was a CTO

Previously I was co-founder and CTO of Progression, a VC backed HR-tech startup used by some of the biggest names in tech.

As our sales grew, security questionnaires quickly became one of my biggest pain-points. They were confusing, hard to delegate and arrived like London busses - 3 at a time!

I'm building ResponseHub so that other teams don't have to go through this. Leave the security questionnaires to us so you can get back to closing deals, shipping product and building your team.

Signature
Neil Cameron
Founder, ResponseHub
Neil Cameron