Skip to content
Skip to main content
First Response & Preservation Operational Explainer

What should be recorded during containment?

Record containment as a timed sequence of individual actions and observed results, not as a later summary that “the system was isolated”.

Log each action at the level it occurred

For every step, record the operator, role, authority, trusted time, target and specific risk being addressed. Describe whether the action isolated an interface, revoked a session, changed a credential or rule, stopped a process, shut down a system or contacted a provider. Note whether it was manual, automated or provider-initiated.

Capture the visible state immediately before and after where practicable. Preserve incident tickets, commands, scripts, responder notes, internal communications, approvals and change records.

Record effects and deviations

Document alerts, ended sessions, address changes, service interruptions, notifications, file movements and failures. Identify systems and routes that remained active. If the plan changed or an action failed, record why and what followed rather than smoothing the sequence into an apparent success.

Containment should not be declared effective until its intended result is checked. A precise action log also distinguishes responder-generated records from earlier activity when technical logs are incomplete or distributed.

Key takeaway

Log containment action by action with purpose, authority, target, method, timing and verified result so both operational and evidential consequences can be reconstructed.

Reference: FRP-196First Response & Preservation