Skip to content

ChainShield — Logic App playbook: chainshield-supplier-response #143

Description

@TFT444

Overview

Create a Logic App playbook ARM template that triggers on ChainShield supplier compromise alerts. Handles supplier account suspension, procurement team notification, and incident logging.

Playbook steps

  1. Triage — classify incident type (account compromise / logistics diversion / data exfiltration)
  2. Enrich — look up supplier in Watchlist (contract value, contact, risk tier)
  3. Contain — flag supplier account for review in Azure AD (conditional access block)
  4. Notify — alert Procurement Director and Security team via Teams with supplier details
  5. Log — update Sentinel incident with enrichment, assign to ChainShield analyst queue
  6. Escalate — if value > £10k, auto-page on-call SOC analyst

Acceptance criteria

  • File: playbooks/chainshield-supplier-response/azuredeploy.json
  • Valid ARM JSON
  • Sentinel incident trigger
  • README in playbook folder
  • No hardcoded credentials

Part of

Epic #117 — Phase 2 ChainShield

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions