The preparation phase is the first phase of common incident response procedures and attempts to prevent security incidents. Incident identification occurs after a potential incident occurs and verifies it is an incident.
Containment attempts to limit the damage by preventing an incident from spreading, but it doesn’t prevent the original incident.
Eradication attempts to remove all malicious elements of an incident after it has been contained.
All six steps in order are preparation, identification, containment, eradication, recovery, and lessons learned.