Contingency Plans
1. Objective
The purpose of this document is to establish authoritative, repeatable emergency containment and crisis isolation procedures. These contingency workflows enable anDREa B.V. (hereafter referred to as "anDREa") to execute rapid, high-impact security blockades to neutralize active exploits, isolate infected compute perimeters, and protect tenant data repositories.
2. Scope
The scope of this document aligns directly with the overall scope of the ISMS as defined in Clause 4 (Context of the Organization). It governs all tactical "Emergency Brake" interventions across the myDRE production infrastructure, multi-tenant cloud fabrics, and identity directories.
3. Availability and Access
This document is:
- Required reading for all anDREa employees and contractors.
- Available to all authorized interested parties and platform users via our public ISMS repository.
4. Emergency Isolations
When an active security incident, data breach threat, or programmatic exploit is detected within the myDRE platform, authorized corporate officers must execute specific Emergency Isolations interventions. These actions are designed to limit the blast radius of an incident and operate in conjunction with the Baseline Recovery of myDRE Service policy and the master Disaster Recovery Plan (DRP).
4.1 Identity Blockade: Specific User De-provisioning
To neutralize a compromised user credential or insider threat, an absolute block must be applied to the target identity inside the core directory.
4.1.1 Mandatory Request Criteria
Administrative isolation requires a formal ticketing submission containing:
- Authorized Origin: Submission by a validated Workspace Accountable or a mandated executive of the tenant organization (e.g., Institutional Security Officers, Department Heads).
- Identity Target: The exact legal name and unique system username (
@mydre.org) slated for termination. - Workspace Inventory: A comprehensive list of associated workspace perimeters formatted in the standard
dws-xxx-YYYnomenclature. - Forensic Substantiation: Explicit technical reasoning and accompanying diagnostic evidence.
4.1.2 Tactical Execution Steps
- Validation & Logging: The Director or Operations Manager evaluates the intake ticket and logs formal authorization directly within the ticket lifecycle.
- Directory Disabling: The operator logistically blocks the user account within Microsoft Entra ID, immediately invalidating active tokens and blocking further session authentication.
- Trigger Review Lifecycle: A mandatory follow-up checkpoint is programmatically scheduled for 5 working days post-incident to evaluate the block.
- Inter-Organizational Boundary Isolation: anDREa maintains absolute confidentiality. The organization will not disclose the underlying security reasons or forensic evidence of a block to secondary tenants or external organizations associated with the blocked individual. anDREa will instead facilitate a secure, closed meeting between the respective institutional legal/security bodies.
4.2 Compute Isolation: Virtual Machine Perimeter Quarantine
When a virtual endpoint exhibits signs of malware infection, cryptographic ransomware deployment, or unauthorized network brute-forcing, it must be quarantined immediately.
[System Alert / Tenant Ticket] ──► [Director / Security Officer Review] ──► [Network Quarantine Executed]
│
▼
[Tenant Disposition & Forensic Analysis]
4.2.1 Mandatory Request Criteria
Triggered automatically via Microsoft security telemetry warnings or an institutional support ticket requiring:
- Authorized Origin: Request from a Workspace Accountable or a mandated organizational authority.
- Workspace Scope: Exact identification of the host workspace and target VM hostname.
- Forensic Substantiation: Documentation of anomalous behavior or security logs.
4.2.2 Tactical Execution Steps
- Triage & Authorization: The Director or Security Officer assesses the indicators of compromise and records their administrative approval inside the ticket.
- Network Quarantine Execution: The technical team isolates the target VM, stripping its network interface cards of all inbound and outbound routing capabilities. The VM remains powered on to preserve volatile memory for forensics but is rendered completely inaccessible to the user and the internet.
- Forensic Analysis & Asset Disposition: anDREa initiates a targeted root-cause investigation. If the malware threat is verified to be contained strictly within the isolated VM boundary, the choice of final remediation (e.g., total asset destruction, rollback to an uncorrupted snapshot, or forensic image extraction) is routed to the Tenant's discretion.
4.3 Storage and Workspace Containment: Shutting Down a Workspace
When a multi-user workspace environment is heavily compromised or undergoing a formal data leakage investigation, the entire workspace container must be frozen.
4.3.1 Mandatory Request Criteria
Demands a high-priority ticket detailing:
- Authorized Origin: Request from a Workspace Accountable, Institutional Security Officer, or Department Head.
- Workspace Boundary: Target workspace names in the verified
dws-xxx-YYYformat. - Forensic Substantiation: Documented threat profile justifying full environment suspension.
4.3.2 Tactical Execution Steps
- Administrative Validation: The Director or Operations Manager reviews the submission and records their formal execution approval in the ticket tracking log.
- Logical Deactivation: All active compute nodes within the target workspace are gracefully powered down, and interactive member entry paths are suspended.
- Data Preservation Enforcements: The underlying Azure storage account housing the workspace data must be securely preserved. Deletion locks are verified, and storage configurations are frozen to prevent any modifications or data wiping during the forensic loop.
4.4 Enterprise Fabric Deactivation: Shutting Down a Subscription
In catastrophic scenarios involving widespread institutional compromise or billing disputes, anDREa can decommission an entire Azure subscription architecture.
4.4.1 Mandatory Request Criteria
Requires a strategic ticket containing:
- Authorized Origin: Request restricted exclusively to mandated tenant C-level executives or the primary Institutional Information Security Officer (CISO).
- Subscription Boundary: The explicit Azure Subscription ID and naming tokens.
- Forensic Substantiation: Comprehensive justification for fabric-level shutdown.
4.4.2 Tactical Execution Steps
- Executive Evaluation: The Director and/or Operations Manager perform a dual-authorization review of the request, logging the binding approval within the ticket.
- Fabric Preservation & Remediation Routing: Depending on the nature of the crisis, anDREa will execute one of two remediation paths:
- Absolute Freeze: Enforce a cryptographic and administrative lock across all underlying cloud storage accounts and resource blocks to preserve data integrity for regulatory review.
- Sovereign Handover: Evict anDREa administrative service principals and return absolute control of the entire cloud subscription fabric back to the tenant's internal IT department, shifting the security perimeter out of the anDREa ISMS boundary.
- Closing Documentation: All configuration alterations, principal removals, and timestamped actions are logged within the ticket.
4.5 Platform Deactivation: Shutting Down myDRE
The absolute decommissioning or emergency suspension of the entire global myDRE service is a catastrophic disaster event. The operational execution steps, communication trees, and multi-cloud code escrow triggers for a full service shutdown are governed strictly under the provisions of the master Disaster Recovery Plan.
Priority 1 is to understand what is going and based on that design and execute a plan of action in crises mode.
Do whatever is needed to be able to come in-control.