Skip to content

ChainShield — Logic App playbook: chainshield-supplier-response #143

Description

@TFT444

Overview

Create a Logic App playbook ARM template that triggers on ChainShield supplier compromise alerts. Handles supplier account suspension, procurement team notification, and incident logging.

Playbook steps

  1. Triage — classify incident type (account compromise / logistics diversion / data exfiltration)
  2. Enrich — look up supplier in Watchlist (contract value, contact, risk tier)
  3. Contain — flag supplier account for review in Azure AD (conditional access block)
  4. Notify — alert Procurement Director and Security team via Teams with supplier details
  5. Log — update Sentinel incident with enrichment, assign to ChainShield analyst queue
  6. Escalate — if value > £10k, auto-page on-call SOC analyst

Acceptance criteria

  • File: playbooks/chainshield-supplier-response/azuredeploy.json
  • Valid ARM JSON
  • Sentinel incident trigger
  • README in playbook folder
  • No hardcoded credentials

Part of

Epic #117 — Phase 2 ChainShield

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions