Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Clear out junk files and repair common Windows errorsFree Scan →The incident response plan should name one person to own the containment decision, the technical owners who carry it out, and the business owner who can weigh disruption to the affected service. Those responsibilities may belong to different people; there is no single job title that owns containment in every organization.
What does it mean to own containment?
Containment is the set of actions taken to limit an incident’s spread or impact—for example, isolating a system or restricting access. Ownership is not simply who clicks the button. It involves three distinct responsibilities:
- Decision owner: Coordinates the response, decides or obtains approval for a containment action under the organization’s plan, and records the decision.
- Technical executor: Operates the affected system or security tool and implements the approved isolation or access change.
- Business risk owner: Assesses the consequences of interrupting the affected service and makes or informs decisions about accepting that operational risk.
One person may hold more than one responsibility in a smaller organization, but the plan should still make each responsibility explicit. NIST’s current guidance integrates incident response into broader cybersecurity risk management; it does not impose a universal containment job title. The Government of New Brunswick’s directive offers one jurisdiction-specific example of distinguishing system operation from business accountability.
Who should decide, approve, and act?
The incident lead is a natural coordinator for containment decisions, but the plan must specify who has authority to approve each action. A response can be delayed or misdirected if teams assume that coordination, technical access, and authority to accept service disruption all belong to the same person.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Fix the driver behind crashes, sound loss and screen glitches3Repair Windows errors before they cause bigger problems#1 Best Overall
| Responsibility | What the plan should assign |
|---|---|
| Decision and coordination | A named incident decision owner and a backup, with a route for escalation if neither is available. |
| Approval | Who may authorize specific actions, and whether approval thresholds change with incident severity or potential disruption. |
| Technical execution | The system, identity, or security-tool owners who can perform each containment action. |
| Operational risk | The business owner who understands the affected function and can assess the impact of interruption. |
These assignments are a governance choice, not a fixed org chart. For example, isolating a workstation may have a different approval path from disabling a shared service account or disconnecting an operational technology asset. Action-specific rules can allow urgent steps without treating every containment action as equally disruptive.
How should a containment decision balance speed and risk?
Containment may need to happen before investigators know the full scope of an incident. Microsoft Learn’s compromised-identity incident response SOP template states: “Contain the risk before you complete the full investigation, but apply organization-specific approval logic first.” The template is written for Defender XDR users and must be adapted to an organization’s tools, roles, policies, and escalation paths.
Rank #2
That balance calls for prompt action within pre-agreed authority—not improvisation about who is allowed to act. The plan should address how to limit exposure while preserving evidence and maintaining an adequate record of what was changed and when. The appropriate action depends on the incident and system; a containment step that reduces cyber risk can also interrupt a business function.
What should the plan say about identities and operational technology?
Compromised identities
Identity actions can affect accounts that are difficult to replace or essential to service operation. Microsoft’s SOP advises notifying the service owner before acting on a non-human identity. It also says not to disable a break-glass account without explicit authorization. An organization should identify these accounts and define their approval path in advance rather than assume routine account-handling rules apply.
Recommended Free Tools
Rank #3
Operational technology and critical systems
For operational technology (OT), containment decisions need asset, dependency, and process context. An indiscriminate disconnect can affect mission continuity or safety, so the incident lead should involve relevant OT and operational owners alongside the technical team. The Australian government’s OT inventory guidance recommends identifying assets and dependencies and documenting responsibilities for interacting with assets. It is sector-specific guidance for OT owners and operators, not a rule for every incident.
What to put in a containment ownership checklist
- Name the incident decision owner and a backup.
- Set approval thresholds for containment actions, including urgent or disruptive actions.
- Map each affected system or identity to its technical executor and business owner.
- Specify how evidence is preserved and how actions and decisions are recorded.
- Provide an escalation route for unavailable approvers, conflicting priorities, or uncertain authority.
- Define how containment decisions and system status are handed off to recovery.
Review the assignments against realistic scenarios: a compromised employee account, a critical service identity, and—where relevant—an OT asset with operational dependencies. The useful test is whether responders can identify who decides, who acts, and who assesses disruption without negotiating those roles during the incident.
Rank #4
Which guidance applies to your organization?
NIST SP 800-61 Revision 3, published in April 2025, supersedes Revision 2 and presents incident response recommendations as a CSF 2.0 Community Profile for integrating response throughout cybersecurity risk management. New Brunswick’s 7107-IR1 directive, published in May 2026, applies to the government departments, agencies, personnel, and connected organizations it specifies; it is an example of jurisdiction-specific governance, not a universal mandate. Microsoft’s identity SOP is vendor guidance that requires local customization. The Australian OT inventory guidance, updated August 14, 2025, applies as sector-specific context for OT owners and operators.
Quick Recap
Best Value
- NIST SP 800-61 Revision 3
- Government of New Brunswick directive 7107-IR1
- Microsoft Learn compromised-identity incident response SOP template
- Australian government OT asset inventory guidance
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

