diff --git a/q5-Ransomware-IR-Plan/Ransomware_Incident_Response_Plan.md b/q5-Ransomware-IR-Plan/Ransomware_Incident_Response_Plan.md index 5a2ea5d..818583a 100644 --- a/q5-Ransomware-IR-Plan/Ransomware_Incident_Response_Plan.md +++ b/q5-Ransomware-IR-Plan/Ransomware_Incident_Response_Plan.md @@ -1,20 +1,6 @@ # Ransomware Incident Response Plan ## Scenario: Encryption of ghaymah Block Storage Volumes -**Platform reference:** [ghaymah Block Storage](https://ghaymah.systems/products/storage/block) -**Document owner:** _[fill in โ€” IT/Security Lead]_ -**Last reviewed:** _[fill in date]_ -**Classification:** Internal โ€” Confidential - -**Note on figures in this document:** ghaymah's published pricing page (ghaymah.systems) confirms backup frequency by compute/storage tier (daily backup from the g4.medium plan upward, hourly backup from g5.large upward, with formal availability SLAs of 99.9% and 99.95% on the g6.xlarge and g7.2xlarge tiers respectively). ghaymah does not publish a per-tier RPO/RTO table in absolute time units. Where this document specifies RPO/RTO targets below the confirmed backup cadence, those are industry-standard planning targets and should be validated against the organization's actual ghaymah support/SLA agreement before this plan is finalized. - ---- - -## Table of Contents -1. [Emergency Contingency Plan โ€” First 60 Minutes](#1-emergency-contingency-plan--first-60-minutes) -2. [ghaymah Backup & Recovery Strategy](#2-ghaymah-backup--recovery-strategy) -3. [Prevention Plan](#3-prevention-plan) -4. [Appendices](#4-appendices) --- @@ -221,32 +207,8 @@ Per ghaymah's published shared responsibility model (Section 2.5), the measures --- -## 4. Appendices -### 4.1 Incident Response Roles -| Role | Responsibility | -|---|---| -| Incident Commander (IC) | Overall decision authority, coordinates response, owns comms to execs | -| Infrastructure Lead | Containment, isolation, backup/restore execution | -| Security Lead | Forensics, evidence preservation, threat scoping | -| Legal/Compliance | Regulatory notification, law enforcement liaison, ransom decision input | -| Communications Lead | Internal/external/customer communication | -### 4.2 Key External Contacts -| Contact | Purpose | Details | -|---|---|---| -| ghaymah Support | Platform-level incident support, log access | ghaymah.systems/support ยท ghaymah.systems/create-ticket | -| ghaymah Security Team | Reporting a suspected platform-level vulnerability or breach | ghaymah.systems/security/report | -| Cyber Insurance Provider | Claims, breach coach, negotiator referral | _[fill in]_ | -| National/Sector CERT | Regulatory and threat intelligence | _[fill in]_ | -| External IR/Forensics Firm | Deep forensic investigation | _[fill in]_ | -| Legal Counsel | Notification obligations, ransom legality | _[fill in]_ | -Note: ghaymah's public support channels also list WhatsApp and Telegram as live support options in addition to the ticketing links above; confirm current escalation paths and after-hours coverage directly with ghaymah support, as these are not detailed in public documentation. - -### 4.3 Revision History -| Date | Author | Change | -|---|---|---| -| _[fill in]_ | _[fill in]_ | Initial version |