Files
splunk-security_content/response_phases/containment.yml
divious1 339e117806 skeleton
2020-08-25 18:56:44 -04:00

27 lines
1.0 KiB
YAML

name: Containment
id: 5d790fae-8ba6-4fc9-b288-78b67ef8370c
sla_type: minutes
sla:
description: The containment phase is for the acquiring, preserving, securing, and documenting of evidence that leads to the appropriate containment or mititgation of the incident. This phase will identify additional hosts and known vulnerabilities and implememt monitoring of the containment.
tags:
analytics_story:
NIST SP 800-61r2 Response Plan
usecase:
Advanced Threat Detection
nist:
RS.RP
references:
- 3.3 Containment, Eradication, and Recovery - https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf
response_task:
- id: 3d481dd1-4f30-4262-a846-78af6bdce11c
name: identify_additional_affected_hosts
- id: 735335a5-7ac0-4bdf-b1d3-6f4a6767d02f
name: contain_incident
- id: edb7867c-2e81-4356-a422-92781f4fa34c
name: implement_additional_monitoring
- id: f28177ae-78de-43c9-8692-e972e8a0aa62
name: identify_vunlerabilities
date: '2020-07-30'
version: 2
author: ButterCup