Use when building a structured ransomware incident response playbook
Scanned 9/8/2026
Install to Claude Code
npx -y skills add oyi77/1ai-skills --skill building-ransomware-playbook-with-cisa-framework --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Building Ransomware Playbook With Cisa Framework?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/oyi77-building-ransomware-playbook-with-cisa-framework)More formats (shields.io, HTML) on the badges page.
---
name: building-ransomware-playbook-with-cisa-framework
description: Use when building a structured ransomware incident response playbook
aligned with the CISA StopRansomware Guide and NIST Cybersecurity Framework. Covers
preparation, detection, containment, eradication, recovery, and post-incident phases
with actionable checklists. Activates for requests involving ransomware response
planning, CISA compliance, incident response playbook creation, or ransomware preparedness
assessment.
domain: cybersecurity
tags:
- ransomware
- incident-response
- CISA
- playbook
- compliance
- NIST
subdomain: ransomware-defense
version: 1.0.0
author: oyi77
license: Apache-2.0
nist_csf:
- PR.DS-11
- RS.MA-01
- RC.RP-01
- PR.IR-01
category: cybersecurity
---
# Building Ransomware Playbook With Cisa Framework
## Overview
Cybersecurity skill for building ransomware playbook with cisa framework. Follows industry best practices and security standards.
## When to Use
**Trigger phrases:**
- "building ransomware playbook with cisa framework"
- "Builds a structured ransomware incident response playbook aligned with the CISA "
- An organization needs to create or update its ransomware incident response playbook following CISA guidelines
- A security team is conducting a ransomware readiness assessment against the CISA StopRansomware framework
- Compliance requires documenting ransomware response procedures aligned with NIST CSF and CISA recommendations
- During tabletop exercises to validate that the organization's ransomware response steps match industry best practices
- After a ransomware incident to update the playbook with lessons learned and close identified gaps
**Do not use** as a substitute for legal counsel regarding ransom payment decisions, breach notification timelines, or regulatory obligations specific to your jurisdiction.
## When NOT to Use
- When you lack proper authorization for testing
- For production systems without change management
- When the task requires legal or compliance expertise beyond technical scope
## Prerequisites
- Familiarity with the CISA StopRansomware Guide (cisa.gov/stopransomware/ransomware-guide)
- NIST Cybersecurity Framework (CSF) understanding (Identify, Protect, Detect, Respond, Recover)
- Inventory of critical assets, backup infrastructure, and communication channels
- Defined roles and responsibilities for incident response team members
- Python 3.8+ for playbook generation and compliance checking automation
- Access to organization's asset inventory and backup configuration documentation
## Workflow
```python
# Example: IOC detection
import re
IOC_PATTERNS = {
"ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",
"domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",
"hash_md5": r"\b[a-f0-9]{32}\b",
"hash_sha256": r"\b[a-f0-9]{64}\b",
}
def extract_iocs(text: str) -> dict:
return {k: re.findall(v, text) for k, v in IOC_PATTERNS.items()}
```
1. **Assess Requirements** — Evaluate current environment and define ransomware playbook implementation requirements.
2. **Design Architecture** — Plan the ransomware playbook architecture, including components, integrations, and data flows.
3. **Configure Components** — Set up cisa framework for ransomware playbook according to vendor best practices and security guidelines.
4. **Test Integration** — Validate that all components work together. Run functional and security tests.
5. **Deploy to Production** — Roll out the implementation with monitoring and rollback capabilities.
6. **Validate and Document** — Verify the implementation meets requirements. Document configuration and runbooks.
## Tools
- **cisa framework** — Primary tool for this skill
- **Configuration Management** — Infrastructure as code and automation
- **Monitoring Stack** — Observability and alerting
- **Documentation Platform** — Runbooks and architecture docs
## Process
1. **Design** — Define interface, identify patterns, plan implementation
1. **Implement** — Write code following existing conventions, add tests
1. **Verify** — Run tests, check integration, validate behavior
## Verification
- [ ] All ransomware playbook procedures executed completely and documented
- [ ] Findings validated against multiple data sources
- [ ] False positives identified and filtered
- [ ] Results documented with evidence and timestamps
- [ ] Recommendations provided with risk-based prioritization
## Anti-Rationalization Table
| Rationalization | Reality |
|---|---|
| "We are too small to be targeted" | Automated attacks target everyone. Size does not matter. |
| "Security slows us down" | A breach slows you down 100x more. Build security in from the start. |
| "We will fix it after launch" | Vulnerabilities in production are exploited within hours. Fix before deploy. |Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!