Containment, Eradication, and Recovery
It is one of the main stages of the
security incident response. In this
phase, responders take the right steps
to prevent any damage. In containment,
experts take the right measures to
prevent the spread of viruses. It
includes methods like disconnecting from
infected networks and systems.
Eradication is about eliminating the
threats from the network or systems by
applying removal techniques. The
recovery phase is about eliminating the
malware, recovering data from backups,
and rebuilding the infected systems.