TAGSIA.COM

Rogue Device Response

Incident Investigation & Isolation Protocol

Doc ID: TAG-OT-CHK-02
Issue Date: Feb 2026
Rev: 1.1

PHASE 1: VERIFICATION

PHASE 2: CONTAINMENT

⚠️ DO NOT disconnect critical IACS hardware. Apply only to the unknown rogue device port.

  • Logical Isolation: Shutdown the specific switch port via CLI or Web GUI. If SNMP-triggered automation has already applied a port shutdown, verify the port state is confirmed down before proceeding.
    Verify:
  • Physical Isolation: Trace cable to switch port and physically remove the connection. Do not remove any device from the space until Phase 3 documentation is complete — treat it as evidence.
  • Quarantine: If the device is portable (laptop, USB adapter, rogue AP), remove it from the Engine Room or Bridge space. Place in a secure location pending investigation.

PHASE 3: DOCUMENTATION

Incident Description:

Detection Method:
Root Cause Assessment:

Investigated By (ETO):

Signature & Date

Verified By (Master / C/E):

Stamp & Date

Scroll to Top