View a markdown version of this page

Submit containment preferences - AWS Security Incident Response User Guide

Submit containment preferences

To configure containment preferences for your account or organization, create an AWS Support case.

In your support case, specify the following information:

When configured, AWS Security Incident Response executes executes the authorized containment actions during active security incidents to help protect your environment.

  • Your AWS Organizations ID or specific account IDs where containment actions should be authorized.

  • Your preferred containment option.

Note

AWS Security Incident Response executes containment actions only when configured with the appropriate preferences and after the required AWS CloudFormation StackSet is deployed to grant necessary permissions.