الملفات
ghaymah-exam-waleed-secops/q5-ransomware-dr/ransomware-plan.md

16 أسطر
1.1 KiB
Markdown

# Ransomware Incident Response & Recovery Plan
## 1. First 60-Minute Emergency Action Plan
- **Min 00-15 (Containment)**: Immediately isolate compromised Ghaymah Block Storage volumes via Network Policies. Revoke all API keys and IAM tokens associated with the affected storage node.
- **Min 15-30 (Triage & Assessment)**: Identify encryption entry point, identify affected snapshot IDs, and confirm immutable backup status.
- **Min 30-60 (Eradication)**: Terminate infected container instances and flush compromised cache/session stores.
## 2. Ghaymah Backup & Recovery Strategy
- **3-2-1 Backup Rule**: Maintain 3 copies of data across 2 different storage media types, with 1 immutable offsite copy on Ghaymah Block Storage WORM policies.
- **RPO (Recovery Point Objective)**: < 15 minutes via automated snapshotting.
- **RTO (Recovery Time Objective)**: < 60 minutes for clean environment restoration.
## 3. Comprehensive Prevention Plan
1. Enforce Zero-Trust architecture and Least Privilege IAM policies across storage access points.
2. Enable file integrity monitoring (FIM) and automated write-rate anomaly detection on Ghaymah Block Storage.