Containment Policy
What the AI SOC may do without asking. Edits here create a v1.4 draft that requires CISO signature.
| Action | Critical | High | Medium | Low |
|---|---|---|---|---|
| Isolate workstation | ||||
| Isolate server | ||||
| Isolate CUI-enclave asset | ||||
| Quarantine file | ||||
| Kill process | ||||
| Block IP/URL/domain via SCM EDL | ||||
| Push SCM security policy change | ||||
| Disable user | ||||
| Revoke sessions | ||||
| Reset password | ||||
| Delete email | ||||
| Block sender |
Guardrails
- Servers and domain controllers always require approval.
- CUI enclave assets: isolate auto only for Critical with ≥ 90% confidence and ≥ 95% when the user is an ITAR-authorized engineer.
- SCM changes are limited to EDLs and the Vault-SOC rule folder.
- Below 80% confidence every action requires approval.
- Every action is reversible from Actions & Approvals where the platform allows.
Change history
- v1.3Sep 30, 2026 · CISO, Halcyon Precision
CUI enclave isolation: auto only for Critical ≥ 95% confidence; quarterly review.
- v1.2Aug 14, 2026 · CISO, Halcyon Precision
Enabled auto Revoke sessions for High after tabletop exercise.
- v1.1Jul 22, 2026 · IT Director
Added SCM EDL blocking scoped to Vault-SOC folder.
- v1.0Jul 1, 2026 · CISO, Halcyon Precision
Initial signed policy at service go-live.