Long-Term Containment
Definition
The incident response phase in which emergency stabilisation measures are replaced with durable controls, such as patches, credential rotation, and firewall changes, that limit the attacker's access while preserving business operations and evidence integrity.
- Model
- SANS PICERL incident-response lifecycle
- Follows
- Short-term containment
- Precedes
- Eradication phase
- Typical actions
- Patching, credential rotation, firewall rule changes
- Goal
- Limit attacker access while business keeps operating
Common questions
How does long-term containment differ from short-term containment?+
Short-term containment isolates or disconnects systems immediately to stop active damage. Long-term containment replaces those temporary emergency measures with durable fixes such as patched systems, rotated credentials, and updated firewall rules, so the business can keep operating while the attacker's access stays restricted.
Why does evidence integrity matter during this phase?+
Patching or rebuilding a system can overwrite logs, memory artefacts, and other forensic traces before they are captured. Long-term containment is coordinated with the investigation team so imaging and log collection happen before or alongside remediation, not after it.
Related terms
- Access Revocation
- The removal of permissions, accounts, or trust relationships that the attacker exploited or could exploit. Distinct from credential rotation in that it...
- Attack Surface Reduction
- The systematic elimination of pathways an attacker could use to enter or move within a system. In incident response this includes closing...
- Compensating Control
- A security measure that reduces risk when the ideal control cannot be applied immediately. For example, routing traffic through a monitored proxy...
- Credential Rotation
- The process of invalidating and replacing passwords, API keys, certificates, and other authentication tokens that may have been exposed during an incident....
- System Hardening
- Configuration changes that reduce a system's attack surface by disabling unnecessary services, applying least-privilege access, enabling audit logging, and removing or restricting...