الملفات

1.1 KiB

Ransomware Incident Response & Recovery Plan

1. First 60-Minute Emergency Action Plan

  • Min 00-15 (Containment): Immediately isolate compromised Ghaymah Block Storage volumes via Network Policies. Revoke all API keys and IAM tokens associated with the affected storage node.
  • Min 15-30 (Triage & Assessment): Identify encryption entry point, identify affected snapshot IDs, and confirm immutable backup status.
  • Min 30-60 (Eradication): Terminate infected container instances and flush compromised cache/session stores.

2. Ghaymah Backup & Recovery Strategy

  • 3-2-1 Backup Rule: Maintain 3 copies of data across 2 different storage media types, with 1 immutable offsite copy on Ghaymah Block Storage WORM policies.
  • RPO (Recovery Point Objective): < 15 minutes via automated snapshotting.
  • RTO (Recovery Time Objective): < 60 minutes for clean environment restoration.

3. Comprehensive Prevention Plan

  1. Enforce Zero-Trust architecture and Least Privilege IAM policies across storage access points.
  2. Enable file integrity monitoring (FIM) and automated write-rate anomaly detection on Ghaymah Block Storage.