What is احتواء الحادث?
In this glossary, احتواء الحادث refers to: The actions taken to limit the impact of a security incident by isolating affected systems, preventing lateral movement, and preserving evidence for investigation.
How is احتواء الحادث used in cybersecurity?
In cybersecurity communication, this term appears in contexts such as: "قد تتضمن استراتيجيات احتواء الحادث فصل الأجهزة المخترقة عن الشبكة لمنع انتشار التهديد."
Why does احتواء الحادث matter in cybersecurity?
احتواء الحادث matters because it supports clear communication in SOC contexts for SOC Analysts, Security Engineers, and Incident Responders. It also connects to aviation training and exam language such as CISSP, CompTIA Security+, and CEH.
Who uses احتواء الحادث?
احتواء الحادث is mainly used by SOC Analysts, Security Engineers, and Incident Responders.
What category does احتواء الحادث belong to?
In this glossary, احتواء الحادث is grouped under SOC. Related pages in this category explain adjacent procedures, commands and operational concepts.
Where does this definition come from?
This definition is sourced from ISO 27001, NIST Cybersecurity Framework, MITRE ATT&CK and published by Protermify Cybersecurity as a static cybersecurity reference page.