CSF 2.0 outcome: incidents are contained. Priority High. N1: containment prevents an incident from expanding, limiting damage and avoiding overwhelming resources; most incidents need some. C1: consider configuring security technologies (such as antivirus) and the security features of other technologies (operating systems, network devices) to contain automatically, for example quarantining malware, moving a compromised endpoint to an isolated remediation network or halting an infected container. C2: consider authorizing third parties (internet and cloud service providers) to contain certain incidents automatically on the organization's behalf (for example large-scale DDoS). R1: let incident handlers select and perform containment actions manually instead of or as well as automated measures.
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.