| name | security-incident-containment |
| description | Contain an active security incident with least destructive actions, evidence preservation, credential/session control, isolation, communication, and recovery coordination. |
Security Incident Containment
Use when this procedure is the primary professional method needed for the assignment.
Procedure
- Confirm the decision or outcome this work must support, its scope, owner, constraints, and definition of success.
- Establish the evidence baseline using incident timeline, identities, hosts/services, credentials/tokens, network flows, logs, and business impact. Do not fill material gaps with assumptions when they can change the result.
- Establish incident authority/scope, preserve forensic evidence, choose reversible containment where possible, block active abuse, validate boundary closure, and track recovery prerequisites.
- Exercise realistic edge, failure, transition, or exception cases that could invalidate the result; record unresolved uncertainty explicitly.
- Validate the output against the original outcome and any neighboring professional contracts so this skill does not silently absorb another specialist's authority.
- Record the resulting artifact, measurements, decisions, provenance, and handoff information needed for another owner to reproduce or continue the work.
Quality gate
Active attacker/control path is closed, evidence remains usable, and containment does not create uncontrolled additional damage.