Glossary

    Containment

    Incident Response

    Containment is a critical phase of incident response, focused on stopping the spread of a security incident. The goal is to limit damage while preserving evidence for investigation.

    AWS Containment Actions

    • Deactivate compromised IAM access keys
    • Attach a deny-all IAM policy to compromised users/roles
    • Replace security groups with quarantine groups (no inbound, no outbound)
    • Revoke active role sessions by attaching a deny-all inline policy with an aws:TokenIssueTime condition (note: IAM eventual consistency may create a brief propagation delay)
    • Snapshot EBS volumes before terminating for forensics
    • Block malicious IPs in WAF or NACLs

    Related AWS Services

    Toc Consulting: AWS Security & Cloud Architecture

    Securing your AWS estate?

    Our team helps engineering teams secure and architect AWS the right way: assessment in week one, a prioritized action plan in week two.