Second Modification

هذا الالتزام موجود في:
2026-07-28 12:32:40 +03:00
الأصل 5e1dc7b2dd
التزام d2dbeaf675
14 ملفات معدلة مع 585 إضافات و0 حذوفات

عرض الملف

@@ -0,0 +1,137 @@
Task5:
Scenario
A ransomware attack has encrypted all files stored on Ghaymah Block Storage.
Users can no longer access their files, and the attacker demands payment in exchange for the decryption key.
________________________________________
1. Emergency Response Plan (First 60 Minutes)
015 Minutes: Identification & Isolation
Objectives
• Confirm that a ransomware attack has occurred.
• Prevent the malware from spreading.
Actions
• Disconnect affected virtual machines from the network.
• Disable access to shared Block Storage volumes.
• Block suspicious IP addresses using firewall rules.
• Stop scheduled synchronization tasks.
• Notify the security and incident response teams.
1530 Minutes: Investigation
Objectives
Determine the scope of the attack.
Actions
• Review system and application logs.
• Identify the ransomware entry point.
• Determine which servers and storage volumes are affected.
• Preserve logs and forensic evidence.
• Check whether backups are intact.
3045 Minutes: Containment & Eradication
Objectives
Remove the ransomware and stop further encryption.
Actions
• Isolate infected systems.
• Scan all virtual machines with antivirus/EDR tools.
• Remove malicious processes and scheduled tasks.
• Rotate compromised credentials.
• Patch exploited vulnerabilities.
4560 Minutes: Recovery Preparation
Objectives
Prepare for service restoration.
Actions
• Verify the integrity of backups.
• Restore critical services in a test environment.
• Validate restored data.
• Monitor systems for reinfection.
Gradually return services to production.
Timeline Summary
Time Activity
015 min Detect attack and isolate affected systems
1530 min Investigate logs and identify affected resources
3045 min Remove ransomware and secure infrastructure
4560 min Restore from backups and validate services
________________________________________
2. Ghaymah Backup & Recovery Strategy
Recovery Point Objective (RPO)
Definition: The maximum acceptable amount of data loss.
Proposed Value: 15 minutes
This means backups or snapshots should occur at least every 15 minutes for critical data.
________________________________________
Recovery Time Objective (RTO)
Definition: The maximum acceptable downtime before services are restored.
Proposed Value: 1 hour
Critical applications should be operational again within one hour.
________________________________________
Backup Strategy
Daily Incremental Backups
Capture only changes made since the previous backup.
Advantages: Faster , Less storage usage
________________________________________
Weekly Full Backup
Create a complete copy of all Block Storage volumes.
Advantages: Faster restoration, Simplified disaster recovery
________________________________________
Monthly Offline Backup
Store a copy outside the production environment.
Purpose: Protection against ransomware encrypting online backups.
________________________________________
3-2-1 Backup Rule
The organization should follow the 3-2-1 backup strategy:
• 3 copies of the data (one primary + two backups).
• 2 different storage media (e.g., Block Storage and external storage/object storage).
• 1 off-site or offline backup stored separately from the production environment.
________________________________________
3. Comprehensive Prevention Plan
Identity & Access Management (IAM)
• Enable Multi-Factor Authentication (MFA).
• Apply the Principle of Least Privilege.
• Review user permissions regularly.
• Rotate passwords and API keys.
________________________________________
Network Security
• Enable firewalls.
• Segment production and backup networks.
• Restrict remote administration access.
• Use VPN for administrative access.
________________________________________
Endpoint Security
• Deploy Endpoint Detection and Response (EDR).
• Keep operating systems and software patched.
• Disable unnecessary services.
• Enable application allow-listing where appropriate.
________________________________________
Backup Protection
• Use immutable backups where possible.
• Encrypt backup data.
• Test backup restoration regularly.
• Store backups in separate locations.
________________________________________
Container Security
• Scan container images using Trivy before deployment.
• Avoid running containers as root.
• Store secrets securely.
• Continuously monitor container activity.
________________________________________
Monitoring & Detection
• Deploy a SIEM solution to centralize logs.
• Configure alerts for:
o Multiple failed logins.
o Unusual file modifications.
o Mass file encryption.
o Privilege escalation attempts.
________________________________________
Security Awareness
• Train employees to recognize phishing emails.
• Conduct regular security awareness sessions.
• Simulate phishing campaigns.
• Define clear incident reporting procedures.
________________________________________
Conclusion
A successful ransomware response depends on rapid detection, immediate isolation, reliable backups, and tested recovery procedures.
By implementing layered security controls—including strong IAM, network segmentation, continuous monitoring, secure container practices, and a resilient backup strategy based on the 3-2-1 rule—organizations using Ghaymah Cloud can significantly reduce the impact of ransomware attacks and recover services efficiently.