Learning Objectives:

  • Understand the principles of containment, eradication, and recovery in cyber incident management.

  • Apply containment strategies to limit the spread of cyber incidents.

  • Implement eradication strategies to remove the threat from affected systems.

  • Develop recovery strategies to restore normal operations.

3.1 Containment – Limiting the Spread of the Incident

Containment is the process of limiting the spread of a cyber incident to prevent further damage. The Coursera course teaches participants to “implement structured containment, eradication, and recovery strategies to manage active security incidents and restore affected systems” . The course covers “isolating compromised hosts to limit attacker movement” .

The FSB’s framework identifies mitigation as a key component of incident response, which “prevents the aggravation of the situation and eradicates cyber-threats in a timely manner to alleviate their impact on business operations and services” .

Key Containment Strategies:

  • Network Segmentation: Isolating affected network segments to prevent lateral movement.

  • System Isolation: Isolating compromised systems to prevent further compromise.

  • Access Revocation: Revoking access credentials that may have been compromised.

  • Temporary Shutdown: Temporarily shutting down affected systems to prevent further damage.

3.2 Eradication – Removing the Threat

Eradication is the process of removing the threat from affected systems. The Coursera course covers “removing malicious artifacts” and “validating system integrity before returning services to operation” .

Key Eradication Strategies:

  • Malware Removal: Removing malware from affected systems.

  • Patch Application: Applying patches to address vulnerabilities.

  • System Rebuilding: Rebuilding compromised systems from known-good backups.

  • Credential Resetting: Resetting credentials that may have been compromised.

  • Validation: Validating system integrity after eradication.

3.3 Recovery – Restoring Normal Operations

Recovery is the process of restoring normal operations after a cyber incident. The Coursera course covers “recovery strategies to manage active security incidents” and “validating system integrity before returning services to operation” . The course also covers “evaluating post-incident lessons learned and operational metrics to improve response effectiveness, strengthen defenses, and enhance long-term organizational resilience” .

Key Recovery Strategies:

  • System Restoration: Restoring systems from known-good backups.

  • Data Recovery: Recovering data from backups.

  • Service Restoration: Restoring services to operation.

  • Validation: Validating system integrity after recovery.

  • Resumption: Resuming normal operations.

The FSB’s framework identifies restoration as a key component of incident response, which “repairs and restores systems or assets affected by a cyber-incident to safely resume business-as-usual delivery of impacted services” .

3.4 Recovery Testing and Validation

Testing and validation are essential for ensuring that recovery is successful. The Coursera course covers “validating recovery processes and measuring resilience improvements” .

Key Testing Activities:

  • Backup Testing: Testing backups to ensure they can be restored.

  • Recovery Testing: Testing recovery procedures to ensure they are effective.

  • System Validation: Validating system integrity after recovery.

  • Operational Validation: Validating that operations have been restored.