16 أسطر
1.1 KiB
Markdown
16 أسطر
1.1 KiB
Markdown
# Ransomware Incident Response & Recovery Plan
|
|
|
|
## 1. First 60-Minute Emergency Action Plan
|
|
- **Min 00-15 (Containment)**: Immediately isolate compromised Ghaymah Block Storage volumes via Network Policies. Revoke all API keys and IAM tokens associated with the affected storage node.
|
|
- **Min 15-30 (Triage & Assessment)**: Identify encryption entry point, identify affected snapshot IDs, and confirm immutable backup status.
|
|
- **Min 30-60 (Eradication)**: Terminate infected container instances and flush compromised cache/session stores.
|
|
|
|
## 2. Ghaymah Backup & Recovery Strategy
|
|
- **3-2-1 Backup Rule**: Maintain 3 copies of data across 2 different storage media types, with 1 immutable offsite copy on Ghaymah Block Storage WORM policies.
|
|
- **RPO (Recovery Point Objective)**: < 15 minutes via automated snapshotting.
|
|
- **RTO (Recovery Time Objective)**: < 60 minutes for clean environment restoration.
|
|
|
|
## 3. Comprehensive Prevention Plan
|
|
1. Enforce Zero-Trust architecture and Least Privilege IAM policies across storage access points.
|
|
2. Enable file integrity monitoring (FIM) and automated write-rate anomaly detection on Ghaymah Block Storage.
|