Skip to content
Skip to main content
First Response & Preservation Operational Explainer

What should be recorded before containment?

Record the live technical and operational state that containment is expected to change, prioritising the most volatile and significant evidence when time is short.

Establish the baseline

Note date, time zone, affected systems, users, locations and services. Capture original screens, alerts, applications, accounts, sessions, processes, connections and remote-access indicators without refreshing, filtering or acknowledging them first. Preserve visible device names, addresses, hostnames, usernames, ports, protocols, session IDs and provider references.

State the active harm and the evidence supporting that assessment. Identify critical dependencies - authentication, cloud services, communications, monitoring and safety or business functions - that containment may interrupt.

Record the intended change

Describe the containment objective in plain terms and how success will be tested. Record options considered, expected effects, systems or accounts left connected and possible alternative access routes. Include the decision-maker, authority and specialist advice.

If urgent harm prevents a full baseline, capture what matters most without unsafe delay and document what could not be preserved. Later logs may be incomplete or shaped by the action, so the pre-containment record remains the reference point.

Key takeaway

Preserve a timed baseline of live evidence, harm, dependencies and intended containment outcome before the response changes the environment, documenting any unavoidable gaps.

Reference: FRP-192First Response & Preservation