asterion_ir.md
1siavash@portfolio:~$ cat asterion_ir.md

# project / synthetic incident-response case study

INCIDENT RESPONSE · CUI · ENTRA · FORTIGATE · SPLUNK · DATTO · TABLETOP

Asterion Defense Systems: the operational follow-up

This is the response program that follows the Asterion NIST readiness assessment. It takes the six GRC findings and turns them into roles, provider handoffs, evidence requirements, playbooks, recovery gates, communications, and a realistic ransomware/CUI-exfiltration tabletop.

Scope note

Asterion Defense Systems is fictional. The company, architecture, evidence, providers, scores, owners, dates, and incident scenarios are synthetic. This is an operational design exercise—not a representation of a real employer, customer, incident, certification, or legal determination.

Classified-program boundary

Asterion may support programs involving classified information, including Top Secret material, but that work is handled in a separate accredited facility and classified information system boundary. Classified systems and handling are not stored in, transmitted through, or assessed by this unclassified corporate/CUI incident-response program.

01 / GRC → IR handoff

The response program begins where the assessment leaves off

The companion GRC assessment found an incomplete CUI boundary, inconsistent privileged access, telemetry gaps, weak transfer evidence, unproven restoration, and immature incident/supplier processes. This page is the operational answer to those findings.

assessment define scope → score risk → assign POA&M response detect → contain → preserve → recover → improve
preceding projectAsterion NIST readiness assessment ↗

Workbook transcription, six findings, risk register, evidence register, and six-action POA&M.

this projectIncident-response program

Directive plan, provider model, playbooks, detection evidence, recovery runbook, case forms, and tabletop.

closure loopAfter-action → POA&M

Exercise and incident lessons return to the risk register, owners, due dates, detections, and retest evidence.

02 / architecture and trust boundaries

Response decisions follow the actual environment

The fictional environment has one ISP, one FortiGate edge, Microsoft Entra ID, an on-premises directory dependency, Windows laptops and desktops, one file server, one application server, one SQL server, Splunk, Datto BCDR, and two separate third-party providers.

Asterion incident response architecture showing Entra, FortiGate, Windows endpoints, servers, Splunk, Datto, and third-party providers.
Embedded architecture view for the unclassified corporate/CUI operating model.
identifierzonereference architectureresponse significance

EDGE-FGT-01

Internet edge

One ISP → FortiGate perimeter firewall

Preserve traffic, VPN, policy, admin, and configuration-change evidence; use the edge as one containment control.

CORE-CISCO-01

Core switching

Cisco internal switching and segmented networks

Record isolation changes, affected VLAN/path, approving owner, and rollback condition.

ENTRA-01

Cloud identity

Microsoft Entra ID is the primary cloud identity plane

Disable or restrict identities, revoke sessions, review privileged roles, and preserve sign-in/audit evidence.

AD-DC01

Directory dependency

On-premises Windows domain controller

Scope for lateral movement, privileged access, authentication, and recovery dependencies.

FS01

File services

Windows file server for shared engineering and business data

Check share access, mass-change indicators, staged archives, permissions, and restore-point integrity.

APP01 / SQL01

Application tier

Windows application server with SQL database dependency

Contain credentials separately; validate application behavior, database access, and transaction integrity.

SPLUNK-01

Detection

Splunk SIEM receiving identity, endpoint, server, and network telemetry

Record source health, query window, query owner, evidence export location, and retention limits.

BAK-REPO-01

Recovery

Datto BCDR protection with cloud recovery copies

Protect the backup plane, preserve retention changes, and restore only from a trusted isolated recovery point.

ENDPOINTS

Workstations

Windows laptops and desktops

Isolate affected endpoints, preserve host context, collect Defender/Windows evidence, and reimage when required.

The CUI engineering enclave is the primary boundary for this exercise. Classified operations remain a separate accredited system and are excluded from these response decisions.

03 / roles and provider handoffs

Providers execute tasks; the organization owns the decision

The third-party SOC and third-party IT company are intentionally separate. The SOC provides monitoring and investigation. IT provides infrastructure execution and recovery. The internal security/GRC lead owns incident command, CUI-impact decisions, communications, and corrective actions.

roleresponsibility

Internal security / GRC lead

Declares and leads the incident, assesses CUI impact, sets communications cadence, owns evidence quality, and assigns corrective actions.

Third-party SOC company

Monitors, triages, investigates in Splunk, preserves telemetry, tunes detections, escalates, and hands off with timestamps and queries.

Third-party IT company

Executes approved FortiGate, Entra, Windows, server, and Datto actions; records technical changes and supports recovery.

Leadership / service owners

Accept business risk, prioritize recovery, approve customer/contract decisions, and authorize return to service.

minimum handoff case ID · UTC timestamps · affected asset/account · confidence · query/action performed · evidence location · next decision owner

04 / master response lifecycle

A common clock keeps the response usable under pressure

  1. 01
    Detect and open

    Open one case, capture the initial signal, assign an incident lead, preserve the time window, and record unknowns.

  2. 02
    Classify and scope

    Identify affected users, endpoints, servers, network paths, providers, data types, and possible CUI exposure.

  3. 03
    Contain deliberately

    Choose identity, endpoint, network, server, or backup-plane containment with an owner, expected impact, rollback condition, and timestamp.

  4. 04
    Eradicate and validate

    Remove persistence, rotate exposed secrets, close the entry path, verify telemetry, and confirm that the threat is no longer active.

  5. 05
    Recover from trusted state

    Restore in an isolated network, validate identity and application dependencies, confirm data integrity, and document RTO/RPO.

  6. 06
    Communicate and close

    Provide scheduled leadership updates, coordinate customer/contract decisions through authorized owners, and close only after actions are assigned.

05 / playbook catalog

Five playbooks cover the highest-consequence paths

IR-01 / PLAYBOOKEnclave ransomware + suspected CUI exfiltration

Trigger: Mass file changes, ransom note, archive staging, or suspicious transfer from FS01/engineering endpoints.

First move: Isolate endpoints; protect identity and backup planes; preserve evidence; assess CUI impact before broad restore.

IR-02 / PLAYBOOKEntra identity or privileged-account compromise

Trigger: Risky sign-in, MFA abuse, token/session anomaly, unexpected role assignment, or admin activity outside change windows.

First move: Restrict identity, revoke sessions, scope downstream access, and verify persistence/new privileged principals.

IR-03 / PLAYBOOKWindows workstation compromise

Trigger: Defender alert, suspicious PowerShell, persistence, credential theft, or lateral movement from a laptop/desktop.

First move: Network-isolate, preserve host context, scope adjacent systems, then remediate or reimage from a trusted baseline.

IR-04 / PLAYBOOKBackup-plane compromise

Trigger: Datto retention change, protected-device deletion, unusual console access, or failed jobs during an incident.

First move: Protect Datto administration, preserve console evidence, validate recovery points, and restore only in isolation.

IR-05 / PLAYBOOKPhishing / BEC

Trigger: Mailbox rule, credential phishing, payment fraud, supplier impersonation, or suspicious forwarding.

First move: Contain identity/mailbox persistence, validate requests out of band, and check for CUI access or forwarding.

06 / detection and evidence

Telemetry is part of the response product

The SOC must preserve enough context for the organization to explain what happened, what was affected, what was contained, and why recovery was trusted. Missing source coverage is recorded as a response limitation and a corrective action—not silently treated as “no evidence.”

sourceevidence to preserveowner

Identity

Entra sign-in/audit logs, risky sign-ins, privileged-role changes, MFA and session state

SOC / security lead

Perimeter

FortiGate traffic, VPN, admin, policy, and configuration-change logs

IT provider / SOC

Windows

Defender alerts, Security logs, PowerShell, tasks, services, autoruns, and endpoint timeline

SOC / IT provider

File activity

FS01 share access, mass-change indicators, staged archives, permissions, and shadow-copy status

IT provider

Application / SQL

APP01 application logs, SQL01 authentication, query, job, and integrity indicators

Application owner / IT provider

Backups

Datto job history, retention changes, protected-device status, recovery points, and restore logs

IT provider / security lead

07 / case records and communications

The program produces records that can survive handoffs

case headerCase ID · severity · lead · opened UTC

Record affected account/assets, source signal, current confidence, business owner, and next update time.

decision logDecision · owner · evidence · timestamp

Capture containment, recovery, notification, and risk-acceptance decisions with the assumption being made.

evidence logItem · collector · hash/location · time window

Preserve query names, export locations, source systems, collection times, and chain-of-custody notes.

closure recordRoot cause · scope · actions · retest

Close only after eradication, recovery validation, communications, lessons learned, and POA&M linkage are complete.

communicationpurposeminimum content

Leadership update

Decision support

Known impact, unknowns, containment, business effect, current risk, next decision, and next update time.

Provider handoff

Execution clarity

Case ID, action requested, affected asset/account, evidence location, approval, rollback, and completion criteria.

Customer/contract review

Authorized external decision

Facts only, CUI/classification assessment status, contract owner, approval path, and unresolved questions.

Closure summary

Accountability

Timeline, root cause, affected scope, recovery result, residual risk, corrective actions, and retest owner/date.

08 / tabletop exercise

A realistic inject tests the seams between teams

The exercise starts with an Entra alert and ends with an isolated Datto recovery. It crosses the SOC, IT provider, security/GRC lead, leadership, and business owners so it tests coordination—not just whether one person knows a command.

injectscenariodecision to test

01 / detect

SOC receives an Entra risky-sign-in alert for a user who recently accessed engineering shares.

Who opens the case, what severity is declared, and what evidence is preserved before account action?

02 / scope

The user’s Windows laptop shows PowerShell activity and an archive staged for transfer.

How do SOC and IT isolate the endpoint while security assesses possible CUI exposure?

03 / contain

FS01 begins rapid file modifications; APP01 and SQL01 remain available.

Which systems are isolated, who approves the boundary change, and how is continuity weighed?

04 / recover

A Datto retention policy was modified shortly before the file changes were detected.

How is the backup plane protected, and what makes a recovery point trusted?

05 / communicate

Leadership asks about customer notification, contract review, and law-enforcement coordination.

What is known, what is unknown, who approves external communication, and when is the next update?

06 / improve

The enclave is restored in isolation and a telemetry gap is found.

Which actions become POA&M updates, detections, provider-SLA changes, or training tasks?

outputDecision log + action register

Who decided what, when, with which evidence, and what assumption remained open.

successContainment and recovery decisions are timely

Participants identify the boundary, protect the backup plane, and choose a trusted restore path.

follow-throughCorrective actions map to POA&M

Every gap becomes an owner, due date, evidence requirement, and retest condition.

scorecardCoordination is measurable

Score time to declare, time to isolate, evidence quality, provider handoff quality, and recovery confidence.

09 / recovery and validation

Recovery is not complete until the service and evidence agree

gate 01 / trustProtect the recovery plane

Secure Datto administration, preserve policy changes, validate recovery points, and use an isolated restore network.

gate 02 / integrityValidate the service chain

Check AD-DC01 identity dependency, FS01 data integrity, APP01 behavior, and SQL01 authentication and transactions.

gate 03 / securityRe-establish monitoring

Confirm Entra, FortiGate, Windows, server, and Splunk visibility before reconnecting systems.

gate 04 / businessApprove return to service

Leadership and the service owner accept recovery results, customer impact, residual risk, and remaining actions.

10 / embedded artifact index

The supporting files are represented inside the page

The source package is translated into readable web sections rather than hidden behind download links. This index makes the relationship explicit and gives each artifact a visible home in the case study.

source artifactweb sectionembedded content

incident-response-plan.md

Master plan

Scope, severity, roles, provider handoffs, evidence, containment, eradication, recovery, closure, metrics.

architecture-and-assumptions.md

Architecture

Trust boundaries, asset identifiers, system dependencies, assumptions, and the CUI boundary.

playbooks/01–05

Five playbooks

Enclave ransomware/CUI exfiltration, Entra compromise, Windows compromise, backup compromise, and phishing/BEC.

provider-raci-and-sla.md

Provider operating model

Separate third-party IT and SOC responsibilities, escalation, evidence requirements, and no-unilateral-closure rule.

splunk-detection-catalog.md

Detection catalog

Identity, endpoint, FortiGate, Windows, file activity, and backup-plane detection priorities.

datto-bcdr-recovery-runbook.md

Recovery runbook

Backup-plane protection, trusted restore-point selection, isolated restoration, validation, and return-to-service gates.

incident-case-forms.md

Case records

Minimum incident record, evidence log, decision log, containment record, recovery record, and closure checklist.

communications-templates.md

Communications

Leadership update, provider handoff, internal notice, customer/contract decision, and closure language.

tabletop-exercise.md

Tabletop

Entra alert → Windows compromise → CUI staging → FS01 ransomware → Datto recovery → after-action review.

grc-ir-crosswalk.md

GRC linkage

F-001 through F-006 mapped to operational response controls, POA&M closure, and retest evidence.

methodology-and-csf-profile.md

Method

Synthetic scope, NIST SP 800-171 Rev. 3 / CSF 2.0 relationship, limitations, and measurement model.

11 / GRC-to-IR crosswalk

Every major finding has an operational response hook

Read the assessment first, then follow the findings into response design, exercise evidence, and POA&M closure.

GRC findingIR control pointhow the work connects

F-001 / boundary and assets

IR-01 / IR-03

The boundary map and asset register define the identities, endpoints, servers, controls, and providers to search and contain.

F-002 / privileged access

IR-02 / IR-04

Entra roles, FortiGate administration, Datto console access, and provider access are explicit containment decisions.

F-003 / telemetry

IR-01 / IR-03

Splunk source health and Windows/FortiGate/Entra coverage are part of triage; gaps are recorded as response limitations.

F-004 / CUI transfer

IR-01 / IR-05

Archive staging, forwarding, removable media, and supplier exchange paths are investigated as possible CUI movement.

F-005 / recovery evidence

IR-04

Datto recovery-point integrity, isolated restoration, RTO/RPO results, and corrective actions close the recovery gap.

F-006 / response and suppliers

IR-01 through IR-05

The plan, provider model, tabletop, and after-action workflow turn the finding into an operating capability.

Continue from the assessment

Return to the Asterion NIST readiness assessment ↗ to start with the scope, exact maturity values, six findings, risk register, evidence register, and POA&M.