Files
Anthropic-Cybersecurity-Skills/skills/performing-ransomware-tabletop-exercise/references/standards.md
T

2.2 KiB

Standards & References - Ransomware Tabletop Exercise

Exercise Standards

FEMA HSEEP (Homeland Security Exercise and Evaluation Program)

NIST SP 800-84: Guide to Test, Training, and Exercise Programs

  • Framework for developing IT plan test and exercise programs
  • Section 4.3: Tabletop exercises for incident response testing
  • Covers exercise scoping, objectives, scenario development, and evaluation

CISA Tabletop Exercise Packages (CTEPs)

Ransomware-Specific Guidance

CISA #StopRansomware Guide

  • Ransomware response checklist that exercises should validate
  • Decision tree for ransom payment considerations
  • Recovery priority guidance

NIST IR 8374: Ransomware Risk Management

  • Identifies exercise testing as a key control in the Recover function
  • Recommends annual tabletop exercises with escalating complexity

FBI/CISA Joint Advisories

  • AA24-131A: Black Basta Ransomware
  • AA23-136A: BianLian Ransomware Group
  • AA23-158A: CL0P Ransomware Gang Exploiting MOVEit
  • Use these as source material for realistic exercise scenarios

Regulatory Notification Requirements (for Scenario Design)

Regulation Notification Timeline Authority
GDPR (EU) 72 hours Supervisory Authority
HIPAA (US Healthcare) 60 days (individuals), ASAP (HHS if >500) HHS OCR
SEC (US Public Companies) 4 business days (Form 8-K) SEC
PCI DSS 72 hours Card brands/acquiring bank
NY DFS (23 NYCRR 500) 72 hours NY DFS
CCPA (California) "Expedient time" California AG
NIS2 (EU) 24 hours (early warning), 72 hours (full) National CSIRT