- Supervisore autonomo ticket: prompt operativo + dry-run (scripts/), DRAFT rimosso; gate normativo gia' committato - docs/CONTEXT_LAST_SESSION.md: sessione 2026-06-14 (supervisore LIVE, run#1/#2, rotazione Anthropic rinviata) - docs/sql/039_integrity_keys.sql: migrazione integrita' DB (PK/UNIQUE/FK) gia' applicata in prod 12/6 - docs/MIGRATION_UI_V2.md: piano migrazione UI V2 - docs/nis2/incidente_r00/: 2 mockup incidente (gateway+dashboard) - .gitignore: versiona public/vendor/ (asset Bootstrap Italia self-hosted) - Fix accumulati: EmailService (kill-switch email), Incident/Onboarding/Organization/Services controllers, questionnaire, ReportService, CLAUDE.md standard Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
5257 lines
297 KiB
HTML
5257 lines
297 KiB
HTML
<!DOCTYPE html>
|
||
<html lang="it">
|
||
<head>
|
||
<meta charset="UTF-8">
|
||
<meta name="viewport" content="width=device-width, initial-scale=1.0">
|
||
<title>Gestione Incidenti - NIS2 Management System</title>
|
||
<style>
|
||
:root {
|
||
--bg-primary: #0d1117;
|
||
--bg-secondary: #161b22;
|
||
--bg-tertiary: #1c2128;
|
||
--border-color: #30363d;
|
||
--text-primary: #c9d1d9;
|
||
--text-secondary: #8b949e;
|
||
--accent-primary: #58a6ff;
|
||
--accent-secondary: #1f6feb;
|
||
--success: #3fb950;
|
||
--warning: #d29922;
|
||
--danger: #f85149;
|
||
--essential-bg: #fef3c7;
|
||
--essential-text: #92400e;
|
||
--essential-border: #f59e0b;
|
||
}
|
||
|
||
* {
|
||
margin: 0;
|
||
padding: 0;
|
||
box-sizing: border-box;
|
||
}
|
||
|
||
body {
|
||
font-family: -apple-system, BlinkMacSystemFont, 'Segoe UI', 'Noto Sans', Helvetica, Arial, sans-serif;
|
||
background-color: var(--bg-primary);
|
||
color: var(--text-primary);
|
||
line-height: 1.6;
|
||
overflow-y: auto;
|
||
overflow-x: hidden;
|
||
}
|
||
|
||
.container {
|
||
max-width: 1800px;
|
||
margin: 0 auto;
|
||
padding: 20px;
|
||
}
|
||
|
||
/* Header */
|
||
.header {
|
||
background-color: var(--bg-secondary);
|
||
border-bottom: 1px solid var(--border-color);
|
||
padding: 24px 0;
|
||
margin-bottom: 32px;
|
||
position: sticky;
|
||
top: 0;
|
||
z-index: 100;
|
||
}
|
||
|
||
.header-content {
|
||
max-width: 1800px;
|
||
margin: 0 auto;
|
||
padding: 0 20px;
|
||
display: flex;
|
||
justify-content: space-between;
|
||
align-items: center;
|
||
}
|
||
|
||
.header h1 {
|
||
font-size: 24px;
|
||
font-weight: 600;
|
||
color: var(--text-primary);
|
||
}
|
||
|
||
.breadcrumb {
|
||
font-size: 13px;
|
||
color: var(--text-secondary);
|
||
margin-top: 4px;
|
||
}
|
||
|
||
.breadcrumb a {
|
||
color: var(--accent-primary);
|
||
text-decoration: none;
|
||
}
|
||
|
||
.breadcrumb a:hover {
|
||
text-decoration: underline;
|
||
}
|
||
|
||
.subject-type-badge {
|
||
display: inline-flex;
|
||
align-items: center;
|
||
gap: 8px;
|
||
padding: 8px 16px;
|
||
border-radius: 6px;
|
||
font-size: 13px;
|
||
font-weight: 600;
|
||
}
|
||
|
||
.badge-important {
|
||
background-color: rgba(88, 166, 255, 0.2);
|
||
color: var(--accent-primary);
|
||
border: 1px solid var(--accent-primary);
|
||
}
|
||
|
||
.badge-essential {
|
||
background-color: var(--essential-bg);
|
||
color: var(--essential-text);
|
||
border: 1px solid var(--essential-border);
|
||
}
|
||
|
||
/* Stats Grid */
|
||
.stats-row {
|
||
display: grid;
|
||
grid-template-columns: repeat(auto-fit, minmax(200px, 1fr));
|
||
gap: 16px;
|
||
margin-bottom: 24px;
|
||
}
|
||
|
||
.stat-card {
|
||
background-color: var(--bg-secondary);
|
||
border: 1px solid var(--border-color);
|
||
border-radius: 6px;
|
||
padding: 20px;
|
||
}
|
||
|
||
.stat-label {
|
||
font-size: 12px;
|
||
color: var(--text-secondary);
|
||
text-transform: uppercase;
|
||
letter-spacing: 0.5px;
|
||
margin-bottom: 8px;
|
||
}
|
||
|
||
.stat-value {
|
||
font-size: 28px;
|
||
font-weight: 700;
|
||
color: var(--text-primary);
|
||
}
|
||
|
||
.stat-change {
|
||
font-size: 12px;
|
||
margin-top: 4px;
|
||
}
|
||
|
||
.stat-change.positive {
|
||
color: var(--success);
|
||
}
|
||
|
||
.stat-change.negative {
|
||
color: var(--danger);
|
||
}
|
||
|
||
.stat-change.warning {
|
||
color: var(--warning);
|
||
}
|
||
|
||
/* Tabs */
|
||
.tabs {
|
||
display: flex;
|
||
gap: 8px;
|
||
margin-bottom: 24px;
|
||
border-bottom: 1px solid var(--border-color);
|
||
padding-bottom: 0;
|
||
flex-wrap: wrap;
|
||
}
|
||
|
||
.tab {
|
||
padding: 12px 16px;
|
||
background: transparent;
|
||
border: none;
|
||
color: var(--text-secondary);
|
||
cursor: pointer;
|
||
font-size: 14px;
|
||
font-weight: 500;
|
||
border-bottom: 2px solid transparent;
|
||
transition: all 0.2s;
|
||
}
|
||
|
||
.tab:hover {
|
||
color: var(--text-primary);
|
||
background-color: var(--bg-tertiary);
|
||
}
|
||
|
||
.tab.active {
|
||
color: var(--accent-primary);
|
||
border-bottom-color: var(--accent-primary);
|
||
}
|
||
|
||
/* Section */
|
||
.section {
|
||
background-color: var(--bg-secondary);
|
||
border: 1px solid var(--border-color);
|
||
border-radius: 6px;
|
||
padding: 24px;
|
||
margin-bottom: 24px;
|
||
display: none;
|
||
}
|
||
|
||
.section.active {
|
||
display: block;
|
||
}
|
||
|
||
.section-header {
|
||
display: flex;
|
||
justify-content: space-between;
|
||
align-items: center;
|
||
margin-bottom: 24px;
|
||
padding-bottom: 16px;
|
||
border-bottom: 1px solid var(--border-color);
|
||
}
|
||
|
||
.section-title {
|
||
font-size: 18px;
|
||
font-weight: 600;
|
||
color: var(--text-primary);
|
||
display: flex;
|
||
align-items: center;
|
||
gap: 8px;
|
||
}
|
||
|
||
.section-actions {
|
||
display: flex;
|
||
gap: 8px;
|
||
}
|
||
|
||
.btn {
|
||
padding: 8px 16px;
|
||
background-color: var(--bg-tertiary);
|
||
border: 1px solid var(--border-color);
|
||
border-radius: 6px;
|
||
color: var(--text-primary);
|
||
font-size: 13px;
|
||
font-weight: 500;
|
||
cursor: pointer;
|
||
transition: all 0.2s;
|
||
}
|
||
|
||
.btn:hover {
|
||
background-color: var(--bg-tertiary);
|
||
border-color: var(--accent-primary);
|
||
}
|
||
|
||
.btn-primary {
|
||
background-color: var(--accent-secondary);
|
||
border-color: var(--accent-primary);
|
||
color: var(--text-primary);
|
||
}
|
||
|
||
.btn-primary:hover {
|
||
background-color: var(--accent-primary);
|
||
}
|
||
|
||
.btn-danger {
|
||
background-color: rgba(248, 81, 73, 0.2);
|
||
border-color: var(--danger);
|
||
color: var(--danger);
|
||
}
|
||
|
||
.btn-danger:hover {
|
||
background-color: var(--danger);
|
||
color: var(--text-primary);
|
||
}
|
||
|
||
.btn-interactive {
|
||
color: #a78bfa;
|
||
font-weight: 600;
|
||
}
|
||
|
||
.btn-interactive:hover {
|
||
color: #c4b5fd;
|
||
background-color: rgba(167, 139, 250, 0.1);
|
||
border-color: #a78bfa;
|
||
}
|
||
|
||
/* Help Icon */
|
||
.help-icon {
|
||
display: inline-flex;
|
||
align-items: center;
|
||
justify-content: center;
|
||
width: 22px;
|
||
height: 22px;
|
||
background-color: rgba(167, 139, 250, 0.2);
|
||
border: 2px solid #a78bfa;
|
||
border-radius: 50%;
|
||
font-size: 13px;
|
||
font-weight: 700;
|
||
color: #a78bfa;
|
||
cursor: help;
|
||
position: relative;
|
||
margin-left: 6px;
|
||
}
|
||
|
||
.help-icon:hover {
|
||
background-color: rgba(167, 139, 250, 0.3);
|
||
color: #c4b5fd;
|
||
border-color: #c4b5fd;
|
||
transform: scale(1.1);
|
||
}
|
||
|
||
.tooltip {
|
||
visibility: hidden;
|
||
position: absolute;
|
||
z-index: 1000;
|
||
background-color: var(--bg-tertiary);
|
||
color: var(--text-primary);
|
||
padding: 12px;
|
||
border-radius: 6px;
|
||
border: 1px solid var(--border-color);
|
||
box-shadow: 0 8px 24px rgba(0, 0, 0, 0.5);
|
||
width: 320px;
|
||
top: 28px;
|
||
left: 50%;
|
||
transform: translateX(-50%);
|
||
font-size: 12px;
|
||
line-height: 1.5;
|
||
opacity: 0;
|
||
transition: opacity 0.2s;
|
||
white-space: normal;
|
||
}
|
||
|
||
.tooltip::before {
|
||
content: '';
|
||
position: absolute;
|
||
top: -6px;
|
||
left: 50%;
|
||
transform: translateX(-50%);
|
||
border-left: 6px solid transparent;
|
||
border-right: 6px solid transparent;
|
||
border-bottom: 6px solid var(--border-color);
|
||
}
|
||
|
||
.tooltip-title {
|
||
color: var(--accent-primary);
|
||
font-weight: 600;
|
||
margin-bottom: 8px;
|
||
font-size: 11px;
|
||
text-transform: uppercase;
|
||
letter-spacing: 0.5px;
|
||
}
|
||
|
||
.help-icon:hover .tooltip {
|
||
visibility: visible;
|
||
opacity: 1;
|
||
}
|
||
|
||
/* Info Box */
|
||
.info-box {
|
||
background-color: var(--bg-tertiary);
|
||
border: 1px solid var(--border-color);
|
||
border-left: 3px solid var(--accent-primary);
|
||
padding: 16px;
|
||
border-radius: 6px;
|
||
margin-bottom: 16px;
|
||
}
|
||
|
||
.info-box-title {
|
||
font-weight: 600;
|
||
color: var(--accent-primary);
|
||
margin-bottom: 8px;
|
||
font-size: 14px;
|
||
}
|
||
|
||
.info-box-content {
|
||
font-size: 13px;
|
||
color: var(--text-secondary);
|
||
line-height: 1.6;
|
||
}
|
||
|
||
.warning-box {
|
||
border-left-color: var(--warning);
|
||
}
|
||
|
||
.warning-box .info-box-title {
|
||
color: var(--warning);
|
||
}
|
||
|
||
.danger-box {
|
||
border-left-color: var(--danger);
|
||
}
|
||
|
||
.danger-box .info-box-title {
|
||
color: var(--danger);
|
||
}
|
||
|
||
/* Essential Badge */
|
||
.essential-badge {
|
||
display: inline-block;
|
||
background-color: var(--essential-bg);
|
||
color: var(--essential-text);
|
||
padding: 4px 8px;
|
||
border-radius: 3px;
|
||
font-size: 10px;
|
||
font-weight: 700;
|
||
text-transform: uppercase;
|
||
letter-spacing: 0.5px;
|
||
border: 1px solid var(--essential-border);
|
||
margin-left: 8px;
|
||
transform: rotate(-1deg);
|
||
box-shadow: 0 2px 4px rgba(0, 0, 0, 0.3);
|
||
}
|
||
|
||
/* Classification Grid */
|
||
.classification-grid {
|
||
display: grid;
|
||
grid-template-columns: repeat(auto-fit, minmax(300px, 1fr));
|
||
gap: 16px;
|
||
margin-top: 16px;
|
||
}
|
||
|
||
.classification-card {
|
||
background-color: var(--bg-tertiary);
|
||
border: 1px solid var(--border-color);
|
||
border-left: 4px solid var(--danger);
|
||
border-radius: 6px;
|
||
padding: 20px;
|
||
transition: all 0.2s;
|
||
}
|
||
|
||
.classification-card:hover {
|
||
transform: translateX(4px);
|
||
border-left-color: var(--accent-primary);
|
||
}
|
||
|
||
.classification-header {
|
||
display: flex;
|
||
justify-content: space-between;
|
||
align-items: flex-start;
|
||
margin-bottom: 12px;
|
||
}
|
||
|
||
.classification-code {
|
||
font-size: 16px;
|
||
font-weight: 700;
|
||
color: var(--danger);
|
||
font-family: 'Courier New', monospace;
|
||
}
|
||
|
||
.classification-severity {
|
||
padding: 4px 8px;
|
||
border-radius: 3px;
|
||
font-size: 11px;
|
||
font-weight: 600;
|
||
text-transform: uppercase;
|
||
}
|
||
|
||
.severity-critical {
|
||
background-color: rgba(248, 81, 73, 0.2);
|
||
color: var(--danger);
|
||
border: 1px solid var(--danger);
|
||
}
|
||
|
||
.classification-title {
|
||
font-size: 15px;
|
||
font-weight: 600;
|
||
color: var(--text-primary);
|
||
margin-bottom: 8px;
|
||
}
|
||
|
||
.classification-description {
|
||
font-size: 13px;
|
||
color: var(--text-secondary);
|
||
line-height: 1.5;
|
||
margin-bottom: 12px;
|
||
}
|
||
|
||
.classification-examples {
|
||
font-size: 12px;
|
||
color: var(--text-secondary);
|
||
padding-left: 16px;
|
||
border-left: 2px solid var(--border-color);
|
||
}
|
||
|
||
.classification-examples strong {
|
||
color: var(--accent-primary);
|
||
}
|
||
|
||
/* Process Flow */
|
||
.process-flow {
|
||
display: flex;
|
||
flex-direction: column;
|
||
gap: 16px;
|
||
margin-top: 16px;
|
||
}
|
||
|
||
.process-step {
|
||
background-color: var(--bg-tertiary);
|
||
border: 1px solid var(--border-color);
|
||
border-radius: 6px;
|
||
padding: 20px;
|
||
position: relative;
|
||
}
|
||
|
||
.process-step::before {
|
||
content: '';
|
||
position: absolute;
|
||
left: 20px;
|
||
top: -16px;
|
||
width: 2px;
|
||
height: 16px;
|
||
background-color: var(--accent-primary);
|
||
}
|
||
|
||
.process-step:first-child::before {
|
||
display: none;
|
||
}
|
||
|
||
.process-header {
|
||
display: flex;
|
||
justify-content: space-between;
|
||
align-items: center;
|
||
margin-bottom: 16px;
|
||
}
|
||
|
||
.process-number {
|
||
width: 40px;
|
||
height: 40px;
|
||
background-color: var(--accent-secondary);
|
||
border: 2px solid var(--accent-primary);
|
||
border-radius: 50%;
|
||
display: flex;
|
||
align-items: center;
|
||
justify-content: center;
|
||
font-size: 18px;
|
||
font-weight: 700;
|
||
color: var(--text-primary);
|
||
}
|
||
|
||
.process-title {
|
||
flex: 1;
|
||
margin-left: 16px;
|
||
font-size: 16px;
|
||
font-weight: 600;
|
||
color: var(--text-primary);
|
||
}
|
||
|
||
.process-content {
|
||
font-size: 13px;
|
||
color: var(--text-secondary);
|
||
line-height: 1.6;
|
||
margin-bottom: 12px;
|
||
}
|
||
|
||
.process-details {
|
||
background-color: var(--bg-secondary);
|
||
border: 1px solid var(--border-color);
|
||
border-radius: 4px;
|
||
padding: 12px;
|
||
font-size: 12px;
|
||
}
|
||
|
||
.process-details ul {
|
||
margin-left: 20px;
|
||
margin-top: 8px;
|
||
}
|
||
|
||
.process-details li {
|
||
margin-bottom: 6px;
|
||
color: var(--text-secondary);
|
||
}
|
||
|
||
/* Timeline */
|
||
.timeline {
|
||
display: grid;
|
||
grid-template-columns: repeat(auto-fit, minmax(200px, 1fr));
|
||
gap: 16px;
|
||
margin-top: 16px;
|
||
}
|
||
|
||
.timeline-item {
|
||
background-color: var(--bg-tertiary);
|
||
border: 1px solid var(--border-color);
|
||
border-radius: 6px;
|
||
padding: 16px;
|
||
text-align: center;
|
||
}
|
||
|
||
.timeline-time {
|
||
font-size: 24px;
|
||
font-weight: 700;
|
||
color: var(--danger);
|
||
margin-bottom: 8px;
|
||
}
|
||
|
||
.timeline-label {
|
||
font-size: 12px;
|
||
color: var(--text-secondary);
|
||
text-transform: uppercase;
|
||
letter-spacing: 0.5px;
|
||
margin-bottom: 8px;
|
||
}
|
||
|
||
.timeline-description {
|
||
font-size: 13px;
|
||
color: var(--text-primary);
|
||
line-height: 1.4;
|
||
}
|
||
|
||
/* Table */
|
||
.table-container {
|
||
overflow-x: auto;
|
||
margin-top: 16px;
|
||
}
|
||
|
||
table {
|
||
width: 100%;
|
||
border-collapse: collapse;
|
||
font-size: 13px;
|
||
}
|
||
|
||
th {
|
||
background-color: var(--bg-tertiary);
|
||
color: var(--text-secondary);
|
||
font-weight: 600;
|
||
text-align: left;
|
||
padding: 12px;
|
||
border: 1px solid var(--border-color);
|
||
text-transform: uppercase;
|
||
font-size: 11px;
|
||
letter-spacing: 0.5px;
|
||
}
|
||
|
||
td {
|
||
padding: 12px;
|
||
border: 1px solid var(--border-color);
|
||
color: var(--text-primary);
|
||
}
|
||
|
||
tr:hover {
|
||
background-color: var(--bg-tertiary);
|
||
}
|
||
|
||
/* Modal/Tooltip Output */
|
||
.output-modal {
|
||
display: none;
|
||
position: fixed;
|
||
z-index: 2000;
|
||
left: 0;
|
||
top: 0;
|
||
width: 100%;
|
||
height: 100%;
|
||
background-color: rgba(0, 0, 0, 0.8);
|
||
align-items: center;
|
||
justify-content: center;
|
||
}
|
||
|
||
.output-modal.active {
|
||
display: flex;
|
||
}
|
||
|
||
.output-content {
|
||
background-color: var(--bg-secondary);
|
||
border: 1px solid var(--border-color);
|
||
border-radius: 6px;
|
||
max-width: 800px;
|
||
max-height: 80vh;
|
||
overflow-y: auto;
|
||
padding: 32px;
|
||
position: relative;
|
||
}
|
||
|
||
.output-close {
|
||
position: absolute;
|
||
top: 16px;
|
||
right: 16px;
|
||
background: none;
|
||
border: none;
|
||
color: var(--text-secondary);
|
||
font-size: 24px;
|
||
cursor: pointer;
|
||
padding: 4px 8px;
|
||
}
|
||
|
||
.output-close:hover {
|
||
color: var(--text-primary);
|
||
}
|
||
|
||
.output-header {
|
||
margin-bottom: 24px;
|
||
padding-bottom: 16px;
|
||
border-bottom: 1px solid var(--border-color);
|
||
}
|
||
|
||
.output-title {
|
||
font-size: 20px;
|
||
font-weight: 600;
|
||
color: var(--text-primary);
|
||
margin-bottom: 8px;
|
||
}
|
||
|
||
.output-subtitle {
|
||
font-size: 13px;
|
||
color: var(--text-secondary);
|
||
}
|
||
|
||
.output-body {
|
||
font-size: 13px;
|
||
color: var(--text-primary);
|
||
line-height: 1.6;
|
||
}
|
||
|
||
.output-section {
|
||
margin-bottom: 20px;
|
||
}
|
||
|
||
.output-section-title {
|
||
font-size: 14px;
|
||
font-weight: 600;
|
||
color: var(--accent-primary);
|
||
margin-bottom: 12px;
|
||
text-transform: uppercase;
|
||
letter-spacing: 0.5px;
|
||
}
|
||
|
||
.output-field {
|
||
background-color: var(--bg-tertiary);
|
||
border: 1px solid var(--border-color);
|
||
border-radius: 4px;
|
||
padding: 12px;
|
||
margin-bottom: 12px;
|
||
}
|
||
|
||
.output-field-label {
|
||
font-size: 11px;
|
||
color: var(--text-secondary);
|
||
text-transform: uppercase;
|
||
letter-spacing: 0.5px;
|
||
margin-bottom: 6px;
|
||
}
|
||
|
||
.output-field-value {
|
||
font-size: 13px;
|
||
color: var(--text-primary);
|
||
}
|
||
|
||
.output-actions {
|
||
display: flex;
|
||
gap: 12px;
|
||
margin-top: 24px;
|
||
padding-top: 16px;
|
||
border-top: 1px solid var(--border-color);
|
||
}
|
||
|
||
/* Checklist */
|
||
.checklist {
|
||
margin-top: 16px;
|
||
}
|
||
|
||
.checklist-item {
|
||
background-color: var(--bg-tertiary);
|
||
border: 1px solid var(--border-color);
|
||
border-radius: 4px;
|
||
padding: 12px;
|
||
margin-bottom: 8px;
|
||
display: flex;
|
||
align-items: flex-start;
|
||
gap: 12px;
|
||
}
|
||
|
||
.checklist-checkbox {
|
||
width: 20px;
|
||
height: 20px;
|
||
border: 2px solid var(--border-color);
|
||
border-radius: 4px;
|
||
cursor: pointer;
|
||
flex-shrink: 0;
|
||
margin-top: 2px;
|
||
}
|
||
|
||
.checklist-checkbox:hover {
|
||
border-color: var(--accent-primary);
|
||
}
|
||
|
||
.checklist-text {
|
||
font-size: 13px;
|
||
color: var(--text-primary);
|
||
line-height: 1.5;
|
||
}
|
||
|
||
/* Responsive */
|
||
@media (max-width: 768px) {
|
||
.header-content {
|
||
flex-direction: column;
|
||
align-items: flex-start;
|
||
gap: 12px;
|
||
}
|
||
|
||
.tabs {
|
||
overflow-x: auto;
|
||
flex-wrap: nowrap;
|
||
}
|
||
|
||
.stats-row {
|
||
grid-template-columns: 1fr;
|
||
}
|
||
|
||
.classification-grid {
|
||
grid-template-columns: 1fr;
|
||
}
|
||
|
||
.timeline {
|
||
grid-template-columns: 1fr;
|
||
}
|
||
|
||
.output-content {
|
||
margin: 20px;
|
||
max-width: calc(100% - 40px);
|
||
}
|
||
}
|
||
</style>
|
||
</head>
|
||
<body>
|
||
<div class="header">
|
||
<div class="header-content">
|
||
<div>
|
||
<h1>Gestione Incidenti, Ripristino e Comunicazioni</h1>
|
||
<div class="breadcrumb">
|
||
<a href="dashboard.html">Dashboard</a> / Gestione Incidenti NIS2
|
||
</div>
|
||
</div>
|
||
<div class="section-actions">
|
||
<span class="subject-type-badge" id="subjectTypeBadge"></span>
|
||
<button class="btn btn-danger" onclick="reportIncident()">🚨 Segnala Incidente</button>
|
||
</div>
|
||
</div>
|
||
</div>
|
||
|
||
<div class="container">
|
||
<!-- Statistics -->
|
||
<div class="stats-row">
|
||
<div class="stat-card">
|
||
<div class="stat-label">Incidenti Attivi</div>
|
||
<div class="stat-value">3</div>
|
||
<div class="stat-change negative">2 critici in gestione</div>
|
||
</div>
|
||
<div class="stat-card">
|
||
<div class="stat-label">Incidenti Mese Corrente</div>
|
||
<div class="stat-value">12</div>
|
||
<div class="stat-change warning">+3 rispetto al mese scorso</div>
|
||
</div>
|
||
<div class="stat-card">
|
||
<div class="stat-label">Tempo Medio Risposta</div>
|
||
<div class="stat-value">2.4h</div>
|
||
<div class="stat-change positive">Target: <4h</div>
|
||
</div>
|
||
<div class="stat-card">
|
||
<div class="stat-label">Notifiche CSIRT</div>
|
||
<div class="stat-value">8</div>
|
||
<div class="stat-change positive">100% entro tempistiche</div>
|
||
</div>
|
||
<div class="stat-card">
|
||
<div class="stat-label">Tasso Risoluzione</div>
|
||
<div class="stat-value">94%</div>
|
||
<div class="stat-change positive">Entro SLA definiti</div>
|
||
</div>
|
||
<div class="stat-card">
|
||
<div class="stat-label">Conformità NIS2</div>
|
||
<div class="stat-value">98%</div>
|
||
<div class="stat-change positive">Requisiti coperti</div>
|
||
</div>
|
||
</div>
|
||
|
||
<!-- Info Box -->
|
||
<div class="info-box">
|
||
<div class="info-box-title">Requisiti NIS2 Coperti</div>
|
||
<div class="info-box-content">
|
||
<strong>RS.MA-01</strong> Gestione incidenti |
|
||
<strong>RS.CO-02</strong> Coordinamento risposta incidenti |
|
||
<strong>RC.RP-01</strong> Piano ripristino |
|
||
<strong>RC.CO-03</strong> Comunicazioni ripristino |
|
||
<strong>Art. 23 D.Lgs. 138/2024</strong> Notifica incidenti
|
||
</div>
|
||
</div>
|
||
|
||
<!-- Tabs -->
|
||
<div class="tabs">
|
||
<button class="tab active" onclick="showTab('classification')">Classificazione Incidenti</button>
|
||
<button class="tab" onclick="showTab('process')">Processo Gestione</button>
|
||
<button class="tab" onclick="showTab('notification')">Notifiche CSIRT</button>
|
||
<button class="tab" onclick="showTab('recovery')">Ripristino</button>
|
||
<button class="tab" onclick="showTab('communication')">Comunicazioni</button>
|
||
<button class="tab" onclick="showTab('preparedness')">Preparedness</button>
|
||
</div>
|
||
|
||
<!-- SEZIONE 1: Classificazione Incidenti -->
|
||
<div class="section active" id="section-classification">
|
||
<div class="section-header">
|
||
<div class="section-title">
|
||
Sezione 1: Classificazione Incidenti
|
||
<span class="help-icon">?
|
||
<div class="tooltip">
|
||
<div class="tooltip-title">HELP DELLA SEZIONE</div>
|
||
Sistema di classificazione incidenti secondo D.Lgs. 138/2024. Ogni incidente deve essere classificato secondo tipologia IS-1/IS-2/IS-3/IS-4 per determinare gli obblighi di notifica al CSIRT Italia.
|
||
</div>
|
||
</span>
|
||
</div>
|
||
</div>
|
||
|
||
<div class="info-box danger-box">
|
||
<div class="info-box-title">⚠️ Definizione di Incidente (Art. 6 D.Lgs. 138/2024)</div>
|
||
<div class="info-box-content">
|
||
Un <strong>incidente</strong> è qualsiasi evento che comprometta la <strong>disponibilità, autenticità, integrità o riservatezza</strong> dei dati conservati, trasmessi o elaborati, o dei servizi offerti o resi accessibili tramite reti e sistemi informativi.
|
||
</div>
|
||
</div>
|
||
|
||
<div class="classification-grid">
|
||
<div class="classification-card">
|
||
<div class="classification-header">
|
||
<div class="classification-code">IS-1</div>
|
||
<div class="classification-severity severity-critical">CRITICO</div>
|
||
</div>
|
||
<div class="classification-title">Incidente con Impatto Significativo sui Servizi</div>
|
||
<div class="classification-description">
|
||
Incidente che ha causato o può causare una grave interruzione operativa dei servizi o perdite finanziarie significative per l'organizzazione o gli utenti.
|
||
</div>
|
||
<div class="classification-examples">
|
||
<strong>Esempi:</strong><br>
|
||
• Interruzione servizio critico >4 ore<br>
|
||
• Ransomware con cifratura dati produzione<br>
|
||
• DDoS che blocca servizi essenziali<br>
|
||
• Perdita dati clienti con impatto operativo
|
||
</div>
|
||
</div>
|
||
|
||
<div class="classification-card">
|
||
<div class="classification-header">
|
||
<div class="classification-code">IS-2</div>
|
||
<div class="classification-severity severity-critical">CRITICO</div>
|
||
</div>
|
||
<div class="classification-title">Incidente con Impatto su Integrità/Riservatezza Dati</div>
|
||
<div class="classification-description">
|
||
Incidente che ha compromesso l'integrità, autenticità o riservatezza dei dati, con particolare riferimento a dati personali, sensibili o proprietari.
|
||
</div>
|
||
<div class="classification-examples">
|
||
<strong>Esempi:</strong><br>
|
||
• Data breach con esfiltrazione dati<br>
|
||
• Accesso non autorizzato a database<br>
|
||
• Modifica non autorizzata dati critici<br>
|
||
• Furto credenziali amministrative
|
||
</div>
|
||
</div>
|
||
|
||
<div class="classification-card">
|
||
<div class="classification-header">
|
||
<div class="classification-code">IS-3</div>
|
||
<div class="classification-severity severity-critical">CRITICO</div>
|
||
</div>
|
||
<div class="classification-title">Incidente con Impatto su Altri Soggetti/Supply Chain</div>
|
||
<div class="classification-description">
|
||
Incidente che ha avuto o può avere impatto significativo su altri soggetti NIS2, fornitori critici o sulla catena di fornitura ICT.
|
||
</div>
|
||
<div class="classification-examples">
|
||
<strong>Esempi:</strong><br>
|
||
• Compromissione fornitore servizi critici<br>
|
||
• Propagazione malware a clienti<br>
|
||
• Incidente che impatta servizi a valle<br>
|
||
• Compromissione supply chain software
|
||
</div>
|
||
</div>
|
||
|
||
<div class="classification-card">
|
||
<div class="classification-header">
|
||
<div class="classification-code">IS-4</div>
|
||
<div class="classification-severity severity-critical">CRITICO</div>
|
||
</div>
|
||
<div class="classification-title">Incidente Ricorrente con Impatto Cumulativo</div>
|
||
<div class="classification-description">
|
||
Serie di incidenti correlati che, considerati cumulativamente, hanno causato o possono causare un impatto significativo.
|
||
</div>
|
||
<div class="classification-examples">
|
||
<strong>Esempi:</strong><br>
|
||
• Tentativi di accesso ripetuti (brute force)<br>
|
||
• Micro-interruzioni frequenti stesso servizio<br>
|
||
• Pattern di attacco coordinato nel tempo<br>
|
||
• Incidenti minori con causa comune
|
||
</div>
|
||
</div>
|
||
</div>
|
||
|
||
<div class="info-box warning-box" style="margin-top: 24px;">
|
||
<div class="info-box-title">📋 Criteri di Significatività (Art. 23 D.Lgs. 138/2024)</div>
|
||
<div class="info-box-content">
|
||
Un incidente è considerato <strong>significativo</strong> se ricade in una delle categorie IS-1, IS-2, IS-3 o IS-4 e richiede <strong>notifica obbligatoria al CSIRT Italia</strong> secondo le tempistiche previste.
|
||
</div>
|
||
</div>
|
||
</div>
|
||
|
||
<!-- SEZIONE 2: Processo di Gestione Incidenti -->
|
||
<div class="section" id="section-process">
|
||
<div class="section-header">
|
||
<div class="section-title">
|
||
Sezione 2: Processo di Gestione Incidenti
|
||
<span class="help-icon">?
|
||
<div class="tooltip">
|
||
<div class="tooltip-title">HELP DELLA SEZIONE</div>
|
||
Processo strutturato in 6 fasi per la gestione completa degli incidenti di sicurezza, dalla rilevazione al miglioramento continuo. Conforme ai requisiti RS.MA-01 e RS.CO-02.
|
||
</div>
|
||
</span>
|
||
</div>
|
||
</div>
|
||
|
||
<div class="process-flow">
|
||
<!-- Fase 1 -->
|
||
<div class="process-step">
|
||
<div class="process-header">
|
||
<div class="process-number">1</div>
|
||
<div class="process-title">Rilevazione e Segnalazione</div>
|
||
</div>
|
||
<div class="process-content">
|
||
<strong>Obiettivo:</strong> Identificare tempestivamente eventi di sicurezza potenzialmente critici attraverso molteplici canali di rilevazione.
|
||
</div>
|
||
<div class="process-details">
|
||
<strong>Fonti di Rilevazione:</strong>
|
||
<ul>
|
||
<li><strong>SIEM/SOC:</strong> Alert automatici da sistemi di monitoraggio <span class="essential-badge" id="siem-essential">OBBLIGATORIO ESSENZIALI</span></li>
|
||
<li><strong>Antivirus/EDR:</strong> Rilevazione malware e comportamenti anomali</li>
|
||
<li><strong>IDS/IPS:</strong> Rilevazione intrusioni e tentativi di attacco</li>
|
||
<li><strong>Segnalazioni utenti:</strong> Report da personale interno</li>
|
||
<li><strong>Fornitori:</strong> Notifiche da provider e partner</li>
|
||
<li><strong>Threat Intelligence:</strong> Indicatori di compromissione esterni</li>
|
||
</ul>
|
||
<strong>Canali di Segnalazione:</strong>
|
||
<ul>
|
||
<li>📧 Email: security@azienda.it (24/7)</li>
|
||
<li>📞 Hotline: +39 XXX XXXXXXX (H24)</li>
|
||
<li>🌐 Portale: https://security.azienda.it/incident</li>
|
||
<li>💬 Chat interna: #security-incidents</li>
|
||
</ul>
|
||
</div>
|
||
</div>
|
||
|
||
<!-- Fase 2 -->
|
||
<div class="process-step">
|
||
<div class="process-header">
|
||
<div class="process-number">2</div>
|
||
<div class="process-title">Triage e Classificazione</div>
|
||
</div>
|
||
<div class="process-content">
|
||
<strong>Obiettivo:</strong> Valutare rapidamente la severità dell'incidente e determinare la risposta appropriata entro 1 ora dalla segnalazione.
|
||
</div>
|
||
<div class="process-details">
|
||
<strong>Determinazione Severità:</strong>
|
||
<ul>
|
||
<li><strong>P1 - Critico:</strong> Servizio essenziale offline, data breach in corso, ransomware attivo</li>
|
||
<li><strong>P2 - Alto:</strong> Servizio importante degradato, tentativo di intrusione rilevato</li>
|
||
<li><strong>P3 - Medio:</strong> Incidente contenuto, impatto limitato</li>
|
||
<li><strong>P4 - Basso:</strong> Evento di sicurezza minore, nessun impatto immediato</li>
|
||
</ul>
|
||
<strong>Classificazione NIS2:</strong>
|
||
<ul>
|
||
<li>Verifica criteri IS-1, IS-2, IS-3, IS-4</li>
|
||
<li>Determinazione obbligo notifica CSIRT</li>
|
||
<li>Assegnazione responsabile gestione</li>
|
||
<li>Attivazione team di risposta</li>
|
||
</ul>
|
||
<button class="btn btn-interactive" onclick="showOutput('triage-form')" style="margin-top: 12px;">
|
||
📋 Visualizza Form Triage
|
||
</button>
|
||
</div>
|
||
</div>
|
||
|
||
<!-- Fase 3 -->
|
||
<div class="process-step">
|
||
<div class="process-header">
|
||
<div class="process-number">3</div>
|
||
<div class="process-title">Contenimento</div>
|
||
</div>
|
||
<div class="process-content">
|
||
<strong>Obiettivo:</strong> Limitare l'impatto e prevenire la propagazione dell'incidente ad altri sistemi o dati.
|
||
</div>
|
||
<div class="process-details">
|
||
<strong>Azioni di Contenimento Immediato:</strong>
|
||
<ul>
|
||
<li><strong>Isolamento:</strong> Disconnessione sistemi compromessi dalla rete</li>
|
||
<li><strong>Blocco accessi:</strong> Disabilitazione account compromessi</li>
|
||
<li><strong>Firewall rules:</strong> Blocco IP/domini malevoli</li>
|
||
<li><strong>Snapshot:</strong> Acquisizione immagini forensi sistemi critici</li>
|
||
<li><strong>Backup:</strong> Verifica integrità e disponibilità backup</li>
|
||
</ul>
|
||
<strong>Contenimento a Lungo Termine:</strong>
|
||
<ul>
|
||
<li>Segmentazione rete per limitare movimento laterale</li>
|
||
<li>Implementazione controlli compensativi temporanei</li>
|
||
<li>Monitoraggio intensificato sistemi correlati</li>
|
||
</ul>
|
||
<button class="btn btn-interactive" onclick="showOutput('containment-checklist')" style="margin-top: 12px;">
|
||
✅ Checklist Contenimento
|
||
</button>
|
||
</div>
|
||
</div>
|
||
|
||
<!-- Fase 4 -->
|
||
<div class="process-step">
|
||
<div class="process-header">
|
||
<div class="process-number">4</div>
|
||
<div class="process-title">Eradicazione</div>
|
||
</div>
|
||
<div class="process-content">
|
||
<strong>Obiettivo:</strong> Rimuovere completamente la causa dell'incidente e tutte le tracce dell'attaccante dai sistemi.
|
||
</div>
|
||
<div class="process-details">
|
||
<strong>Attività di Eradicazione:</strong>
|
||
<ul>
|
||
<li><strong>Rimozione malware:</strong> Eliminazione completa codice malevolo</li>
|
||
<li><strong>Chiusura vulnerabilità:</strong> Patching sistemi sfruttati</li>
|
||
<li><strong>Eliminazione backdoor:</strong> Ricerca e rimozione persistenze</li>
|
||
<li><strong>Reset credenziali:</strong> Cambio password account compromessi</li>
|
||
<li><strong>Hardening:</strong> Rafforzamento configurazioni sicurezza</li>
|
||
</ul>
|
||
<strong>Verifica Eradicazione:</strong>
|
||
<ul>
|
||
<li>Scansione completa antimalware</li>
|
||
<li>Vulnerability assessment post-remediation</li>
|
||
<li>Verifica assenza IoC (Indicators of Compromise)</li>
|
||
<li>Monitoraggio comportamento sistemi 48-72h</li>
|
||
</ul>
|
||
</div>
|
||
</div>
|
||
|
||
<!-- Fase 5 -->
|
||
<div class="process-step">
|
||
<div class="process-header">
|
||
<div class="process-number">5</div>
|
||
<div class="process-title">Ripristino</div>
|
||
</div>
|
||
<div class="process-content">
|
||
<strong>Obiettivo:</strong> Riportare i sistemi e servizi alla normale operatività in modo sicuro e controllato.
|
||
</div>
|
||
<div class="process-details">
|
||
<strong>Processo di Ripristino:</strong>
|
||
<ul>
|
||
<li><strong>Validazione sistemi:</strong> Verifica integrità prima del ripristino</li>
|
||
<li><strong>Ripristino graduale:</strong> Riattivazione controllata per priorità</li>
|
||
<li><strong>Monitoraggio intensivo:</strong> Sorveglianza 24/7 durante ripristino</li>
|
||
<li><strong>Test funzionalità:</strong> Verifica operatività servizi</li>
|
||
<li><strong>Comunicazioni:</strong> Aggiornamenti stakeholder su avanzamento</li>
|
||
</ul>
|
||
<strong>Criteri di Successo:</strong>
|
||
<ul>
|
||
<li>RTO (Recovery Time Objective) rispettato</li>
|
||
<li>RPO (Recovery Point Objective) rispettato</li>
|
||
<li>Nessuna ricomparsa indicatori compromissione</li>
|
||
<li>Servizi operativi con performance normali</li>
|
||
</ul>
|
||
<button class="btn btn-interactive" onclick="showOutput('recovery-plan')" style="margin-top: 12px;">
|
||
📊 Piano Ripristino
|
||
</button>
|
||
</div>
|
||
</div>
|
||
|
||
<!-- Fase 6 -->
|
||
<div class="process-step">
|
||
<div class="process-header">
|
||
<div class="process-number">6</div>
|
||
<div class="process-title">Lesson Learned e Miglioramento</div>
|
||
</div>
|
||
<div class="process-content">
|
||
<strong>Obiettivo:</strong> Analizzare l'incidente per identificare aree di miglioramento e prevenire ricorrenze future.
|
||
</div>
|
||
<div class="process-details">
|
||
<strong>Post-Incident Review (entro 7 giorni):</strong>
|
||
<ul>
|
||
<li><strong>Timeline dettagliata:</strong> Ricostruzione cronologica eventi</li>
|
||
<li><strong>Root cause analysis:</strong> Identificazione causa radice</li>
|
||
<li><strong>Efficacia risposta:</strong> Valutazione tempi e azioni</li>
|
||
<li><strong>Gap identificati:</strong> Lacune in processi/tecnologie</li>
|
||
<li><strong>Raccomandazioni:</strong> Azioni correttive e preventive</li>
|
||
</ul>
|
||
<strong>Azioni di Miglioramento:</strong>
|
||
<ul>
|
||
<li>Aggiornamento procedure e playbook</li>
|
||
<li>Implementazione controlli aggiuntivi</li>
|
||
<li>Training personale su lezioni apprese</li>
|
||
<li>Aggiornamento risk assessment</li>
|
||
</ul>
|
||
<button class="btn btn-interactive" onclick="showOutput('pir-template')" style="margin-top: 12px;">
|
||
📝 Template Post-Incident Review
|
||
</button>
|
||
</div>
|
||
</div>
|
||
</div>
|
||
</div>
|
||
|
||
<!-- SEZIONE 3: Notifica Incidenti CSIRT -->
|
||
<div class="section" id="section-notification">
|
||
<div class="section-header">
|
||
<div class="section-title">
|
||
Sezione 3: Notifica Incidenti e Comunicazioni Obbligatorie
|
||
<span class="help-icon">?
|
||
<div class="tooltip">
|
||
<div class="tooltip-title">HELP DELLA SEZIONE</div>
|
||
Procedure di notifica al CSIRT Italia secondo Art. 23 D.Lgs. 138/2024. Tempistiche stringenti: preallarme 24h, notifica completa 72h, relazione finale 1 mese.
|
||
</div>
|
||
</span>
|
||
</div>
|
||
<div class="section-actions">
|
||
<button class="btn btn-danger" onclick="showOutput('csirt-notification')">
|
||
📤 Genera Notifica CSIRT
|
||
</button>
|
||
</div>
|
||
</div>
|
||
|
||
<div class="info-box danger-box">
|
||
<div class="info-box-title">⚠️ Obblighi di Notifica (Art. 23 D.Lgs. 138/2024)</div>
|
||
<div class="info-box-content">
|
||
I soggetti NIS2 devono notificare <strong>senza indebito ritardo</strong> al CSIRT Italia gli incidenti significativi (IS-1, IS-2, IS-3, IS-4). La mancata notifica o notifica tardiva comporta <strong>sanzioni amministrative</strong> fino a 10 milioni di euro o 2% del fatturato globale annuo.
|
||
</div>
|
||
</div>
|
||
|
||
<div class="timeline">
|
||
<div class="timeline-item">
|
||
<div class="timeline-time">24h</div>
|
||
<div class="timeline-label">Preallarme</div>
|
||
<div class="timeline-description">
|
||
Notifica iniziale con informazioni disponibili
|
||
</div>
|
||
</div>
|
||
<div class="timeline-item">
|
||
<div class="timeline-time">72h</div>
|
||
<div class="timeline-label">Notifica Completa</div>
|
||
<div class="timeline-description">
|
||
Report dettagliato con valutazione impatto
|
||
</div>
|
||
</div>
|
||
<div class="timeline-item">
|
||
<div class="timeline-time">1 mese</div>
|
||
<div class="timeline-label">Relazione Finale</div>
|
||
<div class="timeline-description">
|
||
Analisi completa, causa radice e azioni correttive
|
||
</div>
|
||
</div>
|
||
</div>
|
||
|
||
<div style="margin-top: 24px;">
|
||
<h3 style="font-size: 16px; font-weight: 600; margin-bottom: 16px;">Contenuti Minimi delle Notifiche</h3>
|
||
|
||
<div class="info-box">
|
||
<div class="info-box-title">📋 Notifica di Preallarme (entro 24 ore)</div>
|
||
<div class="info-box-content">
|
||
<strong>Contenuti minimi richiesti:</strong><br>
|
||
• Identificazione soggetto notificante<br>
|
||
• Data e ora rilevazione incidente<br>
|
||
• Classificazione preliminare (IS-1/IS-2/IS-3/IS-4)<br>
|
||
• Descrizione sintetica dell'incidente<br>
|
||
• Sistemi/servizi potenzialmente impattati<br>
|
||
• Indicazione se l'incidente è ancora in corso<br>
|
||
• Eventuali impatti su altri soggetti NIS2<br>
|
||
• Referente per comunicazioni successive
|
||
</div>
|
||
</div>
|
||
|
||
<div class="info-box" style="margin-top: 16px;">
|
||
<div class="info-box-title">📊 Notifica Completa (entro 72 ore)</div>
|
||
<div class="info-box-content">
|
||
<strong>Contenuti aggiuntivi richiesti:</strong><br>
|
||
• Aggiornamento classificazione incidente<br>
|
||
• Descrizione dettagliata dell'incidente e timeline<br>
|
||
• Valutazione impatto operativo e finanziario<br>
|
||
• Numero utenti/clienti impattati<br>
|
||
• Tipologia di dati compromessi (se applicabile)<br>
|
||
• Vettore di attacco e vulnerabilità sfruttate<br>
|
||
• Azioni di contenimento implementate<br>
|
||
• Stato attuale dell'incidente<br>
|
||
• Indicatori di compromissione (IoC)<br>
|
||
• Impatto transfrontaliero (se applicabile)
|
||
</div>
|
||
</div>
|
||
|
||
<div class="info-box" style="margin-top: 16px;">
|
||
<div class="info-box-title">📄 Relazione Finale (entro 1 mese)</div>
|
||
<div class="info-box-content">
|
||
<strong>Contenuti della relazione conclusiva:</strong><br>
|
||
• Descrizione completa e dettagliata dell'incidente<br>
|
||
• Timeline completa con tutti gli eventi<br>
|
||
• Causa radice (root cause analysis)<br>
|
||
• Impatto finale quantificato<br>
|
||
• Tutte le azioni di risposta implementate<br>
|
||
• Risultati delle attività di eradicazione<br>
|
||
• Misure correttive implementate<br>
|
||
• Raccomandazioni per prevenire ricorrenze<br>
|
||
• Lesson learned e miglioramenti al processo<br>
|
||
• Costi sostenuti per la gestione dell'incidente
|
||
</div>
|
||
</div>
|
||
</div>
|
||
<div class="info-box warning-box" style="margin-top: 24px;" id="essential-public-comm">
|
||
<div class="info-box-title">📢 Comunicazioni Pubbliche <span class="essential-badge">SOLO ESSENZIALI</span></div>
|
||
<div class="info-box-content">
|
||
I <strong>soggetti essenziali</strong> devono rendere pubblico l'incidente quando la divulgazione è nell'interesse pubblico o necessaria per prevenire conseguenze negative. La comunicazione deve essere coordinata con ACN e può includere: comunicati stampa, aggiornamenti sul sito web, notifiche dirette agli utenti impattati.
|
||
</div>
|
||
</div>
|
||
|
||
<div style="margin-top: 24px;">
|
||
<h3 style="font-size: 16px; font-weight: 600; margin-bottom: 16px;">Canali di Notifica CSIRT Italia</h3>
|
||
<div class="table-container">
|
||
<table>
|
||
<thead>
|
||
<tr>
|
||
<th>Canale</th>
|
||
<th>Utilizzo</th>
|
||
<th>Disponibilità</th>
|
||
<th>Dettagli</th>
|
||
</tr>
|
||
</thead>
|
||
<tbody>
|
||
<tr>
|
||
<td><strong>Portale ACN</strong></td>
|
||
<td>Notifiche formali obbligatorie</td>
|
||
<td>24/7</td>
|
||
<td>https://csirt.acn.gov.it</td>
|
||
</tr>
|
||
<tr>
|
||
<td><strong>Email PEC</strong></td>
|
||
<td>Notifiche urgenti e backup</td>
|
||
<td>24/7</td>
|
||
<td>csirt@pec.acn.gov.it</td>
|
||
</tr>
|
||
<tr>
|
||
<td><strong>Telefono H24</strong></td>
|
||
<td>Emergenze e coordinamento</td>
|
||
<td>24/7</td>
|
||
<td>+39 06 XXXX XXXX</td>
|
||
</tr>
|
||
<tr>
|
||
<td><strong>Email Operativa</strong></td>
|
||
<td>Comunicazioni operative</td>
|
||
<td>24/7</td>
|
||
<td>incidents@csirt.gov.it</td>
|
||
</tr>
|
||
</tbody>
|
||
</table>
|
||
</div>
|
||
</div>
|
||
</div>
|
||
|
||
<!-- SEZIONE 4: Ripristino Servizi -->
|
||
<div class="section" id="section-recovery">
|
||
<div class="section-header">
|
||
<div class="section-title">
|
||
Sezione 4: Ripristino Servizi e Sistemi
|
||
<span class="help-icon">?
|
||
<div class="tooltip">
|
||
<div class="tooltip-title">HELP DELLA SEZIONE</div>
|
||
Piano strutturato per il ripristino sicuro e controllato dei servizi dopo un incidente. Conforme a RC.RP-01 con prioritizzazione basata su criticità e dipendenze.
|
||
</div>
|
||
</span>
|
||
</div>
|
||
<div class="section-actions">
|
||
<button class="btn btn-primary" onclick="showOutput('recovery-dashboard')">
|
||
📊 Dashboard Ripristino
|
||
</button>
|
||
</div>
|
||
</div>
|
||
|
||
<div class="info-box">
|
||
<div class="info-box-title">🎯 Principi di Ripristino</div>
|
||
<div class="info-box-content">
|
||
<strong>1. Sicurezza prima di tutto:</strong> Verificare completa eradicazione prima del ripristino<br>
|
||
<strong>2. Prioritizzazione:</strong> Ripristinare prima i servizi essenziali e critici<br>
|
||
<strong>3. Gradualità:</strong> Approccio incrementale con validazione continua<br>
|
||
<strong>4. Monitoraggio:</strong> Sorveglianza intensiva durante e dopo il ripristino<br>
|
||
<strong>5. Comunicazione:</strong> Aggiornamenti costanti agli stakeholder
|
||
</div>
|
||
</div>
|
||
|
||
<div style="margin-top: 24px;">
|
||
<h3 style="font-size: 16px; font-weight: 600; margin-bottom: 16px;">Processo di Ripristino</h3>
|
||
|
||
<div class="process-flow">
|
||
<div class="process-step">
|
||
<div class="process-header">
|
||
<div class="process-number">1</div>
|
||
<div class="process-title">Valutazione Pre-Ripristino</div>
|
||
</div>
|
||
<div class="process-content">
|
||
Verifica che tutte le condizioni per un ripristino sicuro siano soddisfatte.
|
||
</div>
|
||
<div class="process-details">
|
||
<strong>Checklist Pre-Ripristino:</strong>
|
||
<ul>
|
||
<li>✓ Minaccia completamente eradicata e verificata</li>
|
||
<li>✓ Vulnerabilità sfruttate corrette e testate</li>
|
||
<li>✓ Backup verificati e disponibili</li>
|
||
<li>✓ Team di ripristino allertato e disponibile</li>
|
||
<li>✓ Piano di rollback preparato</li>
|
||
<li>✓ Stakeholder informati della timeline</li>
|
||
<li>✓ Monitoraggio intensivo attivato</li>
|
||
</ul>
|
||
</div>
|
||
</div>
|
||
|
||
<div class="process-step">
|
||
<div class="process-header">
|
||
<div class="process-number">2</div>
|
||
<div class="process-title">Ripristino per Priorità</div>
|
||
</div>
|
||
<div class="process-content">
|
||
Ripristino graduale seguendo l'ordine di criticità dei servizi.
|
||
</div>
|
||
<div class="process-details">
|
||
<strong>Ordine di Ripristino:</strong>
|
||
<ul>
|
||
<li><strong>Priorità 1 - Servizi Essenziali:</strong> Infrastruttura critica, servizi core business (RTO: 4h)</li>
|
||
<li><strong>Priorità 2 - Servizi Importanti:</strong> Applicazioni business-critical (RTO: 24h)</li>
|
||
<li><strong>Priorità 3 - Servizi Standard:</strong> Applicazioni supporto operativo (RTO: 72h)</li>
|
||
<li><strong>Priorità 4 - Servizi Non Critici:</strong> Sistemi accessori (RTO: 1 settimana)</li>
|
||
</ul>
|
||
<button class="btn btn-interactive" onclick="showOutput('priority-matrix')" style="margin-top: 12px;">
|
||
📋 Matrice Priorità Ripristino
|
||
</button>
|
||
</div>
|
||
</div>
|
||
|
||
<div class="process-step">
|
||
<div class="process-header">
|
||
<div class="process-number">3</div>
|
||
<div class="process-title">Validazione e Testing</div>
|
||
</div>
|
||
<div class="process-content">
|
||
Test approfonditi prima di dichiarare il servizio completamente ripristinato.
|
||
</div>
|
||
<div class="process-details">
|
||
<strong>Test di Validazione:</strong>
|
||
<ul>
|
||
<li>Test funzionali: Verifica operatività completa</li>
|
||
<li>Test performance: Verifica tempi di risposta normali</li>
|
||
<li>Test sicurezza: Scan vulnerabilità post-ripristino</li>
|
||
<li>Test integrazione: Verifica connessioni con altri sistemi</li>
|
||
<li>User Acceptance Test: Validazione utenti chiave</li>
|
||
</ul>
|
||
</div>
|
||
</div>
|
||
|
||
<div class="process-step">
|
||
<div class="process-header">
|
||
<div class="process-number">4</div>
|
||
<div class="process-title">Monitoraggio Post-Ripristino</div>
|
||
</div>
|
||
<div class="process-content">
|
||
Sorveglianza intensiva per 72 ore dopo il ripristino per rilevare eventuali anomalie.
|
||
</div>
|
||
<div class="process-details">
|
||
<strong>Attività di Monitoraggio:</strong>
|
||
<ul>
|
||
<li>Monitoraggio 24/7 per 72 ore minimo</li>
|
||
<li>Alert configurati con soglie ridotte</li>
|
||
<li>Verifica periodica IoC (Indicators of Compromise)</li>
|
||
<li>Analisi log approfondita</li>
|
||
<li>Report giornalieri al management</li>
|
||
</ul>
|
||
</div>
|
||
</div>
|
||
</div>
|
||
</div>
|
||
|
||
<div style="margin-top: 24px;">
|
||
<h3 style="font-size: 16px; font-weight: 600; margin-bottom: 16px;">Strategie di Ripristino</h3>
|
||
<div class="table-container">
|
||
<table>
|
||
<thead>
|
||
<tr>
|
||
<th>Strategia</th>
|
||
<th>Quando Utilizzare</th>
|
||
<th>RTO Tipico</th>
|
||
<th>Complessità</th>
|
||
</tr>
|
||
</thead>
|
||
<tbody>
|
||
<tr>
|
||
<td><strong>Ripristino da Backup</strong></td>
|
||
<td>Dati corrotti o cifrati (ransomware)</td>
|
||
<td>4-24h</td>
|
||
<td>Media</td>
|
||
</tr>
|
||
<tr>
|
||
<td><strong>Rebuild da Zero</strong></td>
|
||
<td>Compromissione profonda del sistema</td>
|
||
<td>24-72h</td>
|
||
<td>Alta</td>
|
||
</tr>
|
||
<tr>
|
||
<td><strong>Failover a DR Site</strong></td>
|
||
<td>Datacenter primario compromesso</td>
|
||
<td>1-4h</td>
|
||
<td>Bassa</td>
|
||
</tr>
|
||
<tr>
|
||
<td><strong>Ripristino Selettivo</strong></td>
|
||
<td>Solo alcuni componenti impattati</td>
|
||
<td>2-8h</td>
|
||
<td>Media</td>
|
||
</tr>
|
||
<tr>
|
||
<td><strong>Riconfigurazione</strong></td>
|
||
<td>Configurazioni alterate ma sistema integro</td>
|
||
<td>1-4h</td>
|
||
<td>Bassa</td>
|
||
</tr>
|
||
</tbody>
|
||
</table>
|
||
</div>
|
||
</div>
|
||
|
||
<div class="info-box warning-box" style="margin-top: 24px;">
|
||
<div class="info-box-title">⚠️ Criteri di Rollback</div>
|
||
<div class="info-box-content">
|
||
Il ripristino deve essere <strong>immediatamente interrotto e fatto rollback</strong> se:<br>
|
||
• Ricompaiono indicatori di compromissione<br>
|
||
• I test di validazione falliscono<br>
|
||
• Si rilevano nuove anomalie di sicurezza<br>
|
||
• L'impatto operativo è peggiore dello stato pre-ripristino<br>
|
||
• Il team identifica rischi non previsti
|
||
</div>
|
||
</div>
|
||
</div>
|
||
|
||
<!-- SEZIONE 5: Comunicazione Ripristino -->
|
||
<div class="section" id="section-communication">
|
||
<div class="section-header">
|
||
<div class="section-title">
|
||
Sezione 5: Comunicazione Ripristino e Lesson Learned
|
||
<span class="help-icon">?
|
||
<div class="tooltip">
|
||
<div class="tooltip-title">HELP DELLA SEZIONE</div>
|
||
Gestione delle comunicazioni durante e dopo il ripristino. Include aggiornamenti interni/esterni e processo di Post-Incident Review. Conforme a RC.CO-03.
|
||
</div>
|
||
</span>
|
||
</div>
|
||
</div>
|
||
|
||
<div style="margin-top: 24px;">
|
||
<h3 style="font-size: 16px; font-weight: 600; margin-bottom: 16px;">Piano di Comunicazione</h3>
|
||
|
||
<div class="table-container">
|
||
<table>
|
||
<thead>
|
||
<tr>
|
||
<th>Stakeholder</th>
|
||
<th>Tipo Comunicazione</th>
|
||
<th>Frequenza</th>
|
||
<th>Canale</th>
|
||
<th>Responsabile</th>
|
||
</tr>
|
||
</thead>
|
||
<tbody>
|
||
<tr>
|
||
<td><strong>Top Management</strong></td>
|
||
<td>Briefing esecutivo</td>
|
||
<td>Ogni 4h durante incidente</td>
|
||
<td>Email + Call</td>
|
||
<td>CISO</td>
|
||
</tr>
|
||
<tr>
|
||
<td><strong>CdA</strong></td>
|
||
<td>Report formale</td>
|
||
<td>Giornaliero per incidenti critici</td>
|
||
<td>Email + Presentazione</td>
|
||
<td>CEO/CISO</td>
|
||
</tr>
|
||
<tr>
|
||
<td><strong>Dipendenti</strong></td>
|
||
<td>Aggiornamento operativo</td>
|
||
<td>Ogni 8h</td>
|
||
<td>Intranet + Email</td>
|
||
<td>IT Manager</td>
|
||
</tr>
|
||
<tr>
|
||
<td><strong>Clienti/Utenti</strong></td>
|
||
<td>Status update</td>
|
||
<td>Ogni 12h o al cambio stato</td>
|
||
<td>Website + Email</td>
|
||
<td>Customer Care</td>
|
||
</tr>
|
||
<tr>
|
||
<td><strong>CSIRT Italia</strong></td>
|
||
<td>Notifica formale</td>
|
||
<td>Secondo tempistiche NIS2</td>
|
||
<td>Portale ACN</td>
|
||
<td>CISO</td>
|
||
</tr>
|
||
<tr>
|
||
<td><strong>Fornitori Critici</strong></td>
|
||
<td>Coordinamento tecnico</td>
|
||
<td>Secondo necessità</td>
|
||
<td>Email + Call</td>
|
||
<td>IT Manager</td>
|
||
</tr>
|
||
<tr>
|
||
<td><strong>Media</strong> <span class="essential-badge">SE RICHIESTO</span></td>
|
||
<td>Comunicato stampa</td>
|
||
<td>Secondo necessità</td>
|
||
<td>Press Release</td>
|
||
<td>Ufficio Stampa</td>
|
||
</tr>
|
||
<tr>
|
||
<td><strong>Autorità Garante Privacy</strong></td>
|
||
<td>Notifica data breach</td>
|
||
<td>Entro 72h se dati personali</td>
|
||
<td>Portale GPDP</td>
|
||
<td>DPO</td>
|
||
</tr>
|
||
</tbody>
|
||
</table>
|
||
</div>
|
||
|
||
<button class="btn btn-interactive" onclick="showOutput('comm-templates')" style="margin-top: 16px;">
|
||
📧 Visualizza Template Comunicazioni
|
||
</button>
|
||
</div>
|
||
|
||
<div style="margin-top: 32px;">
|
||
<h3 style="font-size: 16px; font-weight: 600; margin-bottom: 16px;">Aggiornamenti Durante il Ripristino</h3>
|
||
|
||
<div class="info-box">
|
||
<div class="info-box-title">📊 Status Page Pubblico</div>
|
||
<div class="info-box-content">
|
||
Mantenere una <strong>status page</strong> aggiornata in tempo reale con:<br>
|
||
• Stato corrente dei servizi (Operativo / Degradato / Non disponibile)<br>
|
||
• Descrizione dell'incidente (livello appropriato di dettaglio)<br>
|
||
• Impatto stimato sugli utenti<br>
|
||
• Timeline degli aggiornamenti<br>
|
||
• ETA (Estimated Time of Arrival) per il ripristino<br>
|
||
• Workaround disponibili<br>
|
||
• Canali di supporto attivi
|
||
</div>
|
||
</div>
|
||
|
||
<div class="info-box" style="margin-top: 16px;">
|
||
<div class="info-box-title">📱 Comunicazioni Interne</div>
|
||
<div class="info-box-content">
|
||
<strong>War Room virtuale:</strong> Canale dedicato (es. Microsoft Teams, Slack) per coordinamento in tempo reale<br>
|
||
<strong>Daily Standup:</strong> Riunione giornaliera team risposta incidenti (15 min)<br>
|
||
<strong>Incident Log:</strong> Documento condiviso con timeline dettagliata e decisioni prese<br>
|
||
<strong>Escalation Path:</strong> Procedure chiare per escalation a livelli superiori
|
||
</div>
|
||
</div>
|
||
</div>
|
||
|
||
<div style="margin-top: 32px;">
|
||
<h3 style="font-size: 16px; font-weight: 600; margin-bottom: 16px;">Post-Incident Review (PIR)</h3>
|
||
|
||
<div class="info-box danger-box">
|
||
<div class="info-box-title">📋 Obbligatorietà PIR</div>
|
||
<div class="info-box-content">
|
||
Per <strong>tutti gli incidenti significativi</strong> (IS-1, IS-2, IS-3, IS-4) è <strong>obbligatorio</strong> condurre un Post-Incident Review entro <strong>7 giorni lavorativi</strong> dalla chiusura dell'incidente.
|
||
</div>
|
||
</div>
|
||
|
||
<div class="process-flow" style="margin-top: 16px;">
|
||
<div class="process-step">
|
||
<div class="process-header">
|
||
<div class="process-number">1</div>
|
||
<div class="process-title">Raccolta Dati</div>
|
||
</div>
|
||
<div class="process-content">
|
||
Raccogliere tutta la documentazione e i dati relativi all'incidente.
|
||
</div>
|
||
<div class="process-details">
|
||
<strong>Documenti da raccogliere:</strong>
|
||
<ul>
|
||
<li>Log completi dei sistemi impattati</li>
|
||
<li>Timeline dettagliata degli eventi</li>
|
||
<li>Tutte le comunicazioni (email, chat, call)</li>
|
||
<li>Report tecnici (forensics, malware analysis)</li>
|
||
<li>Decisioni prese e relative motivazioni</li>
|
||
<li>Costi sostenuti (diretti e indiretti)</li>
|
||
</ul>
|
||
</div>
|
||
</div>
|
||
|
||
<div class="process-step">
|
||
<div class="process-header">
|
||
<div class="process-number">2</div>
|
||
<div class="process-title">Riunione PIR</div>
|
||
</div>
|
||
<div class="process-content">
|
||
Sessione facilitata con tutti i partecipanti alla gestione dell'incidente.
|
||
</div>
|
||
<div class="process-details">
|
||
<strong>Partecipanti richiesti:</strong>
|
||
<ul>
|
||
<li>CISO (facilitatore)</li>
|
||
<li>Incident Response Team</li>
|
||
<li>IT Operations</li>
|
||
<li>Business Owner servizi impattati</li>
|
||
<li>Eventuali consulenti esterni</li>
|
||
</ul>
|
||
<strong>Agenda riunione (2-3 ore):</strong>
|
||
<ul>
|
||
<li>Ricostruzione timeline (30 min)</li>
|
||
<li>Analisi causa radice (45 min)</li>
|
||
<li>Valutazione risposta (30 min)</li>
|
||
<li>Identificazione gap (30 min)</li>
|
||
<li>Definizione azioni correttive (30 min)</li>
|
||
</ul>
|
||
</div>
|
||
</div>
|
||
|
||
<div class="process-step">
|
||
<div class="process-header">
|
||
<div class="process-number">3</div>
|
||
<div class="process-title">Report PIR</div>
|
||
</div>
|
||
<div class="process-content">
|
||
Documentazione formale delle lezioni apprese e azioni di miglioramento.
|
||
</div>
|
||
<div class="process-details">
|
||
<strong>Struttura Report PIR:</strong>
|
||
<ul>
|
||
<li><strong>Executive Summary:</strong> Sintesi per il management</li>
|
||
<li><strong>Incident Overview:</strong> Descrizione e classificazione</li>
|
||
<li><strong>Timeline Dettagliata:</strong> Cronologia completa eventi</li>
|
||
<li><strong>Root Cause Analysis:</strong> Causa radice e fattori contributivi</li>
|
||
<li><strong>Impact Assessment:</strong> Impatto operativo, finanziario, reputazionale</li>
|
||
<li><strong>Response Evaluation:</strong> Cosa ha funzionato e cosa no</li>
|
||
<li><strong>Gap Analysis:</strong> Lacune identificate</li>
|
||
<li><strong>Recommendations:</strong> Azioni correttive e preventive</li>
|
||
<li><strong>Action Plan:</strong> Piano implementazione con responsabili e deadline</li>
|
||
</ul>
|
||
<button class="btn btn-interactive" onclick="showOutput('pir-report')" style="margin-top: 12px;">
|
||
📄 Genera Report PIR
|
||
</button>
|
||
</div>
|
||
</div>
|
||
|
||
<div class="process-step">
|
||
<div class="process-header">
|
||
<div class="process-number">4</div>
|
||
<div class="process-title">Implementazione Miglioramenti</div>
|
||
</div>
|
||
<div class="process-content">
|
||
Attuazione delle azioni correttive identificate con tracking e follow-up.
|
||
</div>
|
||
<div class="process-details">
|
||
<strong>Categorie di miglioramento:</strong>
|
||
<ul>
|
||
<li><strong>Tecnologici:</strong> Nuovi controlli, upgrade sistemi</li>
|
||
<li><strong>Procedurali:</strong> Aggiornamento procedure e playbook</li>
|
||
<li><strong>Organizzativi:</strong> Modifiche a ruoli e responsabilità</li>
|
||
<li><strong>Formativi:</strong> Training e awareness per il personale</li>
|
||
</ul>
|
||
<strong>Tracking:</strong> Ogni azione deve avere responsabile, deadline e stato avanzamento monitorato mensilmente.
|
||
</div>
|
||
</div>
|
||
</div>
|
||
</div>
|
||
</div>
|
||
|
||
<!-- SEZIONE 6: Preparedness -->
|
||
<div class="section" id="section-preparedness">
|
||
<div class="section-header">
|
||
<div class="section-title">
|
||
Sezione 6: Preparedness — Preparazione alla Gestione Incidenti
|
||
<span class="help-icon">?
|
||
<div class="tooltip">
|
||
<div class="tooltip-title">HELP DELLA SEZIONE</div>
|
||
Attività di preparazione e readiness per garantire una risposta efficace agli incidenti. Include playbook, checklist operative, esercitazioni e formazione continua.
|
||
</div>
|
||
</span>
|
||
</div>
|
||
<div class="section-actions">
|
||
<button class="btn btn-primary" onclick="showOutput('drill-calendar')">
|
||
📅 Calendario Esercitazioni
|
||
</button>
|
||
</div>
|
||
</div>
|
||
|
||
<div class="info-box">
|
||
<div class="info-box-title">🎯 Obiettivi Preparedness</div>
|
||
<div class="info-box-content">
|
||
<strong>1. Readiness:</strong> Team preparato e procedure testate<br>
|
||
<strong>2. Efficienza:</strong> Riduzione tempi di risposta attraverso automazione e preparazione<br>
|
||
<strong>3. Resilienza:</strong> Capacità di gestire incidenti complessi e multipli<br>
|
||
<strong>4. Miglioramento continuo:</strong> Aggiornamento costante basato su threat intelligence e lezioni apprese
|
||
</div>
|
||
</div>
|
||
|
||
<div style="margin-top: 24px;">
|
||
<h3 style="font-size: 16px; font-weight: 600; margin-bottom: 16px;">Piano di Risposta agli Incidenti</h3>
|
||
|
||
<div class="table-container">
|
||
<table>
|
||
<thead>
|
||
<tr>
|
||
<th>Componente</th>
|
||
<th>Descrizione</th>
|
||
<th>Frequenza Aggiornamento</th>
|
||
<th>Responsabile</th>
|
||
</tr>
|
||
</thead>
|
||
<tbody>
|
||
<tr>
|
||
<td><strong>Incident Response Plan</strong></td>
|
||
<td>Documento master con policy e procedure generali</td>
|
||
<td>Annuale</td>
|
||
<td>CISO</td>
|
||
</tr>
|
||
<tr>
|
||
<td><strong>Playbook Operativi</strong></td>
|
||
<td>Guide step-by-step per tipologie specifiche</td>
|
||
<td>Semestrale</td>
|
||
<td>IR Team Lead</td>
|
||
</tr>
|
||
<tr>
|
||
<td><strong>Runbook Tecnici</strong></td>
|
||
<td>Procedure tecniche dettagliate</td>
|
||
<td>Trimestrale</td>
|
||
<td>Technical Lead</td>
|
||
</tr>
|
||
<tr>
|
||
<td><strong>Contact List</strong></td>
|
||
<td>Elenco contatti emergenza (interni/esterni)</td>
|
||
<td>Mensile</td>
|
||
<td>IR Coordinator</td>
|
||
</tr>
|
||
<tr>
|
||
<td><strong>Asset Inventory</strong></td>
|
||
<td>Inventario aggiornato sistemi critici</td>
|
||
<td>Continuo</td>
|
||
<td>IT Operations</td>
|
||
</tr>
|
||
<tr>
|
||
<td><strong>Communication Templates</strong></td>
|
||
<td>Template pre-approvati per comunicazioni</td>
|
||
<td>Semestrale</td>
|
||
<td>Communication Lead</td>
|
||
</tr>
|
||
</tbody>
|
||
</table>
|
||
</div>
|
||
</div>
|
||
|
||
<div style="margin-top: 32px;">
|
||
<h3 style="font-size: 16px; font-weight: 600; margin-bottom: 16px;">Playbook per Tipologia di Incidente</h3>
|
||
|
||
<div class="classification-grid">
|
||
<div class="classification-card">
|
||
<div class="classification-header">
|
||
<div class="classification-code">🔒</div>
|
||
</div>
|
||
<div class="classification-title">Ransomware</div>
|
||
<div class="classification-description">
|
||
Procedura per gestione attacchi ransomware con cifratura dati
|
||
</div>
|
||
<button class="btn btn-interactive" onclick="showOutput('playbook-ransomware')" style="margin-top: 12px; width: 100%;">
|
||
📖 Visualizza Playbook
|
||
</button>
|
||
</div>
|
||
|
||
<div class="classification-card">
|
||
<div class="classification-header">
|
||
<div class="classification-code">🚪</div>
|
||
</div>
|
||
<div class="classification-title">Data Breach</div>
|
||
<div class="classification-description">
|
||
Gestione violazioni dati con esfiltrazione informazioni sensibili
|
||
</div>
|
||
<button class="btn btn-interactive" onclick="showOutput('playbook-breach')" style="margin-top: 12px; width: 100%;">
|
||
📖 Visualizza Playbook
|
||
</button>
|
||
</div>
|
||
|
||
<div class="classification-card">
|
||
<div class="classification-header">
|
||
<div class="classification-code">⚡</div>
|
||
</div>
|
||
<div class="classification-title">DDoS Attack</div>
|
||
<div class="classification-description">
|
||
Risposta ad attacchi denial-of-service distribuiti
|
||
</div>
|
||
<button class="btn btn-interactive" onclick="showOutput('playbook-ddos')" style="margin-top: 12px; width: 100%;">
|
||
📖 Visualizza Playbook
|
||
</button>
|
||
</div>
|
||
|
||
<div class="classification-card">
|
||
<div class="classification-header">
|
||
<div class="classification-code">🎣</div>
|
||
</div>
|
||
<div class="classification-title">Phishing/BEC</div>
|
||
<div class="classification-description">
|
||
Gestione compromissione account via phishing o BEC
|
||
</div>
|
||
<button class="btn btn-interactive" onclick="showOutput('playbook-phishing')" style="margin-top: 12px; width: 100%;">
|
||
📖 Visualizza Playbook
|
||
</button>
|
||
</div>
|
||
|
||
<div class="classification-card">
|
||
<div class="classification-header">
|
||
<div class="classification-code">🦠</div>
|
||
</div>
|
||
<div class="classification-title">Malware Infection</div>
|
||
<div class="classification-description">
|
||
Risposta a infezioni malware generalizzate
|
||
</div>
|
||
<button class="btn btn-interactive" onclick="showOutput('playbook-malware')" style="margin-top: 12px; width: 100%;">
|
||
📖 Visualizza Playbook
|
||
</button>
|
||
</div>
|
||
|
||
<div class="classification-card">
|
||
<div class="classification-header">
|
||
<div class="classification-code">🔓</div>
|
||
</div>
|
||
<div class="classification-title">Unauthorized Access</div>
|
||
<div class="classification-description">
|
||
Gestione accessi non autorizzati a sistemi critici
|
||
</div>
|
||
<button class="btn btn-interactive" onclick="showOutput('playbook-access')" style="margin-top: 12px; width: 100%;">
|
||
📖 Visualizza Playbook
|
||
</button>
|
||
</div>
|
||
</div>
|
||
</div>
|
||
|
||
<div style="margin-top: 32px;">
|
||
<h3 style="font-size: 16px; font-weight: 600; margin-bottom: 16px;">Programma Esercitazioni</h3>
|
||
|
||
<div class="info-box warning-box">
|
||
<div class="info-box-title">📅 Obbligatorietà Esercitazioni NIS2</div>
|
||
<div class="info-box-content">
|
||
I soggetti NIS2 devono condurre <strong>esercitazioni periodiche</strong> per testare i piani di risposta agli incidenti. Frequenza minima consigliata: <strong>2 esercitazioni tabletop all'anno + 1 esercitazione tecnica completa</strong>.
|
||
</div>
|
||
</div>
|
||
|
||
<div class="table-container" style="margin-top: 16px;">
|
||
<table>
|
||
<thead>
|
||
<tr>
|
||
<th>Tipo Esercitazione</th>
|
||
<th>Descrizione</th>
|
||
<th>Frequenza</th>
|
||
<th>Partecipanti</th>
|
||
<th>Durata</th>
|
||
</tr>
|
||
</thead>
|
||
<tbody>
|
||
<tr>
|
||
<td><strong>Tabletop Exercise</strong></td>
|
||
<td>Discussione scenario ipotetico in sala riunioni</td>
|
||
<td>Semestrale</td>
|
||
<td>Management + IR Team</td>
|
||
<td>2-3 ore</td>
|
||
</tr>
|
||
<tr>
|
||
<td><strong>Walkthrough</strong></td>
|
||
<td>Revisione dettagliata procedure passo-passo</td>
|
||
<td>Trimestrale</td>
|
||
<td>IR Team</td>
|
||
<td>1-2 ore</td>
|
||
</tr>
|
||
<tr>
|
||
<td><strong>Simulation</strong></td>
|
||
<td>Simulazione realistica con azioni operative</td>
|
||
<td>Annuale</td>
|
||
<td>Tutti i team coinvolti</td>
|
||
<td>4-8 ore</td>
|
||
</tr>
|
||
<tr>
|
||
<td><strong>Full-Scale Exercise</strong></td>
|
||
<td>Esercitazione completa in ambiente reale</td>
|
||
<td>Annuale</td>
|
||
<td>Intera organizzazione</td>
|
||
<td>1-2 giorni</td>
|
||
</tr>
|
||
<tr>
|
||
<td><strong>Red Team Exercise</strong></td>
|
||
<td>Attacco simulato da team esterno</td>
|
||
<td>Annuale</td>
|
||
<td>Blue Team + SOC</td>
|
||
<td>1-4 settimane</td>
|
||
</tr>
|
||
</tbody>
|
||
</table>
|
||
</div>
|
||
|
||
<button class="btn btn-interactive" onclick="showOutput('exercise-report')" style="margin-top: 16px;">
|
||
📊 Template Report Esercitazione
|
||
</button>
|
||
</div>
|
||
|
||
<div style="margin-top: 32px;">
|
||
<h3 style="font-size: 16px; font-weight: 600; margin-bottom: 16px;">Formazione e Awareness</h3>
|
||
|
||
<div class="table-container">
|
||
<table>
|
||
<thead>
|
||
<tr>
|
||
<th>Target</th>
|
||
<th>Contenuti</th>
|
||
<th>Modalità</th>
|
||
<th>Frequenza</th>
|
||
</tr>
|
||
</thead>
|
||
<tbody>
|
||
<tr>
|
||
<td><strong>Incident Response Team</strong></td>
|
||
<td>Training tecnico avanzato, certificazioni (GCIH, GCFA)</td>
|
||
<td>Corso + Lab pratici</td>
|
||
<td>Annuale</td>
|
||
</tr>
|
||
<tr>
|
||
<td><strong>IT Operations</strong></td>
|
||
<td>Rilevazione incidenti, escalation, procedure base</td>
|
||
<td>Workshop</td>
|
||
<td>Semestrale</td>
|
||
</tr>
|
||
<tr>
|
||
<td><strong>Management</strong></td>
|
||
<td>Ruoli in crisi, comunicazioni, decisioni strategiche</td>
|
||
<td>Tabletop</td>
|
||
<td>Annuale</td>
|
||
</tr>
|
||
<tr>
|
||
<td><strong>Tutti i Dipendenti</strong></td>
|
||
<td>Riconoscimento minacce, segnalazione incidenti</td>
|
||
<td>E-learning</td>
|
||
<td>Annuale</td>
|
||
</tr>
|
||
<tr>
|
||
<td><strong>Fornitori Critici</strong></td>
|
||
<td>Procedure coordinamento, comunicazioni emergenza</td>
|
||
<td>Workshop congiunto</td>
|
||
<td>Annuale</td>
|
||
</tr>
|
||
</tbody>
|
||
</table>
|
||
</div>
|
||
</div>
|
||
|
||
<div class="info-box" style="margin-top: 24px;">
|
||
<div class="info-box-title">📚 Risorse e Strumenti</div>
|
||
<div class="info-box-content">
|
||
<strong>Documentazione di riferimento:</strong><br>
|
||
• NIST SP 800-61 Rev. 2 - Computer Security Incident Handling Guide<br>
|
||
• SANS Incident Handler's Handbook<br>
|
||
• ENISA - Good Practice Guide for Incident Management<br>
|
||
• Linee Guida ACN per soggetti NIS2<br>
|
||
<br>
|
||
<strong>Tool consigliati:</strong><br>
|
||
• SIEM/SOAR per automazione risposta<br>
|
||
• Threat Intelligence Platform<br>
|
||
• Forensics toolkit (FTK, EnCase, Volatility)<br>
|
||
• Incident Management Platform (TheHive, RTIR)<br>
|
||
• Communication tools (War Room, Status Page)
|
||
</div>
|
||
</div>
|
||
</div>
|
||
</div>
|
||
|
||
<!-- Modal per Output -->
|
||
<div class="output-modal" id="outputModal">
|
||
<div class="output-content">
|
||
<button class="output-close" onclick="closeOutput()">×</button>
|
||
<div id="outputBody"></div>
|
||
</div>
|
||
</div>
|
||
|
||
<script>
|
||
// Gestione tipo soggetto
|
||
window.addEventListener('DOMContentLoaded', function() {
|
||
const subjectType = sessionStorage.getItem('nis2_subject_type');
|
||
|
||
if (!subjectType) {
|
||
window.location.href = 'incident-gateway.html';
|
||
return;
|
||
}
|
||
|
||
// Imposta badge
|
||
const badge = document.getElementById('subjectTypeBadge');
|
||
if (subjectType === 'essential') {
|
||
badge.className = 'subject-type-badge badge-essential';
|
||
badge.innerHTML = '⚡ SOGGETTO ESSENZIALE';
|
||
} else {
|
||
badge.className = 'subject-type-badge badge-important';
|
||
badge.innerHTML = '🔷 SOGGETTO IMPORTANTE';
|
||
}
|
||
|
||
// Nascondi elementi solo per essenziali se soggetto è importante
|
||
if (subjectType === 'important') {
|
||
const essentialElements = document.querySelectorAll('#essential-public-comm, #siem-essential');
|
||
essentialElements.forEach(el => {
|
||
if (el.id === 'essential-public-comm') {
|
||
el.style.display = 'none';
|
||
}
|
||
});
|
||
}
|
||
});
|
||
|
||
// Gestione tabs
|
||
function showTab(tabName) {
|
||
// Nascondi tutte le sezioni
|
||
document.querySelectorAll('.section').forEach(section => {
|
||
section.classList.remove('active');
|
||
});
|
||
|
||
// Rimuovi active da tutti i tab
|
||
document.querySelectorAll('.tab').forEach(tab => {
|
||
tab.classList.remove('active');
|
||
});
|
||
|
||
// Mostra sezione selezionata
|
||
const section = document.getElementById('section-' + tabName);
|
||
if (section) {
|
||
section.classList.add('active');
|
||
}
|
||
|
||
// Attiva tab cliccato
|
||
event.target.classList.add('active');
|
||
}
|
||
|
||
// Funzione per mostrare output
|
||
function showOutput(type) {
|
||
const modal = document.getElementById('outputModal');
|
||
const body = document.getElementById('outputBody');
|
||
|
||
let content = '';
|
||
|
||
switch(type) {
|
||
case 'triage-form':
|
||
content = generateTriageForm();
|
||
break;
|
||
case 'containment-checklist':
|
||
content = generateContainmentChecklist();
|
||
break;
|
||
case 'recovery-plan':
|
||
content = generateRecoveryPlan();
|
||
break;
|
||
case 'pir-template':
|
||
content = generatePIRTemplate();
|
||
break;
|
||
case 'csirt-notification':
|
||
content = generateCSIRTNotification();
|
||
break;
|
||
case 'recovery-dashboard':
|
||
content = generateRecoveryDashboard();
|
||
break;
|
||
case 'priority-matrix':
|
||
content = generatePriorityMatrix();
|
||
break;
|
||
case 'comm-templates':
|
||
content = generateCommTemplates();
|
||
break;
|
||
case 'pir-report':
|
||
content = generatePIRReport();
|
||
break;
|
||
case 'drill-calendar':
|
||
content = generateDrillCalendar();
|
||
break;
|
||
case 'playbook-ransomware':
|
||
content = generatePlaybookRansomware();
|
||
break;
|
||
case 'playbook-breach':
|
||
content = generatePlaybookBreach();
|
||
break;
|
||
case 'playbook-ddos':
|
||
content = generatePlaybookDDoS();
|
||
break;
|
||
case 'playbook-phishing':
|
||
content = generatePlaybookPhishing();
|
||
break;
|
||
case 'playbook-malware':
|
||
content = generatePlaybookMalware();
|
||
break;
|
||
case 'playbook-access':
|
||
content = generatePlaybookAccess();
|
||
break;
|
||
case 'exercise-report':
|
||
content = generateExerciseReport();
|
||
break;
|
||
}
|
||
|
||
body.innerHTML = content;
|
||
modal.classList.add('active');
|
||
}
|
||
|
||
function closeOutput() {
|
||
document.getElementById('outputModal').classList.remove('active');
|
||
}
|
||
|
||
function reportIncident() {
|
||
showOutput('triage-form');
|
||
}
|
||
|
||
// Generatori di contenuto per gli output
|
||
function generateTriageForm() {
|
||
return `
|
||
<div class="output-header">
|
||
<div class="output-title">🚨 Form Triage Incidente</div>
|
||
<div class="output-subtitle">Compilare entro 1 ora dalla segnalazione</div>
|
||
</div>
|
||
<div class="output-body">
|
||
<div class="output-section">
|
||
<div class="output-section-title">Informazioni Base</div>
|
||
<div class="output-field">
|
||
<div class="output-field-label">ID Incidente</div>
|
||
<div class="output-field-value">INC-2024-${Math.floor(Math.random() * 1000).toString().padStart(4, '0')}</div>
|
||
</div>
|
||
<div class="output-field">
|
||
<div class="output-field-label">Data/Ora Rilevazione</div>
|
||
<div class="output-field-value">${new Date().toLocaleString('it-IT')}</div>
|
||
</div>
|
||
<div class="output-field">
|
||
<div class="output-field-label">Segnalato da</div>
|
||
<div class="output-field-value">[Nome Cognome / Sistema Automatico]</div>
|
||
</div>
|
||
</div>
|
||
|
||
<div class="output-section">
|
||
<div class="output-section-title">Classificazione Iniziale</div>
|
||
<div class="output-field">
|
||
<div class="output-field-label">Severità</div>
|
||
<div class="output-field-value">
|
||
☐ P1 - Critico<br>
|
||
☐ P2 - Alto<br>
|
||
☐ P3 - Medio<br>
|
||
☐ P4 - Basso
|
||
</div>
|
||
</div>
|
||
<div class="output-field">
|
||
<div class="output-field-label">Classificazione NIS2</div>
|
||
<div class="output-field-value">
|
||
☐ IS-1: Impatto significativo servizi<br>
|
||
☐ IS-2: Impatto integrità/riservatezza dati<br>
|
||
☐ IS-3: Impatto supply chain<br>
|
||
☐ IS-4: Incidente ricorrente<br>
|
||
☐ Non significativo (no notifica CSIRT)
|
||
</div>
|
||
</div>
|
||
</div>
|
||
|
||
<div class="output-section">
|
||
<div class="output-section-title">Descrizione Incidente</div>
|
||
<div class="output-field">
|
||
<div class="output-field-label">Descrizione sintetica</div>
|
||
<div class="output-field-value">[Descrivere l'incidente in 2-3 frasi]</div>
|
||
</div>
|
||
<div class="output-field">
|
||
<div class="output-field-label">Sistemi/Servizi impattati</div>
|
||
<div class="output-field-value">[Elencare sistemi coinvolti]</div>
|
||
</div>
|
||
<div class="output-field">
|
||
<div class="output-field-label">Numero utenti impattati (stima)</div>
|
||
<div class="output-field-value">[Numero]</div>
|
||
</div>
|
||
</div>
|
||
|
||
<div class="output-section">
|
||
<div class="output-section-title">Azioni Immediate</div>
|
||
<div class="output-field">
|
||
<div class="output-field-label">Responsabile gestione</div>
|
||
<div class="output-field-value">[Nome Cognome]</div>
|
||
</div>
|
||
<div class="output-field">
|
||
<div class="output-field-label">Team attivato</div>
|
||
<div class="output-field-value">
|
||
☐ Incident Response Team<br>
|
||
☐ IT Operations<br>
|
||
☐ Security Team<br>
|
||
☐ Fornitori esterni<br>
|
||
☐ Management
|
||
</div>
|
||
</div>
|
||
<div class="output-field">
|
||
<div class="output-field-label">Notifica CSIRT richiesta</div>
|
||
<div class="output-field-value">☐ SI (entro 24h) ☐ NO</div>
|
||
</div>
|
||
</div>
|
||
</div>
|
||
<div class="output-actions">
|
||
<button class="btn btn-primary" onclick="alert('Form salvato e team notificato')">💾 Salva e Notifica Team</button>
|
||
<button class="btn" onclick="closeOutput()">Annulla</button>
|
||
</div>
|
||
`;
|
||
}
|
||
|
||
function generateContainmentChecklist() {
|
||
return `
|
||
<div class="output-header">
|
||
<div class="output-title">✅ Checklist Contenimento Incidente</div>
|
||
<div class="output-subtitle">Azioni immediate per limitare l'impatto</div>
|
||
</div>
|
||
<div class="output-body">
|
||
<div class="output-section">
|
||
<div class="output-section-title">Contenimento Immediato (0-2 ore)</div>
|
||
<div class="checklist">
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>Isolamento sistemi compromessi:</strong> Disconnettere dalla rete i sistemi identificati come compromessi</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>Snapshot forensi:</strong> Acquisire immagini memoria RAM e disco dei sistemi critici</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>Blocco account compromessi:</strong> Disabilitare immediatamente account utente sospetti</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>Firewall rules:</strong> Implementare regole per bloccare IP/domini malevoli identificati</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>Preservazione log:</strong> Assicurare che i log non vengano sovrascritti o eliminati</div>
|
||
</div>
|
||
</div>
|
||
</div>
|
||
|
||
<div class="output-section">
|
||
<div class="output-section-title">Contenimento a Breve Termine (2-8 ore)</div>
|
||
<div class="checklist">
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>Segmentazione rete:</strong> Implementare segmentazione per limitare movimento laterale</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>Verifica backup:</strong> Controllare integrità e disponibilità backup recenti</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>Scansione antimalware:</strong> Eseguire scansione completa su tutti i sistemi della rete</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>Reset credenziali critiche:</strong> Forzare cambio password account amministrativi</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>Monitoraggio intensificato:</strong> Attivare monitoraggio 24/7 su sistemi correlati</div>
|
||
</div>
|
||
</div>
|
||
</div>
|
||
|
||
<div class="output-section">
|
||
<div class="output-section-title">Contenimento a Lungo Termine (8-24 ore)</div>
|
||
<div class="checklist">
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>Controlli compensativi:</strong> Implementare controlli temporanei per servizi critici offline</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>Hardening configurazioni:</strong> Rafforzare configurazioni sicurezza su sistemi esposti</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>Threat hunting:</strong> Ricerca proattiva di IoC su tutta l'infrastruttura</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>Coordinamento fornitori:</strong> Informare e coordinare con fornitori critici impattati</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>Documentazione:</strong> Documentare tutte le azioni intraprese con timestamp</div>
|
||
</div>
|
||
</div>
|
||
</div>
|
||
|
||
<div class="output-section">
|
||
<div class="output-section-title">Verifica Efficacia Contenimento</div>
|
||
<div class="checklist">
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>Nessuna propagazione:</strong> Verificare che l'incidente non si stia propagando</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>Sistemi isolati stabili:</strong> Confermare che i sistemi isolati siano stabili</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>Nessun nuovo alert:</strong> Verificare assenza nuovi alert correlati</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>Perimetro definito:</strong> Confermare che il perimetro dell'incidente sia chiaro</div>
|
||
</div>
|
||
</div>
|
||
</div>
|
||
</div>
|
||
<div class="output-actions">
|
||
<button class="btn btn-primary" onclick="alert('Checklist salvata')">💾 Salva Checklist</button>
|
||
<button class="btn btn-interactive" onclick="alert('PDF generato')">📄 Esporta PDF</button>
|
||
<button class="btn" onclick="closeOutput()">Chiudi</button>
|
||
</div>
|
||
`;
|
||
}
|
||
|
||
function generateRecoveryPlan() {
|
||
return `
|
||
<div class="output-header">
|
||
<div class="output-title">📊 Piano di Ripristino</div>
|
||
<div class="output-subtitle">Strategia e timeline per il ripristino dei servizi</div>
|
||
</div>
|
||
<div class="output-body">
|
||
<div class="output-section">
|
||
<div class="output-section-title">Informazioni Incidente</div>
|
||
<div class="output-field">
|
||
<div class="output-field-label">ID Incidente</div>
|
||
<div class="output-field-value">INC-2024-0156</div>
|
||
</div>
|
||
<div class="output-field">
|
||
<div class="output-field-label">Stato Eradicazione</div>
|
||
<div class="output-field-value">✅ Completata e verificata il ${new Date().toLocaleDateString('it-IT')}</div>
|
||
</div>
|
||
</div>
|
||
|
||
<div class="output-section">
|
||
<div class="output-section-title">Priorità 1 - Servizi Essenziali (RTO: 4h)</div>
|
||
<table style="width: 100%; font-size: 12px; margin-top: 12px;">
|
||
<thead>
|
||
<tr style="background-color: var(--bg-tertiary);">
|
||
<th style="padding: 8px;">Servizio</th>
|
||
<th style="padding: 8px;">Strategia</th>
|
||
<th style="padding: 8px;">ETA</th>
|
||
<th style="padding: 8px;">Responsabile</th>
|
||
</tr>
|
||
</thead>
|
||
<tbody>
|
||
<tr>
|
||
<td style="padding: 8px;">ERP Sistema Produzione</td>
|
||
<td style="padding: 8px;">Ripristino da backup</td>
|
||
<td style="padding: 8px;">2h</td>
|
||
<td style="padding: 8px;">M. Rossi</td>
|
||
</tr>
|
||
<tr>
|
||
<td style="padding: 8px;">Firewall Perimetrale</td>
|
||
<td style="padding: 8px;">Riconfigurazione</td>
|
||
<td style="padding: 8px;">1h</td>
|
||
<td style="padding: 8px;">L. Bianchi</td>
|
||
</tr>
|
||
<tr>
|
||
<td style="padding: 8px;">Database Principale</td>
|
||
<td style="padding: 8px;">Failover a DR</td>
|
||
<td style="padding: 8px;">30min</td>
|
||
<td style="padding: 8px;">G. Verdi</td>
|
||
</tr>
|
||
</tbody>
|
||
</table>
|
||
</div>
|
||
|
||
<div class="output-section">
|
||
<div class="output-section-title">Priorità 2 - Servizi Importanti (RTO: 24h)</div>
|
||
<table style="width: 100%; font-size: 12px; margin-top: 12px;">
|
||
<thead>
|
||
<tr style="background-color: var(--bg-tertiary);">
|
||
<th style="padding: 8px;">Servizio</th>
|
||
<th style="padding: 8px;">Strategia</th>
|
||
<th style="padding: 8px;">ETA</th>
|
||
<th style="padding: 8px;">Responsabile</th>
|
||
</tr>
|
||
</thead>
|
||
<tbody>
|
||
<tr>
|
||
<td style="padding: 8px;">CRM Salesforce</td>
|
||
<td style="padding: 8px;">Verifica integrità</td>
|
||
<td style="padding: 8px;">4h</td>
|
||
<td style="padding: 8px;">A. Neri</td>
|
||
</tr>
|
||
<tr>
|
||
<td style="padding: 8px;">Email Server</td>
|
||
<td style="padding: 8px;">Rebuild da zero</td>
|
||
<td style="padding: 8px;">8h</td>
|
||
<td style="padding: 8px;">P. Gialli</td>
|
||
</tr>
|
||
</tbody>
|
||
</table>
|
||
</div>
|
||
|
||
<div class="output-section">
|
||
<div class="output-section-title">Timeline Ripristino</div>
|
||
<div style="font-size: 13px; line-height: 2;">
|
||
<strong>T+0h:</strong> Inizio ripristino Priorità 1<br>
|
||
<strong>T+1h:</strong> Firewall operativo, Database failover completato<br>
|
||
<strong>T+2h:</strong> ERP ripristinato da backup<br>
|
||
<strong>T+4h:</strong> Tutti servizi P1 operativi, inizio P2<br>
|
||
<strong>T+8h:</strong> Email server ripristinato<br>
|
||
<strong>T+12h:</strong> Tutti servizi P2 operativi<br>
|
||
<strong>T+24h:</strong> Ripristino completo, inizio monitoraggio intensivo
|
||
</div>
|
||
</div>
|
||
|
||
<div class="output-section">
|
||
<div class="output-section-title">Criteri di Successo</div>
|
||
<div class="checklist">
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text">Tutti i servizi P1 operativi entro RTO di 4h</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text">RPO rispettato: perdita dati < 1h</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text">Nessuna ricomparsa di IoC nelle prime 72h</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text">Performance dei servizi entro parametri normali</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text">Stakeholder informati e soddisfatti del ripristino</div>
|
||
</div>
|
||
</div>
|
||
</div>
|
||
|
||
<div class="output-section">
|
||
<div class="output-section-title">Piano di Rollback</div>
|
||
<div class="output-field">
|
||
<div class="output-field-label">Trigger per Rollback</div>
|
||
<div class="output-field-value">
|
||
• Ricomparsa indicatori di compromissione<br>
|
||
• Fallimento test di validazione<br>
|
||
• Nuove anomalie di sicurezza<br>
|
||
• Impatto operativo peggiore dello stato pre-ripristino
|
||
</div>
|
||
</div>
|
||
<div class="output-field">
|
||
<div class="output-field-label">Procedura Rollback</div>
|
||
<div class="output-field-value">
|
||
1. Stop immediato operazioni ripristino<br>
|
||
2. Isolamento sistemi problematici<br>
|
||
3. Analisi causa del fallimento<br>
|
||
4. Decisione go/no-go con management<br>
|
||
5. Eventuale ritorno a stato precedente
|
||
</div>
|
||
</div>
|
||
</div>
|
||
</div>
|
||
<div class="output-actions">
|
||
<button class="btn btn-primary" onclick="alert('Piano di ripristino approvato e avviato')">✅ Approva e Avvia</button>
|
||
<button class="btn btn-interactive" onclick="alert('PDF generato e inviato al team')">📄 Esporta PDF</button>
|
||
<button class="btn" onclick="closeOutput()">Chiudi</button>
|
||
</div>
|
||
`;
|
||
}
|
||
|
||
function generateCSIRTNotification() {
|
||
const subjectType = sessionStorage.getItem('nis2_subject_type');
|
||
return `
|
||
<div class="output-header">
|
||
<div class="output-title">📤 Notifica al CSIRT Italia</div>
|
||
<div class="output-subtitle">Generazione notifica secondo Art. 23 D.Lgs. 138/2024</div>
|
||
</div>
|
||
<div class="output-body">
|
||
<div class="output-section">
|
||
<div class="output-section-title">Tipo Notifica</div>
|
||
<div class="output-field">
|
||
<div class="output-field-label">Seleziona tipo notifica</div>
|
||
<div class="output-field-value">
|
||
<select style="width: 100%; padding: 8px; background-color: var(--bg-tertiary); border: 1px solid var(--border-color); color: var(--text-primary); border-radius: 4px;">
|
||
<option>Preallarme (entro 24h)</option>
|
||
<option>Notifica Completa (entro 72h)</option>
|
||
<option>Relazione Finale (entro 1 mese)</option>
|
||
<option>Aggiornamento Intermedio</option>
|
||
</select>
|
||
</div>
|
||
</div>
|
||
</div>
|
||
|
||
<div class="output-section">
|
||
<div class="output-section-title">Dati Soggetto Notificante</div>
|
||
<div class="output-field">
|
||
<div class="output-field-label">Ragione Sociale</div>
|
||
<div class="output-field-value">[Nome Organizzazione S.p.A.]</div>
|
||
</div>
|
||
<div class="output-field">
|
||
<div class="output-field-label">Codice Fiscale / P.IVA</div>
|
||
<div class="output-field-value">[12345678901]</div>
|
||
</div>
|
||
<div class="output-field">
|
||
<div class="output-field-label">Tipologia Soggetto</div>
|
||
<div class="output-field-value">${subjectType === 'essential' ? 'ESSENZIALE' : 'IMPORTANTE'}</div>
|
||
</div>
|
||
<div class="output-field">
|
||
<div class="output-field-label">Settore</div>
|
||
<div class="output-field-value">
|
||
<select style="width: 100%; padding: 8px; background-color: var(--bg-tertiary); border: 1px solid var(--border-color); color: var(--text-primary); border-radius: 4px;">
|
||
<option>Energia</option>
|
||
<option>Trasporti</option>
|
||
<option>Bancario</option>
|
||
<option>Sanitario</option>
|
||
<option>Infrastrutture digitali</option>
|
||
<option>Pubblica Amministrazione</option>
|
||
<option>Altro</option>
|
||
</select>
|
||
</div>
|
||
</div>
|
||
</div>
|
||
|
||
<div class="output-section">
|
||
<div class="output-section-title">Dati Incidente</div>
|
||
<div class="output-field">
|
||
<div class="output-field-label">ID Incidente Interno</div>
|
||
<div class="output-field-value">INC-2024-${Math.floor(Math.random() * 1000).toString().padStart(4, '0')}</div>
|
||
</div>
|
||
<div class="output-field">
|
||
<div class="output-field-label">Data/Ora Rilevazione</div>
|
||
<div class="output-field-value">${new Date().toLocaleString('it-IT')}</div>
|
||
</div>
|
||
<div class="output-field">
|
||
<div class="output-field-label">Classificazione NIS2</div>
|
||
<div class="output-field-value">
|
||
<select style="width: 100%; padding: 8px; background-color: var(--bg-tertiary); border: 1px solid var(--border-color); color: var(--text-primary); border-radius: 4px;">
|
||
<option>IS-1: Impatto significativo sui servizi</option>
|
||
<option>IS-2: Impatto su integrità/riservatezza dati</option>
|
||
<option>IS-3: Impatto su altri soggetti/supply chain</option>
|
||
<option>IS-4: Incidente ricorrente con impatto cumulativo</option>
|
||
</select>
|
||
</div>
|
||
</div>
|
||
<div class="output-field">
|
||
<div class="output-field-label">Incidente ancora in corso</div>
|
||
<div class="output-field-value">
|
||
<select style="width: 100%; padding: 8px; background-color: var(--bg-tertiary); border: 1px solid var(--border-color); color: var(--text-primary); border-radius: 4px;">
|
||
<option>SI - In corso</option>
|
||
<option>NO - Risolto</option>
|
||
<option>PARZIALMENTE - In fase di ripristino</option>
|
||
</select>
|
||
</div>
|
||
</div>
|
||
</div>
|
||
|
||
<div class="output-section">
|
||
<div class="output-section-title">Descrizione Incidente</div>
|
||
<div class="output-field">
|
||
<div class="output-field-label">Descrizione sintetica</div>
|
||
<div class="output-field-value">
|
||
<textarea style="width: 100%; min-height: 80px; padding: 8px; background-color: var(--bg-tertiary); border: 1px solid var(--border-color); color: var(--text-primary); border-radius: 4px; font-family: inherit;" placeholder="Descrivere l'incidente in modo chiaro e conciso..."></textarea>
|
||
</div>
|
||
</div>
|
||
<div class="output-field">
|
||
<div class="output-field-label">Tipologia di attacco/incidente</div>
|
||
<div class="output-field-value">
|
||
<select style="width: 100%; padding: 8px; background-color: var(--bg-tertiary); border: 1px solid var(--border-color); color: var(--text-primary); border-radius: 4px;">
|
||
<option>Ransomware</option>
|
||
<option>Data Breach</option>
|
||
<option>DDoS</option>
|
||
<option>Phishing/BEC</option>
|
||
<option>Malware</option>
|
||
<option>Accesso non autorizzato</option>
|
||
<option>Vulnerabilità sfruttata</option>
|
||
<option>Altro</option>
|
||
</select>
|
||
</div>
|
||
</div>
|
||
</div>
|
||
|
||
<div class="output-section">
|
||
<div class="output-section-title">Impatto</div>
|
||
<div class="output-field">
|
||
<div class="output-field-label">Sistemi/Servizi impattati</div>
|
||
<div class="output-field-value">
|
||
<textarea style="width: 100%; min-height: 60px; padding: 8px; background-color: var(--bg-tertiary); border: 1px solid var(--border-color); color: var(--text-primary); border-radius: 4px; font-family: inherit;" placeholder="Elencare i sistemi e servizi coinvolti..."></textarea>
|
||
</div>
|
||
</div>
|
||
<div class="output-field">
|
||
<div class="output-field-label">Numero utenti/clienti impattati (stima)</div>
|
||
<div class="output-field-value">
|
||
<input type="number" style="width: 100%; padding: 8px; background-color: var(--bg-tertiary); border: 1px solid var(--border-color); color: var(--text-primary); border-radius: 4px;" placeholder="Numero stimato">
|
||
</div>
|
||
</div>
|
||
<div class="output-field">
|
||
<div class="output-field-label">Dati personali compromessi</div>
|
||
<div class="output-field-value">
|
||
<select style="width: 100%; padding: 8px; background-color: var(--bg-tertiary); border: 1px solid var(--border-color); color: var(--text-primary); border-radius: 4px;">
|
||
<option>NO</option>
|
||
<option>SI - Dati comuni</option>
|
||
<option>SI - Dati particolari (art. 9 GDPR)</option>
|
||
<option>SI - Dati giudiziari</option>
|
||
<option>In valutazione</option>
|
||
</select>
|
||
</div>
|
||
</div>
|
||
<div class="output-field">
|
||
<div class="output-field-label">Impatto su altri soggetti NIS2</div>
|
||
<div class="output-field-value">
|
||
<select style="width: 100%; padding: 8px; background-color: var(--bg-tertiary); border: 1px solid var(--border-color); color: var(--text-primary); border-radius: 4px;">
|
||
<option>NO</option>
|
||
<option>SI - Specificare nei dettagli</option>
|
||
<option>POTENZIALE - In valutazione</option>
|
||
</select>
|
||
</div>
|
||
</div>
|
||
<div class="output-field">
|
||
<div class="output-field-label">Impatto transfrontaliero</div>
|
||
<div class="output-field-value">
|
||
<select style="width: 100%; padding: 8px; background-color: var(--bg-tertiary); border: 1px solid var(--border-color); color: var(--text-primary); border-radius: 4px;">
|
||
<option>NO</option>
|
||
<option>SI - Specificare paesi coinvolti</option>
|
||
</select>
|
||
</div>
|
||
</div>
|
||
</div>
|
||
|
||
<div class="output-section">
|
||
<div class="output-section-title">Azioni Intraprese</div>
|
||
<div class="output-field">
|
||
<div class="output-field-label">Misure di contenimento implementate</div>
|
||
<div class="output-field-value">
|
||
<textarea style="width: 100%; min-height: 80px; padding: 8px; background-color: var(--bg-tertiary); border: 1px solid var(--border-color); color: var(--text-primary); border-radius: 4px; font-family: inherit;" placeholder="Descrivere le azioni di contenimento..."></textarea>
|
||
</div>
|
||
</div>
|
||
<div class="output-field">
|
||
<div class="output-field-label">Indicatori di Compromissione (IoC)</div>
|
||
<div class="output-field-value">
|
||
<textarea style="width: 100%; min-height: 60px; padding: 8px; background-color: var(--bg-tertiary); border: 1px solid var(--border-color); color: var(--text-primary); border-radius: 4px; font-family: inherit;" placeholder="IP, hash, domini malevoli identificati..."></textarea>
|
||
</div>
|
||
</div>
|
||
</div>
|
||
|
||
<div class="output-section">
|
||
<div class="output-section-title">Referente per Comunicazioni</div>
|
||
<div class="output-field">
|
||
<div class="output-field-label">Nome e Cognome</div>
|
||
<div class="output-field-value">[Nome Cognome - CISO]</div>
|
||
</div>
|
||
<div class="output-field">
|
||
<div class="output-field-label">Email</div>
|
||
<div class="output-field-value">[ciso@azienda.it]</div>
|
||
</div>
|
||
<div class="output-field">
|
||
<div class="output-field-label">Telefono</div>
|
||
<div class="output-field-value">[+39 XXX XXXXXXX]</div>
|
||
</div>
|
||
</div>
|
||
|
||
<div class="info-box warning-box" style="margin-top: 16px;">
|
||
<div class="info-box-title">⚠️ Tempistiche di Notifica</div>
|
||
<div class="info-box-content">
|
||
<strong>Preallarme:</strong> Entro 24 ore dalla rilevazione<br>
|
||
<strong>Notifica completa:</strong> Entro 72 ore dalla rilevazione<br>
|
||
<strong>Relazione finale:</strong> Entro 1 mese dalla risoluzione<br>
|
||
<br>
|
||
La notifica deve essere inviata tramite il <strong>Portale ACN</strong> (https://csirt.acn.gov.it)
|
||
</div>
|
||
</div>
|
||
</div>
|
||
<div class="output-actions">
|
||
<button class="btn btn-danger" onclick="alert('Notifica inviata al CSIRT Italia via Portale ACN')">📤 Invia Notifica CSIRT</button>
|
||
<button class="btn btn-interactive" onclick="alert('Bozza salvata')">💾 Salva Bozza</button>
|
||
<button class="btn" onclick="alert('PDF generato')">📄 Esporta PDF</button>
|
||
<button class="btn" onclick="closeOutput()">Chiudi</button>
|
||
</div>
|
||
`;
|
||
}
|
||
|
||
function generatePIRTemplate() {
|
||
return `
|
||
<div class="output-header">
|
||
<div class="output-title">📝 Template Post-Incident Review</div>
|
||
<div class="output-subtitle">Analisi completa delle lezioni apprese</div>
|
||
</div>
|
||
<div class="output-body">
|
||
<div class="output-section">
|
||
<div class="output-section-title">Executive Summary</div>
|
||
<div class="output-field">
|
||
<div class="output-field-value">
|
||
<textarea style="width: 100%; min-height: 100px; padding: 8px; background-color: var(--bg-tertiary); border: 1px solid var(--border-color); color: var(--text-primary); border-radius: 4px; font-family: inherit;" placeholder="Sintesi esecutiva dell'incidente per il management (max 300 parole)..."></textarea>
|
||
</div>
|
||
</div>
|
||
</div>
|
||
|
||
<div class="output-section">
|
||
<div class="output-section-title">1. Incident Overview</div>
|
||
<div class="output-field">
|
||
<div class="output-field-label">ID Incidente</div>
|
||
<div class="output-field-value">INC-2024-XXXX</div>
|
||
</div>
|
||
<div class="output-field">
|
||
<div class="output-field-label">Classificazione</div>
|
||
<div class="output-field-value">IS-X / Severità: PX</div>
|
||
</div>
|
||
<div class="output-field">
|
||
<div class="output-field-label">Data Rilevazione</div>
|
||
<div class="output-field-value">[GG/MM/AAAA HH:MM]</div>
|
||
</div>
|
||
<div class="output-field">
|
||
<div class="output-field-label">Data Risoluzione</div>
|
||
<div class="output-field-value">[GG/MM/AAAA HH:MM]</div>
|
||
</div>
|
||
<div class="output-field">
|
||
<div class="output-field-label">Durata Totale</div>
|
||
<div class="output-field-value">[XX ore YY minuti]</div>
|
||
</div>
|
||
</div>
|
||
|
||
<div class="output-section">
|
||
<div class="output-section-title">2. Timeline Dettagliata</div>
|
||
<div class="output-field">
|
||
<div class="output-field-value">
|
||
<table style="width: 100%; font-size: 12px;">
|
||
<thead>
|
||
<tr style="background-color: var(--bg-tertiary);">
|
||
<th style="padding: 8px;">Data/Ora</th>
|
||
<th style="padding: 8px;">Evento</th>
|
||
<th style="padding: 8px;">Azione Intrapresa</th>
|
||
<th style="padding: 8px;">Responsabile</th>
|
||
</tr>
|
||
</thead>
|
||
<tbody>
|
||
<tr>
|
||
<td style="padding: 8px;">[timestamp]</td>
|
||
<td style="padding: 8px;">[descrizione evento]</td>
|
||
<td style="padding: 8px;">[azione]</td>
|
||
<td style="padding: 8px;">[nome]</td>
|
||
</tr>
|
||
<tr>
|
||
<td style="padding: 8px;" colspan="4">[Aggiungere righe per ogni evento significativo]</td>
|
||
</tr>
|
||
</tbody>
|
||
</table>
|
||
</div>
|
||
</div>
|
||
</div>
|
||
|
||
<div class="output-section">
|
||
<div class="output-section-title">3. Root Cause Analysis</div>
|
||
<div class="output-field">
|
||
<div class="output-field-label">Causa Radice Primaria</div>
|
||
<div class="output-field-value">
|
||
<textarea style="width: 100%; min-height: 60px; padding: 8px; background-color: var(--bg-tertiary); border: 1px solid var(--border-color); color: var(--text-primary); border-radius: 4px; font-family: inherit;" placeholder="Identificare la causa principale..."></textarea>
|
||
</div>
|
||
</div>
|
||
<div class="output-field">
|
||
<div class="output-field-label">Fattori Contributivi</div>
|
||
<div class="output-field-value">
|
||
<textarea style="width: 100%; min-height: 80px; padding: 8px; background-color: var(--bg-tertiary); border: 1px solid var(--border-color); color: var(--text-primary); border-radius: 4px; font-family: inherit;" placeholder="Elencare tutti i fattori che hanno contribuito..."></textarea>
|
||
</div>
|
||
</div>
|
||
<div class="output-field">
|
||
<div class="output-field-label">Vulnerabilità Sfruttate</div>
|
||
<div class="output-field-value">
|
||
<textarea style="width: 100%; min-height: 60px; padding: 8px; background-color: var(--bg-tertiary); border: 1px solid var(--border-color); color: var(--text-primary); border-radius: 4px; font-family: inherit;" placeholder="Descrivere le vulnerabilità..."></textarea>
|
||
</div>
|
||
</div>
|
||
</div>
|
||
|
||
<div class="output-section">
|
||
<div class="output-section-title">4. Impact Assessment</div>
|
||
<div class="output-field">
|
||
<div class="output-field-label">Impatto Operativo</div>
|
||
<div class="output-field-value">
|
||
• Servizi interrotti: [elenco]<br>
|
||
• Durata interruzione: [ore]<br>
|
||
• Utenti impattati: [numero]<br>
|
||
• Produttività persa: [stima]
|
||
</div>
|
||
</div>
|
||
<div class="output-field">
|
||
<div class="output-field-label">Impatto Finanziario</div>
|
||
<div class="output-field-value">
|
||
• Costi diretti (risposta): € [importo]<br>
|
||
• Costi indiretti (mancato fatturato): € [importo]<br>
|
||
• Costi ripristino: € [importo]<br>
|
||
• <strong>TOTALE: € [importo]</strong>
|
||
</div>
|
||
</div>
|
||
<div class="output-field">
|
||
<div class="output-field-label">Impatto Reputazionale</div>
|
||
<div class="output-field-value">
|
||
<textarea style="width: 100%; min-height: 60px; padding: 8px; background-color: var(--bg-tertiary); border: 1px solid var(--border-color); color: var(--text-primary); border-radius: 4px; font-family: inherit;" placeholder="Valutare l'impatto su reputazione e brand..."></textarea>
|
||
</div>
|
||
</div>
|
||
<div class="output-field">
|
||
<div class="output-field-label">Impatto su Dati</div>
|
||
<div class="output-field-value">
|
||
• Dati compromessi: [SI/NO]<br>
|
||
• Tipologia: [descrizione]<br>
|
||
• Volume: [quantità]<br>
|
||
• Notifica GPDP: [SI/NO]
|
||
</div>
|
||
</div>
|
||
</div>
|
||
|
||
<div class="output-section">
|
||
<div class="output-section-title">5. Response Evaluation</div>
|
||
<div class="output-field">
|
||
<div class="output-field-label">Cosa ha funzionato bene (Strengths)</div>
|
||
<div class="output-field-value">
|
||
<textarea style="width: 100%; min-height: 80px; padding: 8px; background-color: var(--bg-tertiary); border: 1px solid var(--border-color); color: var(--text-primary); border-radius: 4px; font-family: inherit;" placeholder="Elencare gli aspetti positivi della risposta..."></textarea>
|
||
</div>
|
||
</div>
|
||
<div class="output-field">
|
||
<div class="output-field-label">Cosa non ha funzionato (Weaknesses)</div>
|
||
<div class="output-field-value">
|
||
<textarea style="width: 100%; min-height: 80px; padding: 8px; background-color: var(--bg-tertiary); border: 1px solid var(--border-color); color: var(--text-primary); border-radius: 4px; font-family: inherit;" placeholder="Identificare le criticità e problemi riscontrati..."></textarea>
|
||
</div>
|
||
</div>
|
||
<div class="output-field">
|
||
<div class="output-field-label">Tempi di Risposta</div>
|
||
<div class="output-field-value">
|
||
• Tempo rilevazione → triage: [minuti]<br>
|
||
• Tempo triage → contenimento: [minuti]<br>
|
||
• Tempo contenimento → eradicazione: [ore]<br>
|
||
• Tempo eradicazione → ripristino: [ore]<br>
|
||
• <strong>Tempo totale risposta: [ore]</strong>
|
||
</div>
|
||
</div>
|
||
</div>
|
||
|
||
<div class="output-section">
|
||
<div class="output-section-title">6. Gap Analysis</div>
|
||
<div class="output-field">
|
||
<div class="output-field-value">
|
||
<table style="width: 100%; font-size: 12px;">
|
||
<thead>
|
||
<tr style="background-color: var(--bg-tertiary);">
|
||
<th style="padding: 8px;">Categoria</th>
|
||
<th style="padding: 8px;">Gap Identificato</th>
|
||
<th style="padding: 8px;">Impatto</th>
|
||
</tr>
|
||
</thead>
|
||
<tbody>
|
||
<tr>
|
||
<td style="padding: 8px;">Tecnologico</td>
|
||
<td style="padding: 8px;">[descrizione gap]</td>
|
||
<td style="padding: 8px;">[Alto/Medio/Basso]</td>
|
||
</tr>
|
||
<tr>
|
||
<td style="padding: 8px;">Procedurale</td>
|
||
<td style="padding: 8px;">[descrizione gap]</td>
|
||
<td style="padding: 8px;">[Alto/Medio/Basso]</td>
|
||
</tr>
|
||
<tr>
|
||
<td style="padding: 8px;">Organizzativo</td>
|
||
<td style="padding: 8px;">[descrizione gap]</td>
|
||
<td style="padding: 8px;">[Alto/Medio/Basso]</td>
|
||
</tr>
|
||
<tr>
|
||
<td style="padding: 8px;">Formativo</td>
|
||
<td style="padding: 8px;">[descrizione gap]</td>
|
||
<td style="padding: 8px;">[Alto/Medio/Basso]</td>
|
||
</tr>
|
||
</tbody>
|
||
</table>
|
||
</div>
|
||
</div>
|
||
</div>
|
||
|
||
<div class="output-section">
|
||
<div class="output-section-title">7. Recommendations & Action Plan</div>
|
||
<div class="output-field">
|
||
<div class="output-field-value">
|
||
<table style="width: 100%; font-size: 12px;">
|
||
<thead>
|
||
<tr style="background-color: var(--bg-tertiary);">
|
||
<th style="padding: 8px;">ID</th>
|
||
<th style="padding: 8px;">Azione Correttiva</th>
|
||
<th style="padding: 8px;">Priorità</th>
|
||
<th style="padding: 8px;">Responsabile</th>
|
||
<th style="padding: 8px;">Deadline</th>
|
||
<th style="padding: 8px;">Stato</th>
|
||
</tr>
|
||
</thead>
|
||
<tbody>
|
||
<tr>
|
||
<td style="padding: 8px;">ACT-001</td>
|
||
<td style="padding: 8px;">[descrizione azione]</td>
|
||
<td style="padding: 8px;">Alta</td>
|
||
<td style="padding: 8px;">[nome]</td>
|
||
<td style="padding: 8px;">[data]</td>
|
||
<td style="padding: 8px;">Aperto</td>
|
||
</tr>
|
||
<tr>
|
||
<td style="padding: 8px;" colspan="6">[Aggiungere tutte le azioni identificate]</td>
|
||
</tr>
|
||
</tbody>
|
||
</table>
|
||
</div>
|
||
</div>
|
||
</div>
|
||
|
||
<div class="output-section">
|
||
<div class="output-section-title">8. Lessons Learned</div>
|
||
<div class="output-field">
|
||
<div class="output-field-value">
|
||
<textarea style="width: 100%; min-height: 120px; padding: 8px; background-color: var(--bg-tertiary); border: 1px solid var(--border-color); color: var(--text-primary); border-radius: 4px; font-family: inherit;" placeholder="Riassumere le principali lezioni apprese da questo incidente..."></textarea>
|
||
</div>
|
||
</div>
|
||
</div>
|
||
|
||
<div class="output-section">
|
||
<div class="output-section-title">Approvazioni</div>
|
||
<div class="output-field">
|
||
<div class="output-field-label">Preparato da</div>
|
||
<div class="output-field-value">[Nome] - [Ruolo] - [Data]</div>
|
||
</div>
|
||
<div class="output-field">
|
||
<div class="output-field-label">Revisionato da</div>
|
||
<div class="output-field-value">[Nome] - [CISO] - [Data]</div>
|
||
</div>
|
||
<div class="output-field">
|
||
<div class="output-field-label">Approvato da</div>
|
||
<div class="output-field-value">[Nome] - [CEO/CIO] - [Data]</div>
|
||
</div>
|
||
</div>
|
||
</div>
|
||
<div class="output-actions">
|
||
<button class="btn btn-primary" onclick="alert('Report PIR salvato')">💾 Salva Report</button>
|
||
<button class="btn btn-interactive" onclick="alert('PDF generato')">📄 Genera PDF</button>
|
||
<button class="btn" onclick="alert('Report inviato al management')">📧 Invia a Management</button>
|
||
<button class="btn" onclick="closeOutput()">Chiudi</button>
|
||
</div>
|
||
`;
|
||
}
|
||
|
||
function generateRecoveryDashboard() {
|
||
return `
|
||
<div class="output-header">
|
||
<div class="output-title">📊 Dashboard Ripristino in Tempo Reale</div>
|
||
<div class="output-subtitle">Monitoraggio stato ripristino servizi</div>
|
||
</div>
|
||
<div class="output-body">
|
||
<div class="output-section">
|
||
<div class="output-section-title">Stato Generale Ripristino</div>
|
||
<div style="display: grid; grid-template-columns: repeat(3, 1fr); gap: 16px;">
|
||
<div style="background-color: var(--bg-tertiary); padding: 16px; border-radius: 6px; text-align: center;">
|
||
<div style="font-size: 32px; font-weight: 700; color: var(--success);">67%</div>
|
||
<div style="font-size: 12px; color: var(--text-secondary); margin-top: 8px;">COMPLETAMENTO</div>
|
||
</div>
|
||
<div style="background-color: var(--bg-tertiary); padding: 16px; border-radius: 6px; text-align: center;">
|
||
<div style="font-size: 32px; font-weight: 700; color: var(--accent-primary);">8/12</div>
|
||
<div style="font-size: 12px; color: var(--text-secondary); margin-top: 8px;">SERVIZI RIPRISTINATI</div>
|
||
</div>
|
||
<div style="background-color: var(--bg-tertiary); padding: 16px; border-radius: 6px; text-align: center;">
|
||
<div style="font-size: 32px; font-weight: 700; color: var(--warning);">3.2h</div>
|
||
<div style="font-size: 12px; color: var(--text-secondary); margin-top: 8px;">ETA COMPLETAMENTO</div>
|
||
</div>
|
||
</div>
|
||
</div>
|
||
|
||
<div class="output-section">
|
||
<div class="output-section-title">Servizi in Ripristino</div>
|
||
<table style="width: 100%; font-size: 12px;">
|
||
<thead>
|
||
<tr style="background-color: var(--bg-tertiary);">
|
||
<th style="padding: 8px;">Servizio</th>
|
||
<th style="padding: 8px;">Priorità</th>
|
||
<th style="padding: 8px;">Stato</th>
|
||
<th style="padding: 8px;">Progresso</th>
|
||
<th style="padding: 8px;">ETA</th>
|
||
<th style="padding: 8px;">Responsabile</th>
|
||
</tr>
|
||
</thead>
|
||
<tbody>
|
||
<tr>
|
||
<td style="padding: 8px;">ERP Produzione</td>
|
||
<td style="padding: 8px;"><span style="background-color: rgba(248, 81, 73, 0.2); color: var(--danger); padding: 2px 6px; border-radius: 3px; font-size: 10px;">P1</span></td>
|
||
<td style="padding: 8px;"><span style="color: var(--success);">✅ Completato</span></td>
|
||
<td style="padding: 8px;">
|
||
<div style="background-color: var(--bg-secondary); height: 8px; border-radius: 4px; overflow: hidden;">
|
||
<div style="background-color: var(--success); width: 100%; height: 100%;"></div>
|
||
</div>
|
||
</td>
|
||
<td style="padding: 8px;">-</td>
|
||
<td style="padding: 8px;">M. Rossi</td>
|
||
</tr>
|
||
<tr>
|
||
<td style="padding: 8px;">Database Principale</td>
|
||
<td style="padding: 8px;"><span style="background-color: rgba(248, 81, 73, 0.2); color: var(--danger); padding: 2px 6px; border-radius: 3px; font-size: 10px;">P1</span></td>
|
||
<td style="padding: 8px;"><span style="color: var(--warning);">🔄 In corso</span></td>
|
||
<td style="padding: 8px;">
|
||
<div style="background-color: var(--bg-secondary); height: 8px; border-radius: 4px; overflow: hidden;">
|
||
<div style="background-color: var(--warning); width: 75%; height: 100%;"></div>
|
||
</div>
|
||
</td>
|
||
<td style="padding: 8px;">45 min</td>
|
||
<td style="padding: 8px;">G. Verdi</td>
|
||
</tr>
|
||
<tr>
|
||
<td style="padding: 8px;">Email Server</td>
|
||
<td style="padding: 8px;"><span style="background-color: rgba(210, 153, 34, 0.2); color: var(--warning); padding: 2px 6px; border-radius: 3px; font-size: 10px;">P2</span></td>
|
||
<td style="padding: 8px;"><span style="color: var(--warning);">🔄 In corso</span></td>
|
||
<td style="padding: 8px;">
|
||
<div style="background-color: var(--bg-secondary); height: 8px; border-radius: 4px; overflow: hidden;">
|
||
<div style="background-color: var(--warning); width: 40%; height: 100%;"></div>
|
||
</div>
|
||
</td>
|
||
<td style="padding: 8px;">2.5h</td>
|
||
<td style="padding: 8px;">P. Gialli</td>
|
||
</tr>
|
||
<tr>
|
||
<td style="padding: 8px;">CRM Salesforce</td>
|
||
<td style="padding: 8px;"><span style="background-color: rgba(210, 153, 34, 0.2); color: var(--warning); padding: 2px 6px; border-radius: 3px; font-size: 10px;">P2</span></td>
|
||
<td style="padding: 8px;"><span style="color: var(--text-secondary);">⏳ In attesa</span></td>
|
||
<td style="padding: 8px;">
|
||
<div style="background-color: var(--bg-secondary); height: 8px; border-radius: 4px; overflow: hidden;">
|
||
<div style="background-color: var(--accent-primary); width: 10%; height: 100%;"></div>
|
||
</div>
|
||
</td>
|
||
<td style="padding: 8px;">4h</td>
|
||
<td style="padding: 8px;">A. Neri</td>
|
||
</tr>
|
||
</tbody>
|
||
</table>
|
||
</div>
|
||
|
||
<div class="output-section">
|
||
<div class="output-section-title">Timeline Ripristino</div>
|
||
<div style="font-size: 13px; line-height: 2.5;">
|
||
<div style="display: flex; align-items: center; gap: 12px;">
|
||
<span style="color: var(--success);">✅</span>
|
||
<strong>T+0h (14:00):</strong> Avvio ripristino Priorità 1
|
||
</div>
|
||
<div style="display: flex; align-items: center; gap: 12px;">
|
||
<span style="color: var(--success);">✅</span>
|
||
<strong>T+1h (15:00):</strong> Firewall ripristinato e operativo
|
||
</div>
|
||
<div style="display: flex; align-items: center; gap: 12px;">
|
||
<span style="color: var(--success);">✅</span>
|
||
<strong>T+2h (16:00):</strong> ERP ripristinato da backup
|
||
</div>
|
||
<div style="display: flex; align-items: center; gap: 12px;">
|
||
<span style="color: var(--warning);">🔄</span>
|
||
<strong>T+3h (17:00):</strong> Database in fase di ripristino (75% completato)
|
||
</div>
|
||
<div style="display: flex; align-items: center; gap: 12px;">
|
||
<span style="color: var(--text-secondary);">⏳</span>
|
||
<strong>T+4h (18:00 EST):</strong> Completamento Database, avvio P2
|
||
</div>
|
||
<div style="display: flex; align-items: center; gap: 12px;">
|
||
<span style="color: var(--text-secondary);">⏳</span>
|
||
<strong>T+6h (20:00 EST):</strong> Email Server operativo
|
||
</div>
|
||
</div>
|
||
</div>
|
||
|
||
<div class="output-section">
|
||
<div class="output-section-title">Alert e Problemi</div>
|
||
<div class="info-box warning-box">
|
||
<div class="info-box-title">⚠️ Attenzione</div>
|
||
<div class="info-box-content">
|
||
<strong>Database Principale:</strong> Rilevato errore di integrità su 3 tabelle secondarie. In corso verifica e correzione. Impatto stimato: +30 minuti su ETA.
|
||
</div>
|
||
</div>
|
||
<div class="info-box" style="margin-top: 12px;">
|
||
<div class="info-box-title">ℹ️ Informazione</div>
|
||
<div class="info-box-content">
|
||
<strong>Monitoraggio:</strong> Tutti i servizi ripristinati sono sotto monitoraggio intensivo 24/7. Nessuna anomalia rilevata finora.
|
||
</div>
|
||
</div>
|
||
</div>
|
||
|
||
<div class="output-section">
|
||
<div class="output-section-title">Team Attivo</div>
|
||
<div style="display: grid; grid-template-columns: repeat(2, 1fr); gap: 12px;">
|
||
<div style="background-color: var(--bg-tertiary); padding: 12px; border-radius: 4px;">
|
||
<strong>M. Rossi</strong> - ERP Lead<br>
|
||
<span style="font-size: 11px; color: var(--text-secondary);">📞 +39 XXX XXX 001 | ✅ Disponibile</span>
|
||
</div>
|
||
<div style="background-color: var(--bg-tertiary); padding: 12px; border-radius: 4px;">
|
||
<strong>G. Verdi</strong> - Database Admin<br>
|
||
<span style="font-size: 11px; color: var(--text-secondary);">📞 +39 XXX XXX 002 | 🔄 Operativo</span>
|
||
</div>
|
||
<div style="background-color: var(--bg-tertiary); padding: 12px; border-radius: 4px;">
|
||
<strong>P. Gialli</strong> - Email Admin<br>
|
||
<span style="font-size: 11px; color: var(--text-secondary);">📞 +39 XXX XXX 003 | 🔄 Operativo</span>
|
||
</div>
|
||
<div style="background-color: var(--bg-tertiary); padding: 12px; border-radius: 4px;">
|
||
<strong>L. Bianchi</strong> - CISO<br>
|
||
<span style="font-size: 11px; color: var(--text-secondary);">📞 +39 XXX XXX 004 | ✅ Coordinamento</span>
|
||
</div>
|
||
</div>
|
||
</div>
|
||
</div>
|
||
<div class="output-actions">
|
||
<button class="btn btn-interactive" onclick="alert('Dashboard aggiornata')">🔄 Aggiorna Dati</button>
|
||
<button class="btn" onclick="alert('Report inviato agli stakeholder')">📧 Invia Update</button>
|
||
<button class="btn" onclick="closeOutput()">Chiudi</button>
|
||
</div>
|
||
`;
|
||
}
|
||
|
||
function generatePriorityMatrix() {
|
||
return `
|
||
<div class="output-header">
|
||
<div class="output-title">📋 Matrice Priorità Ripristino</div>
|
||
<div class="output-subtitle">Classificazione servizi per ordine di ripristino</div>
|
||
</div>
|
||
<div class="output-body">
|
||
<div class="output-section">
|
||
<div class="output-section-title">Priorità 1 - Servizi Essenziali (RTO: 4h)</div>
|
||
<table style="width: 100%; font-size: 12px;">
|
||
<thead>
|
||
<tr style="background-color: var(--bg-tertiary);">
|
||
<th style="padding: 8px;">Servizio</th>
|
||
<th style="padding: 8px;">Criticità Business</th>
|
||
<th style="padding: 8px;">RTO</th>
|
||
<th style="padding: 8px;">RPO</th>
|
||
<th style="padding: 8px;">Dipendenze</th>
|
||
</tr>
|
||
</thead>
|
||
<tbody>
|
||
<tr>
|
||
<td style="padding: 8px;"><strong>Firewall Perimetrale</strong></td>
|
||
<td style="padding: 8px;">Critica</td>
|
||
<td style="padding: 8px;">1h</td>
|
||
<td style="padding: 8px;">0</td>
|
||
<td style="padding: 8px;">Nessuna</td>
|
||
</tr>
|
||
<tr>
|
||
<td style="padding: 8px;"><strong>Active Directory</strong></td>
|
||
<td style="padding: 8px;">Critica</td>
|
||
<td style="padding: 8px;">2h</td>
|
||
<td style="padding: 8px;">15min</td>
|
||
<td style="padding: 8px;">Firewall</td>
|
||
</tr>
|
||
<tr>
|
||
<td style="padding: 8px;"><strong>Database Principale</strong></td>
|
||
<td style="padding: 8px;">Critica</td>
|
||
<td style="padding: 8px;">4h</td>
|
||
<td style="padding: 8px;">1h</td>
|
||
<td style="padding: 8px;">AD, Firewall</td>
|
||
</tr>
|
||
<tr>
|
||
<td style="padding: 8px;"><strong>ERP Produzione</strong></td>
|
||
<td style="padding: 8px;">Critica</td>
|
||
<td style="padding: 8px;">4h</td>
|
||
<td style="padding: 8px;">1h</td>
|
||
<td style="padding: 8px;">Database, AD</td>
|
||
</tr>
|
||
<tr>
|
||
<td style="padding: 8px;"><strong>Sistema Pagamenti</strong></td>
|
||
<td style="padding: 8px;">Critica</td>
|
||
<td style="padding: 8px;">4h</td>
|
||
<td style="padding: 8px;">0</td>
|
||
<td style="padding: 8px;">Database, Firewall</td>
|
||
</tr>
|
||
</tbody>
|
||
</table>
|
||
</div>
|
||
|
||
<div class="output-section">
|
||
<div class="output-section-title">Priorità 2 - Servizi Importanti (RTO: 24h)</div>
|
||
<table style="width: 100%; font-size: 12px;">
|
||
<thead>
|
||
<tr style="background-color: var(--bg-tertiary);">
|
||
<th style="padding: 8px;">Servizio</th>
|
||
<th style="padding: 8px;">Criticità Business</th>
|
||
<th style="padding: 8px;">RTO</th>
|
||
<th style="padding: 8px;">RPO</th>
|
||
<th style="padding: 8px;">Dipendenze</th>
|
||
</tr>
|
||
</thead>
|
||
<tbody>
|
||
<tr>
|
||
<td style="padding: 8px;"><strong>Email Server</strong></td>
|
||
<td style="padding: 8px;">Alta</td>
|
||
<td style="padding: 8px;">8h</td>
|
||
<td style="padding: 8px;">4h</td>
|
||
<td style="padding: 8px;">AD, Firewall</td>
|
||
</tr>
|
||
<tr>
|
||
<td style="padding: 8px;"><strong>CRM Salesforce</strong></td>
|
||
<td style="padding: 8px;">Alta</td>
|
||
<td style="padding: 8px;">12h</td>
|
||
<td style="padding: 8px;">24h</td>
|
||
<td style="padding: 8px;">Internet, AD</td>
|
||
</tr>
|
||
<tr>
|
||
<td style="padding: 8px;"><strong>File Server</strong></td>
|
||
<td style="padding: 8px;">Alta</td>
|
||
<td style="padding: 8px;">24h</td>
|
||
<td style="padding: 8px;">24h</td>
|
||
<td style="padding: 8px;">AD</td>
|
||
</tr>
|
||
<tr>
|
||
<td style="padding: 8px;"><strong>Intranet Aziendale</strong></td>
|
||
<td style="padding: 8px;">Media</td>
|
||
<td style="padding: 8px;">24h</td>
|
||
<td style="padding: 8px;">24h</td>
|
||
<td style="padding: 8px;">Web Server, AD</td>
|
||
</tr>
|
||
</tbody>
|
||
</table>
|
||
</div>
|
||
|
||
<div class="output-section">
|
||
<div class="output-section-title">Priorità 3 - Servizi Standard (RTO: 72h)</div>
|
||
<table style="width: 100%; font-size: 12px;">
|
||
<thead>
|
||
<tr style="background-color: var(--bg-tertiary);">
|
||
<th style="padding: 8px;">Servizio</th>
|
||
<th style="padding: 8px;">Criticità Business</th>
|
||
<th style="padding: 8px;">RTO</th>
|
||
<th style="padding: 8px;">RPO</th>
|
||
<th style="padding: 8px;">Dipendenze</th>
|
||
</tr>
|
||
</thead>
|
||
<tbody>
|
||
<tr>
|
||
<td style="padding: 8px;"><strong>Sistema HR</strong></td>
|
||
<td style="padding: 8px;">Media</td>
|
||
<td style="padding: 8px;">48h</td>
|
||
<td style="padding: 8px;">24h</td>
|
||
<td style="padding: 8px;">Database, AD</td>
|
||
</tr>
|
||
<tr>
|
||
<td style="padding: 8px;"><strong>Sistema Ticketing</strong></td>
|
||
<td style="padding: 8px;">Media</td>
|
||
<td style="padding: 8px;">72h</td>
|
||
<td style="padding: 8px;">24h</td>
|
||
<td style="padding: 8px;">Email, AD</td>
|
||
</tr>
|
||
<tr>
|
||
<td style="padding: 8px;"><strong>Sistemi Reporting</strong></td>
|
||
<td style="padding: 8px;">Bassa</td>
|
||
<td style="padding: 8px;">72h</td>
|
||
<td style="padding: 8px;">72h</td>
|
||
<td style="padding: 8px;">Database</td>
|
||
</tr>
|
||
</tbody>
|
||
</table>
|
||
</div>
|
||
|
||
<div class="output-section">
|
||
<div class="output-section-title">Grafo Dipendenze</div>
|
||
<div style="background-color: var(--bg-tertiary); padding: 20px; border-radius: 6px; text-align: center;">
|
||
<div style="font-size: 13px; color: var(--text-secondary); margin-bottom: 16px;">
|
||
Ordine di ripristino basato su dipendenze:
|
||
</div>
|
||
<div style="font-size: 14px; line-height: 2.5;">
|
||
<strong style="color: var(--danger);">1. Firewall</strong> →<br>
|
||
<strong style="color: var(--warning);">2. Active Directory</strong> →<br>
|
||
<strong style="color: var(--warning);">3. Database Principale</strong> →<br>
|
||
<strong style="color: var(--accent-primary);">4. ERP + Sistema Pagamenti</strong> (parallelo) →<br>
|
||
<strong style="color: var(--success);">5. Email + CRM</strong> (parallelo) →<br>
|
||
<strong style="color: var(--text-secondary);">6. Altri servizi</strong>
|
||
</div>
|
||
</div>
|
||
</div>
|
||
|
||
<div class="info-box" style="margin-top: 16px;">
|
||
<div class="info-box-title">📌 Note Importanti</div>
|
||
<div class="info-box-content">
|
||
• La matrice deve essere aggiornata <strong>trimestralmente</strong> o dopo ogni modifica significativa all'infrastruttura<br>
|
||
• I valori RTO/RPO devono essere concordati con i business owner<br>
|
||
• Le dipendenze devono essere verificate e testate durante le esercitazioni<br>
|
||
• Ogni servizio deve avere una <strong>procedura di ripristino documentata</strong>
|
||
</div>
|
||
</div>
|
||
</div>
|
||
<div class="output-actions">
|
||
<button class="btn btn-primary" onclick="alert('Matrice salvata')">💾 Salva Matrice</button>
|
||
<button class="btn btn-interactive" onclick="alert('PDF esportato')">📄 Esporta PDF</button>
|
||
<button class="btn" onclick="closeOutput()">Chiudi</button>
|
||
</div>
|
||
`;
|
||
}
|
||
|
||
function generateCommTemplates() {
|
||
return `
|
||
<div class="output-header">
|
||
<div class="output-title">📧 Template Comunicazioni</div>
|
||
<div class="output-subtitle">Template pre-approvati per comunicazioni incidente</div>
|
||
</div>
|
||
<div class="output-body">
|
||
<div class="output-section">
|
||
<div class="output-section-title">1. Email Interna - Notifica Incidente</div>
|
||
<div style="background-color: var(--bg-tertiary); padding: 16px; border-radius: 6px; font-size: 13px; font-family: monospace;">
|
||
<strong>Oggetto:</strong> [URGENTE] Incidente di Sicurezza in Corso - INC-[ID]<br><br>
|
||
<strong>A:</strong> Tutti i dipendenti<br>
|
||
<strong>Da:</strong> IT Security Team<br>
|
||
<strong>Data:</strong> [DATA/ORA]<br><br>
|
||
---<br><br>
|
||
Gentili Colleghi,<br><br>
|
||
Vi informiamo che è stato rilevato un incidente di sicurezza informatica che sta impattando [DESCRIZIONE SERVIZI].<br><br>
|
||
<strong>Cosa sta succedendo:</strong><br>
|
||
[DESCRIZIONE SINTETICA INCIDENTE]<br><br>
|
||
<strong>Impatto corrente:</strong><br>
|
||
[ELENCO SERVIZI NON DISPONIBILI/DEGRADATI]<br><br>
|
||
<strong>Azioni richieste:</strong><br>
|
||
• NON tentare di accedere ai servizi elencati sopra<br>
|
||
• Segnalare immediatamente qualsiasi comportamento anomalo a security@azienda.it<br>
|
||
• Seguire le istruzioni del team IT<br>
|
||
• NON condividere informazioni all'esterno dell'azienda<br><br>
|
||
<strong>Prossimi aggiornamenti:</strong><br>
|
||
Vi terremo aggiornati ogni [X] ore o in caso di sviluppi significativi.<br><br>
|
||
Per domande urgenti: [NUMERO HOTLINE]<br><br>
|
||
Grazie per la collaborazione,<br>
|
||
IT Security Team
|
||
</div>
|
||
<button class="btn btn-interactive" onclick="alert('Email copiata negli appunti')" style="margin-top: 12px;">📋 Copia Template</button>
|
||
</div>
|
||
|
||
<div class="output-section">
|
||
<div class="output-section-title">2. Comunicazione Clienti - Interruzione Servizio</div>
|
||
<div style="background-color: var(--bg-tertiary); padding: 16px; border-radius: 6px; font-size: 13px; font-family: monospace;">
|
||
<strong>Oggetto:</strong> Aggiornamento Importante - Interruzione Temporanea Servizi<br><br>
|
||
<strong>A:</strong> Clienti<br>
|
||
<strong>Da:</strong> Customer Care<br>
|
||
<strong>Data:</strong> [DATA/ORA]<br><br>
|
||
---<br><br>
|
||
Gentile Cliente,<br><br>
|
||
Desideriamo informarLa che stiamo attualmente affrontando un problema tecnico che sta impattando [SERVIZI].<br><br>
|
||
<strong>Servizi interessati:</strong><br>
|
||
[ELENCO SERVIZI]<br><br>
|
||
<strong>Cosa stiamo facendo:</strong><br>
|
||
Il nostro team tecnico sta lavorando attivamente per risolvere la situazione. Abbiamo attivato tutte le procedure di emergenza e stiamo collaborando con i nostri partner tecnologici.<br><br>
|
||
<strong>Tempo stimato di ripristino:</strong><br>
|
||
[ETA] - La terremo aggiornato/a su eventuali cambiamenti.<br><br>
|
||
<strong>Cosa può fare:</strong><br>
|
||
[EVENTUALI WORKAROUND DISPONIBILI]<br><br>
|
||
Per assistenza: [CONTATTI CUSTOMER CARE]<br>
|
||
Status page: [URL STATUS PAGE]<br><br>
|
||
Ci scusiamo per il disagio e La ringraziamo per la pazienza.<br><br>
|
||
Cordiali saluti,<br>
|
||
[NOME AZIENDA] - Customer Care Team
|
||
</div>
|
||
<button class="btn btn-interactive" onclick="alert('Email copiata negli appunti')" style="margin-top: 12px;">📋 Copia Template</button>
|
||
</div>
|
||
|
||
<div class="output-section">
|
||
<div class="output-section-title">3. Comunicazione Management - Briefing Esecutivo</div>
|
||
<div style="background-color: var(--bg-tertiary); padding: 16px; border-radius: 6px; font-size: 13px; font-family: monospace;">
|
||
<strong>Oggetto:</strong> [CONFIDENZIALE] Briefing Incidente INC-[ID] - Aggiornamento [#N]<br><br>
|
||
<strong>A:</strong> CEO, CIO, Board Members<br>
|
||
<strong>Da:</strong> CISO<br>
|
||
<strong>Data:</strong> [DATA/ORA]<br>
|
||
<strong>Classificazione:</strong> RISERVATO<br><br>
|
||
---<br><br>
|
||
<strong>EXECUTIVE SUMMARY</strong><br>
|
||
[SINTESI IN 2-3 RIGHE DELLO STATO ATTUALE]<br><br>
|
||
<strong>DETTAGLI INCIDENTE</strong><br>
|
||
• ID: INC-[XXXX]<br>
|
||
• Classificazione: [IS-X] / Severità: [PX]<br>
|
||
• Rilevazione: [DATA/ORA]<br>
|
||
• Durata: [ORE]<br>
|
||
• Stato: [IN CORSO / CONTENUTO / RISOLTO]<br><br>
|
||
<strong>IMPATTO BUSINESS</strong><br>
|
||
• Servizi impattati: [ELENCO]<br>
|
||
• Utenti/Clienti coinvolti: [NUMERO]<br>
|
||
• Stima perdita finanziaria: € [IMPORTO]<br>
|
||
• Impatto reputazionale: [BASSO/MEDIO/ALTO]<br><br>
|
||
<strong>AZIONI IN CORSO</strong><br>
|
||
• [AZIONE 1]<br>
|
||
• [AZIONE 2]<br>
|
||
• [AZIONE 3]<br><br>
|
||
<strong>TIMELINE RIPRISTINO</strong><br>
|
||
• ETA ripristino servizi critici: [TEMPO]<br>
|
||
• ETA ripristino completo: [TEMPO]<br><br>
|
||
<strong>OBBLIGHI NORMATIVI</strong><br>
|
||
• Notifica CSIRT: [COMPLETATA/IN CORSO/NON RICHIESTA]<br>
|
||
• Notifica GPDP: [SI/NO]<br>
|
||
• Comunicazioni pubbliche: [SI/NO]<br><br>
|
||
<strong>RISCHI E CRITICITÀ</strong><br>
|
||
[ELENCARE EVENTUALI RISCHI RESIDUI]<br><br>
|
||
<strong>PROSSIMI STEP</strong><br>
|
||
[AZIONI PIANIFICATE NELLE PROSSIME ORE]<br><br>
|
||
Prossimo aggiornamento: [DATA/ORA]<br>
|
||
Per urgenze: [NUMERO DIRETTO CISO]<br><br>
|
||
[NOME COGNOME]<br>
|
||
Chief Information Security Officer
|
||
</div>
|
||
<button class="btn btn-interactive" onclick="alert('Email copiata negli appunti')" style="margin-top: 12px;">📋 Copia Template</button>
|
||
</div>
|
||
|
||
<div class="output-section">
|
||
<div class="output-section-title">4. Comunicato Stampa (Solo se richiesto)</div>
|
||
<div style="background-color: var(--bg-tertiary); padding: 16px; border-radius: 6px; font-size: 13px; font-family: monospace;">
|
||
<strong>COMUNICATO STAMPA</strong><br>
|
||
<strong>PER DIFFUSIONE IMMEDIATA</strong><br><br>
|
||
[NOME AZIENDA] - Aggiornamento su Incidente di Sicurezza<br><br>
|
||
[CITTÀ, DATA] – [NOME AZIENDA] informa che [DATA INCIDENTE] ha rilevato un incidente di sicurezza informatica che ha temporaneamente impattato [DESCRIZIONE GENERICA SERVIZI].<br><br>
|
||
L'azienda ha immediatamente attivato il proprio team di risposta agli incidenti e ha implementato tutte le misure di contenimento necessarie. [STATO ATTUALE: es. "I servizi sono stati completamente ripristinati" / "Stiamo lavorando attivamente al ripristino"].<br><br>
|
||
La sicurezza dei dati dei nostri clienti è la nostra massima priorità. [INFORMAZIONI SU IMPATTO DATI SE APPLICABILE].<br><br>
|
||
Abbiamo notificato tempestivamente le autorità competenti, inclusi [CSIRT Italia / Garante Privacy / altre autorità rilevanti], e stiamo collaborando pienamente con loro.<br><br>
|
||
I clienti interessati sono stati contattati direttamente e possono trovare aggiornamenti continui su [URL STATUS PAGE] o contattare il nostro servizio clienti al [NUMERO].<br><br>
|
||
Stiamo conducendo un'analisi approfondita dell'incidente per identificare ulteriori misure di sicurezza da implementare.<br><br>
|
||
<strong>Contatti per la stampa:</strong><br>
|
||
[Nome Ufficio Stampa]<br>
|
||
[Email]<br>
|
||
[Telefono]<br><br>
|
||
###
|
||
</div>
|
||
<button class="btn btn-interactive" onclick="alert('Comunicato copiato negli appunti')" style="margin-top: 12px;">📋 Copia Template</button>
|
||
</div>
|
||
|
||
<div class="output-section">
|
||
<div class="output-section-title">5. Status Page Update</div>
|
||
<div style="background-color: var(--bg-tertiary); padding: 16px; border-radius: 6px; font-size: 13px; font-family: monospace;">
|
||
<strong>[TIMESTAMP] - Aggiornamento #[N]</strong><br><br>
|
||
<strong>🔴 INCIDENTE IN CORSO</strong> / <strong>🟡 MONITORAGGIO</strong> / <strong>🟢 RISOLTO</strong><br><br>
|
||
<strong>Servizi impattati:</strong><br>
|
||
• [Servizio 1]: 🔴 Non disponibile<br>
|
||
• [Servizio 2]: 🟡 Prestazioni degradate<br>
|
||
• [Servizio 3]: 🟢 Operativo<br><br>
|
||
<strong>Descrizione:</strong><br>
|
||
Stiamo attualmente affrontando [DESCRIZIONE PROBLEMA]. Il nostro team sta lavorando attivamente alla risoluzione.<br><br>
|
||
<strong>Impatto:</strong><br>
|
||
[DESCRIZIONE IMPATTO UTENTI]<br><br>
|
||
<strong>Workaround:</strong><br>
|
||
[EVENTUALI SOLUZIONI TEMPORANEE]<br><br>
|
||
<strong>ETA Risoluzione:</strong><br>
|
||
[TEMPO STIMATO]<br><br>
|
||
<strong>Prossimo aggiornamento:</strong> [TEMPO]
|
||
</div>
|
||
<button class="btn btn-interactive" onclick="alert('Update copiato negli appunti')" style="margin-top: 12px;">📋 Copia Template</button>
|
||
</div>
|
||
|
||
<div class="output-section">
|
||
<div class="output-section-title">6. Email Ripristino Completato</div>
|
||
<div style="background-color: var(--bg-tertiary); padding: 16px; border-radius: 6px; font-size: 13px; font-family: monospace;">
|
||
<strong>Oggetto:</strong> ✅ Servizi Ripristinati - Incidente INC-[ID] Risolto<br><br>
|
||
<strong>A:</strong> [Stakeholder]<br>
|
||
<strong>Da:</strong> IT Security Team<br>
|
||
<strong>Data:</strong> [DATA/ORA]<br><br>
|
||
---<br><br>
|
||
Gentili [Colleghi/Clienti],<br><br>
|
||
Siamo lieti di informarVi che l'incidente di sicurezza INC-[ID] è stato completamente risolto e tutti i servizi sono stati ripristinati.<br><br>
|
||
<strong>Riepilogo:</strong><br>
|
||
• Inizio incidente: [DATA/ORA]<br>
|
||
• Risoluzione: [DATA/ORA]<br>
|
||
• Durata totale: [ORE]<br>
|
||
• Servizi ripristinati: [ELENCO]<br><br>
|
||
<strong>Azioni intraprese:</strong><br>
|
||
[DESCRIZIONE SINTETICA DELLE AZIONI]<br><br>
|
||
<strong>Misure preventive implementate:</strong><br>
|
||
[ELENCO MIGLIORAMENTI]<br><br>
|
||
<strong>Monitoraggio:</strong><br>
|
||
Continueremo a monitorare attentamente i sistemi nelle prossime 72 ore per garantire la stabilità completa.<br><br>
|
||
Vi ringraziamo per la pazienza e la collaborazione durante la gestione di questo incidente.<br><br>
|
||
Per qualsiasi domanda: [CONTATTI]<br><br>
|
||
Cordiali saluti,<br>
|
||
[NOME AZIENDA] - IT Security Team
|
||
</div>
|
||
<button class="btn btn-interactive" onclick="alert('Email copiata negli appunti')" style="margin-top: 12px;">📋 Copia Template</button>
|
||
</div>
|
||
|
||
<div class="info-box" style="margin-top: 16px;">
|
||
<div class="info-box-title">📌 Linee Guida Comunicazione</div>
|
||
<div class="info-box-content">
|
||
<strong>Principi generali:</strong><br>
|
||
• Essere <strong>trasparenti</strong> ma non divulgare dettagli tecnici sensibili<br>
|
||
• Comunicare <strong>tempestivamente</strong> anche se non si hanno tutte le informazioni<br>
|
||
• Mantenere un <strong>tono professionale</strong> e rassicurante<br>
|
||
• Fornire <strong>aggiornamenti regolari</strong> anche se la situazione non cambia<br>
|
||
• Coordinare con <strong>Legal e PR</strong> prima di comunicazioni esterne<br>
|
||
• Documentare <strong>tutte le comunicazioni</strong> inviate
|
||
</div>
|
||
</div>
|
||
</div>
|
||
<div class="output-actions">
|
||
<button class="btn btn-primary" onclick="alert('Tutti i template salvati')">💾 Salva Tutti i Template</button>
|
||
<button class="btn btn-interactive" onclick="alert('PDF generato')">📄 Esporta PDF</button>
|
||
<button class="btn" onclick="closeOutput()">Chiudi</button>
|
||
</div>
|
||
`;
|
||
}
|
||
|
||
function generatePIRReport() {
|
||
return `
|
||
<div class="output-header">
|
||
<div class="output-title">📄 Report Post-Incident Review</div>
|
||
<div class="output-subtitle">Esempio di report PIR completato</div>
|
||
</div>
|
||
<div class="output-body">
|
||
<div style="text-align: center; padding: 20px; border-bottom: 2px solid var(--border-color);">
|
||
<h2 style="font-size: 20px; margin-bottom: 8px;">POST-INCIDENT REVIEW REPORT</h2>
|
||
<div style="font-size: 14px; color: var(--text-secondary);">Incidente INC-2024-0156 - Attacco Ransomware</div>
|
||
<div style="font-size: 12px; color: var(--text-secondary); margin-top: 8px;">Documento Riservato - Solo per uso interno</div>
|
||
</div>
|
||
|
||
<div class="output-section">
|
||
<div class="output-section-title">Executive Summary</div>
|
||
<div style="font-size: 13px; line-height: 1.8;">
|
||
Il 15 marzo 2024 alle ore 03:47, l'organizzazione ha subito un attacco ransomware che ha compromesso 23 server di produzione, causando l'interruzione di servizi critici per circa 18 ore. L'attacco è stato rilevato dai sistemi EDR e il team di risposta agli incidenti è stato immediatamente attivato. Grazie alle procedure di backup e al piano di disaster recovery, tutti i servizi sono stati ripristinati entro le 21:00 dello stesso giorno senza pagare il riscatto. L'incidente ha evidenziato alcune lacune nei controlli di sicurezza che sono state prontamente affrontate. Il costo totale stimato è di €187.000, principalmente dovuto a mancato fatturato e costi di risposta. Nessun dato cliente è stato esfiltrato.
|
||
</div>
|
||
</div>
|
||
|
||
<div class="output-section">
|
||
<div class="output-section-title">Incident Overview</div>
|
||
<table style="width: 100%; font-size: 13px;">
|
||
<tr>
|
||
<td style="padding: 8px; width: 30%; background-color: var(--bg-tertiary);"><strong>ID Incidente</strong></td>
|
||
<td style="padding: 8px;">INC-2024-0156</td>
|
||
</tr>
|
||
<tr>
|
||
<td style="padding: 8px; background-color: var(--bg-tertiary);"><strong>Classificazione</strong></td>
|
||
<td style="padding: 8px;">IS-1 (Impatto significativo servizi) / Severità P1 (Critico)</td>
|
||
</tr>
|
||
<tr>
|
||
<td style="padding: 8px; background-color: var(--bg-tertiary);"><strong>Tipologia</strong></td>
|
||
<td style="padding: 8px;">Ransomware (LockBit 3.0)</td>
|
||
</tr>
|
||
<tr>
|
||
<td style="padding: 8px; background-color: var(--bg-tertiary);"><strong>Data Rilevazione</strong></td>
|
||
<td style="padding: 8px;">15/03/2024 03:47</td>
|
||
</tr>
|
||
<tr>
|
||
<td style="padding: 8px; background-color: var(--bg-tertiary);"><strong>Data Risoluzione</strong></td>
|
||
<td style="padding: 8px;">15/03/2024 21:00</td>
|
||
</tr>
|
||
<tr>
|
||
<td style="padding: 8px; background-color: var(--bg-tertiary);"><strong>Durata Totale</strong></td>
|
||
<td style="padding: 8px;">17 ore 13 minuti</td>
|
||
</tr>
|
||
<tr>
|
||
<td style="padding: 8px; background-color: var(--bg-tertiary);"><strong>Notifica CSIRT</strong></td>
|
||
<td style="padding: 8px;">✅ Completata entro 24h (15/03/2024 18:30)</td>
|
||
</tr>
|
||
</table>
|
||
</div>
|
||
|
||
<div class="output-section">
|
||
<div class="output-section-title">Root Cause Analysis</div>
|
||
<div class="output-field">
|
||
<div class="output-field-label">Causa Radice Primaria</div>
|
||
<div class="output-field-value">
|
||
Credenziali VPN compromesse di un account amministrativo senza autenticazione multi-fattore (MFA) abilitata. L'attaccante ha sfruttato questa vulnerabilità per accedere alla rete interna e distribuire il ransomware.
|
||
</div>
|
||
</div>
|
||
<div class="output-field">
|
||
<div class="output-field-label">Fattori Contributivi</div>
|
||
<div class="output-field-value">
|
||
1. <strong>MFA non obbligatoria:</strong> Policy MFA non applicata a tutti gli account amministrativi<br>
|
||
2. <strong>Segmentazione insufficiente:</strong> Account VPN aveva accesso troppo ampio alla rete<br>
|
||
3. <strong>Patching ritardato:</strong> Alcuni server non aggiornati con patch critiche<br>
|
||
4. <strong>Monitoraggio limitato:</strong> Alert EDR non configurati per rilevare movimento laterale<br>
|
||
5. <strong>Password debole:</strong> L'account compromesso utilizzava una password non conforme alla policy
|
||
</div>
|
||
</div>
|
||
<div class="output-field">
|
||
<div class="output-field-label">Vettore di Attacco</div>
|
||
<div class="output-field-value">
|
||
1. Compromissione credenziali VPN (probabilmente via phishing o credential stuffing)<br>
|
||
2. Accesso VPN con credenziali legittime<br>
|
||
3. Movimento laterale nella rete sfruttando privilegi eccessivi<br>
|
||
4. Disabilitazione antivirus e backup locali<br>
|
||
5. Distribuzione ransomware su 23 server tramite script PowerShell<br>
|
||
6. Cifratura dati e richiesta riscatto
|
||
</div>
|
||
</div>
|
||
</div>
|
||
|
||
<div class="output-section">
|
||
<div class="output-section-title">Impact Assessment</div>
|
||
<div style="display: grid; grid-template-columns: 1fr 1fr; gap: 16px;">
|
||
<div style="background-color: var(--bg-tertiary); padding: 16px; border-radius: 6px;">
|
||
<strong style="color: var(--danger);">Impatto Operativo</strong><br>
|
||
<div style="font-size: 12px; margin-top: 8px; line-height: 1.6;">
|
||
• 23 server produzione offline<br>
|
||
• ERP non disponibile per 18h<br>
|
||
• 450 utenti impattati<br>
|
||
• Produzione ferma per 12h<br>
|
||
• 85% capacità operativa persa
|
||
</div>
|
||
</div>
|
||
<div style="background-color: var(--bg-tertiary); padding: 16px; border-radius: 6px;">
|
||
<strong style="color: var(--warning);">Impatto Finanziario</strong><br>
|
||
<div style="font-size: 12px; margin-top: 8px; line-height: 1.6;">
|
||
• Mancato fatturato: €125.000<br>
|
||
• Costi risposta: €42.000<br>
|
||
• Consulenti esterni: €15.000<br>
|
||
• Ore straordinario: €5.000<br>
|
||
• <strong>TOTALE: €187.000</strong>
|
||
</div>
|
||
</div>
|
||
</div>
|
||
<div style="margin-top: 16px; background-color: var(--bg-tertiary); padding: 16px; border-radius: 6px;">
|
||
<strong style="color: var(--success);">Impatto su Dati</strong><br>
|
||
<div style="font-size: 12px; margin-top: 8px; line-height: 1.6;">
|
||
✅ <strong>Nessun dato esfiltrato</strong> (verificato tramite analisi log e network forensics)<br>
|
||
✅ Dati ripristinati completamente da backup<br>
|
||
✅ RPO rispettato: perdita dati < 1 ora<br>
|
||
✅ Nessuna notifica GPDP richiesta
|
||
</div>
|
||
</div>
|
||
</div>
|
||
|
||
<div class="output-section">
|
||
<div class="output-section-title">Response Evaluation</div>
|
||
<div class="output-field">
|
||
<div class="output-field-label">✅ Punti di Forza</div>
|
||
<div class="output-field-value">
|
||
• <strong>Rilevazione rapida:</strong> EDR ha rilevato l'attacco in 12 minuti dall'inizio cifratura<br>
|
||
• <strong>Attivazione team:</strong> Incident Response Team operativo in 15 minuti<br>
|
||
• <strong>Backup efficaci:</strong> Backup offline integri e disponibili<br>
|
||
• <strong>Comunicazione:</strong> Stakeholder informati tempestivamente<br>
|
||
• <strong>Coordinamento:</strong> Ottima collaborazione tra team IT, Security e Business<br>
|
||
• <strong>Decisione no-ransom:</strong> Management ha confermato politica di non pagare riscatto<br>
|
||
• <strong>Documentazione:</strong> Tutte le azioni documentate accuratamente
|
||
</div>
|
||
</div>
|
||
<div class="output-field">
|
||
<div class="output-field-label">❌ Aree di Miglioramento</div>
|
||
<div class="output-field-value">
|
||
• <strong>Prevenzione:</strong> L'attacco poteva essere prevenuto con MFA obbligatoria<br>
|
||
• <strong>Rilevazione movimento laterale:</strong> Ritardo di 2 ore nel rilevare la propagazione<br>
|
||
• <strong>Segmentazione:</strong> Mancanza di micro-segmentazione ha facilitato la diffusione<br>
|
||
• <strong>Playbook:</strong> Procedura ransomware non completamente aggiornata<br>
|
||
• <strong>Comunicazione esterna:</strong> Ritardo nell'aggiornamento status page clienti<br>
|
||
• <strong>Forensics:</strong> Alcuni log non disponibili per retention insufficiente
|
||
</div>
|
||
</div>
|
||
<div class="output-field">
|
||
<div class="output-field-label">⏱️ Tempi di Risposta</div>
|
||
<div class="output-field-value">
|
||
• Rilevazione → Triage: <strong>15 min</strong> ✅ (Target: <30min)<br>
|
||
• Triage → Contenimento: <strong>45 min</strong> ✅ (Target: <1h)<br>
|
||
• Contenimento → Eradicazione: <strong>4h</strong> ✅ (Target: <6h)<br>
|
||
• Eradicazione → Ripristino: <strong>12h</strong> ⚠️ (Target: <8h)<br>
|
||
• <strong>Tempo totale: 17h 13min</strong>
|
||
</div>
|
||
</div>
|
||
</div>
|
||
|
||
<div class="output-section">
|
||
<div class="output-section-title">Action Plan - Azioni Correttive</div>
|
||
<table style="width: 100%; font-size: 12px;">
|
||
<thead>
|
||
<tr style="background-color: var(--bg-tertiary);">
|
||
<th style="padding: 8px;">ID</th>
|
||
<th style="padding: 8px;">Azione</th>
|
||
<th style="padding: 8px;">Priorità</th>
|
||
<th style="padding: 8px;">Responsabile</th>
|
||
<th style="padding: 8px;">Deadline</th>
|
||
<th style="padding: 8px;">Stato</th>
|
||
</tr>
|
||
</thead>
|
||
<tbody>
|
||
<tr>
|
||
<td style="padding: 8px;">ACT-001</td>
|
||
<td style="padding: 8px;">Implementare MFA obbligatoria per tutti gli account admin</td>
|
||
<td style="padding: 8px;"><span style="color: var(--danger);">ALTA</span></td>
|
||
<td style="padding: 8px;">IT Security</td>
|
||
<td style="padding: 8px;">31/03/2024</td>
|
||
<td style="padding: 8px;"><span style="color: var(--success);">✅ Completato</span></td>
|
||
</tr>
|
||
<tr>
|
||
<td style="padding: 8px;">ACT-002</td>
|
||
<td style="padding: 8px;">Implementare micro-segmentazione rete</td>
|
||
<td style="padding: 8px;"><span style="color: var(--danger);">ALTA</span></td>
|
||
<td style="padding: 8px;">Network Team</td>
|
||
<td style="padding: 8px;">30/04/2024</td>
|
||
<td style="padding: 8px;"><span style="color: var(--warning);">🔄 In corso (60%)</span></td>
|
||
</tr>
|
||
<tr>
|
||
<td style="padding: 8px;">ACT-003</td>
|
||
<td style="padding: 8px;">Aggiornare playbook ransomware</td>
|
||
<td style="padding: 8px;"><span style="color: var(--warning);">MEDIA</span></td>
|
||
<td style="padding: 8px;">CISO</td>
|
||
<td style="padding: 8px;">15/04/2024</td>
|
||
<td style="padding: 8px;"><span style="color: var(--success);">✅ Completato</span></td>
|
||
</tr>
|
||
<tr>
|
||
<td style="padding: 8px;">ACT-004</td>
|
||
<td style="padding: 8px;">Configurare alert EDR per movimento laterale</td>
|
||
<td style="padding: 8px;"><span style="color: var(--danger);">ALTA</span></td>
|
||
<td style="padding: 8px;">SOC Team</td>
|
||
<td style="padding: 8px;">31/03/2024</td>
|
||
<td style="padding: 8px;"><span style="color: var(--success);">✅ Completato</span></td>
|
||
</tr>
|
||
<tr>
|
||
<td style="padding: 8px;">ACT-005</td>
|
||
<td style="padding: 8px;">Estendere retention log a 12 mesi</td>
|
||
<td style="padding: 8px;"><span style="color: var(--warning);">MEDIA</span></td>
|
||
<td style="padding: 8px;">IT Operations</td>
|
||
<td style="padding: 8px;">30/04/2024</td>
|
||
<td style="padding: 8px;"><span style="color: var(--warning);">🔄 In corso (30%)</span></td>
|
||
</tr>
|
||
<tr>
|
||
<td style="padding: 8px;">ACT-006</td>
|
||
<td style="padding: 8px;">Condurre training ransomware per tutto il personale</td>
|
||
<td style="padding: 8px;"><span style="color: var(--warning);">MEDIA</span></td>
|
||
<td style="padding: 8px;">HR + Security</td>
|
||
<td style="padding: 8px;">31/05/2024</td>
|
||
<td style="padding: 8px;"><span style="color: var(--text-secondary);">⏳ Pianificato</span></td>
|
||
</tr>
|
||
<tr>
|
||
<td style="padding: 8px;">ACT-007</td>
|
||
<td style="padding: 8px;">Implementare privileged access management (PAM)</td>
|
||
<td style="padding: 8px;"><span style="color: var(--danger);">ALTA</span></td>
|
||
<td style="padding: 8px;">IT Security</td>
|
||
<td style="padding: 8px;">30/06/2024</td>
|
||
<td style="padding: 8px;"><span style="color: var(--text-secondary);">⏳ Pianificato</span></td>
|
||
</tr>
|
||
<tr>
|
||
<td style="padding: 8px;">ACT-008</td>
|
||
<td style="padding: 8px;">Esercitazione ransomware full-scale</td>
|
||
<td style="padding: 8px;"><span style="color: var(--warning);">MEDIA</span></td>
|
||
<td style="padding: 8px;">CISO</td>
|
||
<td style="padding: 8px;">30/09/2024</td>
|
||
<td style="padding: 8px;"><span style="color: var(--text-secondary);">⏳ Pianificato</span></td>
|
||
</tr>
|
||
</tbody>
|
||
</table>
|
||
</div>
|
||
|
||
<div class="output-section">
|
||
<div class="output-section-title">Lessons Learned</div>
|
||
<div style="font-size: 13px; line-height: 1.8;">
|
||
<strong>1. La prevenzione è fondamentale:</strong> L'implementazione di MFA avrebbe completamente prevenuto questo attacco. Investire in controlli preventivi è più efficace ed economico della risposta agli incidenti.<br><br>
|
||
<strong>2. I backup salvano l'organizzazione:</strong> La strategia di backup 3-2-1 con copie offline si è rivelata essenziale. Senza backup integri, l'impatto sarebbe stato devastante.<br><br>
|
||
<strong>3. La segmentazione limita i danni:</strong> La mancanza di micro-segmentazione ha permesso la rapida propagazione. Implementare zero-trust architecture è prioritario.<br><br>
|
||
<strong>4. Il training fa la differenza:</strong> Il team ha risposto efficacemente grazie alle esercitazioni precedenti. Continuare con training regolari.<br><br>
|
||
<strong>5. La comunicazione è critica:</strong> Mantenere stakeholder informati riduce ansia e migliora la collaborazione durante la crisi.<br><br>
|
||
<strong>6. La documentazione è essenziale:</strong> La documentazione accurata ha facilitato l'analisi post-incidente e la notifica alle autorità.<br><br>
|
||
<strong>7. Mai pagare il riscatto:</strong> La politica di non pagare è stata validata dal successo del ripristino da backup.
|
||
</div>
|
||
</div>
|
||
|
||
<div class="output-section">
|
||
<div class="output-section-title">Approvazioni</div>
|
||
<table style="width: 100%; font-size: 13px;">
|
||
<tr>
|
||
<td style="padding: 8px; width: 30%; background-color: var(--bg-tertiary);"><strong>Preparato da</strong></td>
|
||
<td style="padding: 8px;">Marco Bianchi - IR Team Lead - 22/03/2024</td>
|
||
</tr>
|
||
<tr>
|
||
<td style="padding: 8px; background-color: var(--bg-tertiary);"><strong>Revisionato da</strong></td>
|
||
<td style="padding: 8px;">Laura Verdi - CISO - 23/03/2024</td>
|
||
</tr>
|
||
<tr>
|
||
<td style="padding: 8px; background-color: var(--bg-tertiary);"><strong>Approvato da</strong></td>
|
||
<td style="padding: 8px;">Giovanni Rossi - CIO - 25/03/2024</td>
|
||
</tr>
|
||
</table>
|
||
</div>
|
||
</div>
|
||
<div class="output-actions">
|
||
<button class="btn btn-primary" onclick="alert('Report salvato')">💾 Salva Report</button>
|
||
<button class="btn btn-interactive" onclick="alert('PDF generato')">📄 Genera PDF</button>
|
||
<button class="btn" onclick="alert('Report distribuito')">📧 Distribuisci</button>
|
||
<button class="btn" onclick="closeOutput()">Chiudi</button>
|
||
</div>
|
||
`;
|
||
}
|
||
|
||
function generateDrillCalendar() {
|
||
return `
|
||
<div class="output-header">
|
||
<div class="output-title">📅 Calendario Esercitazioni 2024</div>
|
||
<div class="output-subtitle">Piano annuale esercitazioni e test</div>
|
||
</div>
|
||
<div class="output-body">
|
||
<div class="output-section">
|
||
<div class="output-section-title">Q1 2024 (Gennaio - Marzo)</div>
|
||
<table style="width: 100%; font-size: 12px;">
|
||
<thead>
|
||
<tr style="background-color: var(--bg-tertiary);">
|
||
<th style="padding: 8px;">Data</th>
|
||
<th style="padding: 8px;">Tipo</th>
|
||
<th style="padding: 8px;">Scenario</th>
|
||
<th style="padding: 8px;">Partecipanti</th>
|
||
<th style="padding: 8px;">Durata</th>
|
||
<th style="padding: 8px;">Stato</th>
|
||
</tr>
|
||
</thead>
|
||
<tbody>
|
||
<tr>
|
||
<td style="padding: 8px;">15 Gennaio</td>
|
||
<td style="padding: 8px;">Tabletop</td>
|
||
<td style="padding: 8px;">Data Breach</td>
|
||
<td style="padding: 8px;">Management + IR Team</td>
|
||
<td style="padding: 8px;">3h</td>
|
||
<td style="padding: 8px;"><span style="color: var(--success);">✅ Completato</span></td>
|
||
</tr>
|
||
<tr>
|
||
<td style="padding: 8px;">20 Febbraio</td>
|
||
<td style="padding: 8px;">Walkthrough</td>
|
||
<td style="padding: 8px;">Revisione Playbook DDoS</td>
|
||
<td style="padding: 8px;">IR Team + Network</td>
|
||
<td style="padding: 8px;">2h</td>
|
||
<td style="padding: 8px;"><span style="color: var(--success);">✅ Completato</span></td>
|
||
</tr>
|
||
<tr>
|
||
<td style="padding: 8px;">28 Marzo</td>
|
||
<td style="padding: 8px;">Simulation</td>
|
||
<td style="padding: 8px;">Ransomware Attack</td>
|
||
<td style="padding: 8px;">Tutti i team</td>
|
||
<td style="padding: 8px;">6h</td>
|
||
<td style="padding: 8px;"><span style="color: var(--success);">✅ Completato</span></td>
|
||
</tr>
|
||
</tbody>
|
||
</table>
|
||
</div>
|
||
|
||
<div class="output-section">
|
||
<div class="output-section-title">Q2 2024 (Aprile - Giugno)</div>
|
||
<table style="width: 100%; font-size: 12px;">
|
||
<thead>
|
||
<tr style="background-color: var(--bg-tertiary);">
|
||
<th style="padding: 8px;">Data</th>
|
||
<th style="padding: 8px;">Tipo</th>
|
||
<th style="padding: 8px;">Scenario</th>
|
||
<th style="padding: 8px;">Partecipanti</th>
|
||
<th style="padding: 8px;">Durata</th>
|
||
<th style="padding: 8px;">Stato</th>
|
||
</tr>
|
||
</thead>
|
||
<tbody>
|
||
<tr>
|
||
<td style="padding: 8px;">18 Aprile</td>
|
||
<td style="padding: 8px;">Walkthrough</td>
|
||
<td style="padding: 8px;">Revisione Procedure Notifica CSIRT</td>
|
||
<td style="padding: 8px;">IR Team + Legal</td>
|
||
<td style="padding: 8px;">2h</td>
|
||
<td style="padding: 8px;"><span style="color: var(--warning);">🔄 In corso</span></td>
|
||
</tr>
|
||
<tr>
|
||
<td style="padding: 8px;">15 Maggio</td>
|
||
<td style="padding: 8px;">Red Team</td>
|
||
<td style="padding: 8px;">Penetration Test + Incident Response</td>
|
||
<td style="padding: 8px;">Blue Team vs Red Team</td>
|
||
<td style="padding: 8px;">2 settimane</td>
|
||
<td style="padding: 8px;"><span style="color: var(--text-secondary);">⏳ Pianificato</span></td>
|
||
</tr>
|
||
<tr>
|
||
<td style="padding: 8px;">27 Giugno</td>
|
||
<td style="padding: 8px;">Tabletop</td>
|
||
<td style="padding: 8px;">Supply Chain Attack</td>
|
||
<td style="padding: 8px;">Management + Procurement</td>
|
||
<td style="padding: 8px;">3h</td>
|
||
<td style="padding: 8px;"><span style="color: var(--text-secondary);">⏳ Pianificato</span></td>
|
||
</tr>
|
||
</tbody>
|
||
</table>
|
||
</div>
|
||
|
||
<div class="output-section">
|
||
<div class="output-section-title">Q3 2024 (Luglio - Settembre)</div>
|
||
<table style="width: 100%; font-size: 12px;">
|
||
<thead>
|
||
<tr style="background-color: var(--bg-tertiary);">
|
||
<th style="padding: 8px;">Data</th>
|
||
<th style="padding: 8px;">Tipo</th>
|
||
<th style="padding: 8px;">Scenario</th>
|
||
<th style="padding: 8px;">Partecipanti</th>
|
||
<th style="padding: 8px;">Durata</th>
|
||
<th style="padding: 8px;">Stato</th>
|
||
</tr>
|
||
</thead>
|
||
<tbody>
|
||
<tr>
|
||
<td style="padding: 8px;">10 Luglio</td>
|
||
<td style="padding: 8px;">Walkthrough</td>
|
||
<td style="padding: 8px;">Backup & Recovery Procedures</td>
|
||
<td style="padding: 8px;">IT Operations</td>
|
||
<td style="padding: 8px;">2h</td>
|
||
<td style="padding: 8px;"><span style="color: var(--text-secondary);">⏳ Pianificato</span></td>
|
||
</tr>
|
||
<tr>
|
||
<td style="padding: 8px;">22 Agosto</td>
|
||
<td style="padding: 8px;">Simulation</td>
|
||
<td style="padding: 8px;">Insider Threat</td>
|
||
<td style="padding: 8px;">IR Team + HR + Legal</td>
|
||
<td style="padding: 8px;">4h</td>
|
||
<td style="padding: 8px;"><span style="color: var(--text-secondary);">⏳ Pianificato</span></td>
|
||
</tr>
|
||
<tr>
|
||
<td style="padding: 8px;">25 Settembre</td>
|
||
<td style="padding: 8px;">Full-Scale</td>
|
||
<td style="padding: 8px;">Multi-Vector Cyber Attack</td>
|
||
<td style="padding: 8px;">Intera organizzazione</td>
|
||
<td style="padding: 8px;">2 giorni</td>
|
||
<td style="padding: 8px;"><span style="color: var(--text-secondary);">⏳ Pianificato</span></td>
|
||
</tr>
|
||
</tbody>
|
||
</table>
|
||
</div>
|
||
|
||
<div class="output-section">
|
||
<div class="output-section-title">Q4 2024 (Ottobre - Dicembre)</div>
|
||
<table style="width: 100%; font-size: 12px;">
|
||
<thead>
|
||
<tr style="background-color: var(--bg-tertiary);">
|
||
<th style="padding: 8px;">Data</th>
|
||
<th style="padding: 8px;">Tipo</th>
|
||
<th style="padding: 8px;">Scenario</th>
|
||
<th style="padding: 8px;">Partecipanti</th>
|
||
<th style="padding: 8px;">Durata</th>
|
||
<th style="padding: 8px;">Stato</th>
|
||
</tr>
|
||
</thead>
|
||
<tbody>
|
||
<tr>
|
||
<td style="padding: 8px;">17 Ottobre</td>
|
||
<td style="padding: 8px;">Tabletop</td>
|
||
<td style="padding: 8px;">Cloud Infrastructure Compromise</td>
|
||
<td style="padding: 8px;">Management + Cloud Team</td>
|
||
<td style="padding: 8px;">3h</td>
|
||
<td style="padding: 8px;"><span style="color: var(--text-secondary);">⏳ Pianificato</span></td>
|
||
</tr>
|
||
<tr>
|
||
<td style="padding: 8px;">21 Novembre</td>
|
||
<td style="padding: 8px;">Walkthrough</td>
|
||
<td style="padding: 8px;">Crisis Communication Procedures</td>
|
||
<td style="padding: 8px;">Management + PR + Legal</td>
|
||
<td style="padding: 8px;">2h</td>
|
||
<td style="padding: 8px;"><span style="color: var(--text-secondary);">⏳ Pianificato</span></td>
|
||
</tr>
|
||
<tr>
|
||
<td style="padding: 8px;">12 Dicembre</td>
|
||
<td style="padding: 8px;">Tabletop</td>
|
||
<td style="padding: 8px;">Review Anno 2024 + Planning 2025</td>
|
||
<td style="padding: 8px;">IR Team + Management</td>
|
||
<td style="padding: 8px;">4h</td>
|
||
<td style="padding: 8px;"><span style="color: var(--text-secondary);">⏳ Pianificato</span></td>
|
||
</tr>
|
||
</tbody>
|
||
</table>
|
||
</div>
|
||
|
||
<div class="output-section">
|
||
<div class="output-section-title">Riepilogo Annuale</div>
|
||
<div style="display: grid; grid-template-columns: repeat(3, 1fr); gap: 16px;">
|
||
<div style="background-color: var(--bg-tertiary); padding: 16px; border-radius: 6px; text-align: center;">
|
||
<div style="font-size: 32px; font-weight: 700; color: var(--accent-primary);">12</div>
|
||
<div style="font-size: 12px; color: var(--text-secondary); margin-top: 8px;">ESERCITAZIONI TOTALI</div>
|
||
</div>
|
||
<div style="background-color: var(--bg-tertiary); padding: 16px; border-radius: 6px; text-align: center;">
|
||
<div style="font-size: 32px; font-weight: 700; color: var(--success);">3</div>
|
||
<div style="font-size: 12px; color: var(--text-secondary); margin-top: 8px;">COMPLETATE</div>
|
||
</div>
|
||
<div style="background-color: var(--bg-tertiary); padding: 16px; border-radius: 6px; text-align: center;">
|
||
<div style="font-size: 32px; font-weight: 700; color: var(--text-secondary);">9</div>
|
||
<div style="font-size: 12px; color: var(--text-secondary); margin-top: 8px;">PIANIFICATE</div>
|
||
</div>
|
||
</div>
|
||
<div style="margin-top: 16px; font-size: 13px;">
|
||
<strong>Distribuzione per tipo:</strong><br>
|
||
• Tabletop Exercise: 5<br>
|
||
• Walkthrough: 4<br>
|
||
• Simulation: 2<br>
|
||
• Full-Scale Exercise: 1<br>
|
||
• Red Team Exercise: 1
|
||
</div>
|
||
</div>
|
||
|
||
<div class="info-box" style="margin-top: 16px;">
|
||
<div class="info-box-title">📌 Note sul Calendario</div>
|
||
<div class="info-box-content">
|
||
• Ogni esercitazione deve essere seguita da un <strong>report di valutazione</strong> entro 7 giorni<br>
|
||
• Le lezioni apprese devono essere integrate nei playbook e procedure<br>
|
||
• La partecipazione è <strong>obbligatoria</strong> per i ruoli indicati<br>
|
||
• Il calendario può essere modificato in base a esigenze operative<br>
|
||
• Almeno <strong>2 esercitazioni all'anno</strong> devono coinvolgere il management
|
||
</div>
|
||
</div>
|
||
</div>
|
||
<div class="output-actions">
|
||
<button class="btn btn-primary" onclick="alert('Calendario salvato')">💾 Salva Calendario</button>
|
||
<button class="btn btn-interactive" onclick="alert('Inviti calendario inviati')">📧 Invia Inviti</button>
|
||
<button class="btn" onclick="alert('PDF esportato')">📄 Esporta PDF</button>
|
||
<button class="btn" onclick="closeOutput()">Chiudi</button>
|
||
</div>
|
||
`;
|
||
}
|
||
|
||
function generatePlaybookRansomware() {
|
||
return `
|
||
<div class="output-header">
|
||
<div class="output-title">🔒 Playbook Ransomware</div>
|
||
<div class="output-subtitle">Procedura operativa per attacchi ransomware</div>
|
||
</div>
|
||
<div class="output-body">
|
||
<div class="info-box danger-box">
|
||
<div class="info-box-title">⚠️ ATTIVAZIONE IMMEDIATA</div>
|
||
<div class="info-box-content">
|
||
Questo playbook deve essere attivato <strong>immediatamente</strong> in caso di:
|
||
• Rilevazione cifratura file in corso<br>
|
||
• Richiesta di riscatto visualizzata<br>
|
||
• Alert EDR/Antivirus per ransomware<br>
|
||
• Segnalazione utenti di file inaccessibili con estensioni anomale
|
||
</div>
|
||
</div>
|
||
|
||
<div class="output-section">
|
||
<div class="output-section-title">FASE 1: Contenimento Immediato (0-15 minuti)</div>
|
||
<div class="checklist">
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>[T+0min] ISOLARE SISTEMI COMPROMESSI:</strong> Disconnettere fisicamente o logicamente dalla rete tutti i sistemi identificati come compromessi</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>[T+2min] BLOCCARE ACCOUNT COMPROMESSI:</strong> Disabilitare immediatamente account utente associati all'attacco</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>[T+5min] PROTEGGERE BACKUP:</strong> Verificare che i backup siano offline e non accessibili dalla rete. Se necessario, disconnetterli immediatamente</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>[T+7min] SNAPSHOT FORENS ICI:</strong> Acquisire immagini RAM e disco dei sistemi critici prima di spegnerli</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>[T+10min] ATTIVARE IR TEAM:</strong> Notificare Incident Response Team e attivare war room</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>[T+12min] IDENTIFICARE VARIANTE:</strong> Raccogliere sample ransomware e note di riscatto per identificazione</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>[T+15min] COMUNICAZIONE INIZIALE:</strong> Informare management e stakeholder chiave</div>
|
||
</div>
|
||
</div>
|
||
</div>
|
||
|
||
<div class="output-section">
|
||
<div class="output-section-title">FASE 2: Valutazione e Analisi (15-60 minuti)</div>
|
||
<div class="checklist">
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>IDENTIFICARE PERIMETRO:</strong> Determinare tutti i sistemi impattati attraverso analisi log e network monitoring</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>ANALIZZARE VARIANTE:</strong> Identificare famiglia ransomware (LockBit, BlackCat, ecc.) e caratteristiche</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>VERIFICARE DECRYPTOR:</strong> Controllare su NoMoreRansom.org e altri database se esiste decryptor gratuito</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>VALUTARE BACKUP:</strong> Verificare disponibilità, integrità e data ultimo backup valido</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>RICOSTRUIRE TIMELINE:</strong> Identificare punto di ingresso e timeline dell'attacco</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>VALUTARE ESFILTRAZIONE:</strong> Verificare se dati sono stati esfiltrati (double extortion)</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>DECISIONE STRATEGICA:</strong> Management decide: ripristino da backup vs pagamento riscatto (raccomandazione: NON PAGARE)</div>
|
||
</div>
|
||
</div>
|
||
</div>
|
||
|
||
<div class="output-section">
|
||
<div class="output-section-title">FASE 3: Eradicazione (1-4 ore)</div>
|
||
<div class="checklist">
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>RIMUOVERE MALWARE:</strong> Eliminare completamente ransomware da tutti i sistemi</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>CHIUDERE VETTORE ATTACCO:</strong> Patchare vulnerabilità sfruttate o chiudere vettore di ingresso</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>ELIMINARE PERSISTENZE:</strong> Rimuovere backdoor, scheduled tasks, registry keys malevoli</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>RESET CREDENZIALI:</strong> Forzare cambio password tutti gli account, specialmente amministrativi</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>SCANSIONE COMPLETA:</strong> Eseguire scansione antimalware su tutta l'infrastruttura</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>VERIFICARE ERADICAZIONE:</strong> Confermare assenza IoC su tutti i sistemi</div>
|
||
</div>
|
||
</div>
|
||
</div>
|
||
|
||
<div class="output-section">
|
||
<div class="output-section-title">FASE 4: Ripristino (4-24 ore)</div>
|
||
<div class="checklist">
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>PRIORITIZZARE SERVIZI:</strong> Seguire matrice priorità ripristino (P1 → P2 → P3)</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>RIPRISTINARE DA BACKUP:</strong> Restore da ultimo backup pulito verificato</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>REBUILD SE NECESSARIO:</strong> Ricostruire da zero sistemi gravemente compromessi</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>HARDENING:</strong> Applicare configurazioni di sicurezza rafforzate</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>TEST VALIDAZIONE:</strong> Eseguire test funzionali e di sicurezza</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>MONITORAGGIO INTENSIVO:</strong> Attivare monitoraggio 24/7 per 72 ore</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>COMUNICARE RIPRISTINO:</strong> Informare stakeholder del completamento</div>
|
||
</div>
|
||
</div>
|
||
</div>
|
||
|
||
<div class="output-section">
|
||
<div class="output-section-title">FASE 5: Post-Incident (entro 7 giorni)</div>
|
||
<div class="checklist">
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>NOTIFICA CSIRT:</strong> Completare notifica finale al CSIRT Italia entro 1 mese</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>NOTIFICA GPDP:</strong> Se dati personali compromessi, notificare Garante Privacy</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>POST-INCIDENT REVIEW:</strong> Condurre PIR completo con tutti gli stakeholder</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>IMPLEMENTARE MIGLIORAMENTI:</strong> Attuare azioni correttive identificate</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>AGGIORNARE PLAYBOOK:</strong> Incorporare lezioni apprese nel playbook</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>TRAINING:</strong> Condurre sessioni formative basate sull'incidente</div>
|
||
</div>
|
||
</div>
|
||
</div>
|
||
|
||
<div class="info-box warning-box" style="margin-top: 16px;">
|
||
<div class="info-box-title">🚫 POLICY AZIENDALE: NON PAGARE IL RISCATTO</div>
|
||
<div class="info-box-content">
|
||
La policy aziendale è di <strong>NON PAGARE MAI</strong> il riscatto per i seguenti motivi:<br>
|
||
• Finanzia attività criminali<br>
|
||
• Non garantisce recupero dati<br>
|
||
• Marca l'organizzazione come target futuro<br>
|
||
• Può violare sanzioni internazionali<br>
|
||
• Abbiamo backup e procedure di ripristino efficaci<br>
|
||
<br>
|
||
Qualsiasi eccezione richiede approvazione CEO + Board
|
||
</div>
|
||
</div>
|
||
|
||
<div class="output-section">
|
||
<div class="output-section-title">Contatti Chiave</div>
|
||
<table style="width: 100%; font-size: 12px;">
|
||
<tr>
|
||
|
||
<td style="padding: 8px; background-color: var(--bg-tertiary);"><strong>CISO</strong></td>
|
||
<td style="padding: 8px;">[Nome] - +39 XXX XXX 002</td>
|
||
</tr>
|
||
<tr>
|
||
<td style="padding: 8px; background-color: var(--bg-tertiary);"><strong>IT Operations Manager</strong></td>
|
||
<td style="padding: 8px;">[Nome] - +39 XXX XXX 003</td>
|
||
</tr>
|
||
<tr>
|
||
<td style="padding: 8px; background-color: var(--bg-tertiary);"><strong>Forensics Expert</strong></td>
|
||
<td style="padding: 8px;">[Nome Consulente Esterno] - +39 XXX XXX 004</td>
|
||
</tr>
|
||
<tr>
|
||
<td style="padding: 8px; background-color: var(--bg-tertiary);"><strong>Legal Counsel</strong></td>
|
||
<td style="padding: 8px;">[Nome] - +39 XXX XXX 005</td>
|
||
</tr>
|
||
<tr>
|
||
<td style="padding: 8px; background-color: var(--bg-tertiary);"><strong>CSIRT Italia</strong></td>
|
||
<td style="padding: 8px;">+39 06 XXXX XXXX | csirt@acn.gov.it</td>
|
||
</tr>
|
||
<tr>
|
||
<td style="padding: 8px; background-color: var(--bg-tertiary);"><strong>Polizia Postale</strong></td>
|
||
<td style="padding: 8px;">+39 06 XXXX XXXX</td>
|
||
</tr>
|
||
</table>
|
||
</div>
|
||
|
||
<div class="output-section">
|
||
<div class="output-section-title">Risorse Utili</div>
|
||
<div style="font-size: 13px; line-height: 2;">
|
||
• <strong>No More Ransom:</strong> https://www.nomoreransom.org<br>
|
||
• <strong>ID Ransomware:</strong> https://id-ransomware.malwarehunterteam.com<br>
|
||
• <strong>CISA Ransomware Guide:</strong> https://www.cisa.gov/stopransomware<br>
|
||
• <strong>Europol Ransomware:</strong> https://www.europol.europa.eu/ransomware<br>
|
||
• <strong>ACN CSIRT Italia:</strong> https://csirt.acn.gov.it
|
||
</div>
|
||
</div>
|
||
</div>
|
||
<div class="output-actions">
|
||
<button class="btn btn-danger" onclick="alert('Playbook attivato - IR Team notificato')">🚨 Attiva Playbook</button>
|
||
<button class="btn btn-interactive" onclick="alert('PDF stampato')">🖨️ Stampa</button>
|
||
<button class="btn" onclick="closeOutput()">Chiudi</button>
|
||
</div>
|
||
`;
|
||
}
|
||
|
||
function generatePlaybookBreach() {
|
||
return `
|
||
<div class="output-header">
|
||
<div class="output-title">🚪 Playbook Data Breach</div>
|
||
<div class="output-subtitle">Procedura per violazioni dati e accessi non autorizzati</div>
|
||
</div>
|
||
<div class="output-body">
|
||
<div class="info-box danger-box">
|
||
<div class="info-box-title">⚠️ ATTIVAZIONE IMMEDIATA</div>
|
||
<div class="info-box-content">
|
||
Attivare immediatamente in caso di:<br>
|
||
• Rilevazione esfiltrazione dati<br>
|
||
• Accesso non autorizzato a database/sistemi critici<br>
|
||
• Furto credenziali amministrative<br>
|
||
• Alert SIEM per data exfiltration<br>
|
||
• Segnalazione dati aziendali su dark web
|
||
</div>
|
||
</div>
|
||
|
||
<div class="output-section">
|
||
<div class="output-section-title">FASE 1: Contenimento (0-30 minuti)</div>
|
||
<div class="checklist">
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>BLOCCARE ACCESSO:</strong> Revocare immediatamente credenziali compromesse</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>ISOLARE SISTEMI:</strong> Disconnettere sistemi compromessi dalla rete</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>BLOCCARE ESFILTRAZIONE:</strong> Implementare regole firewall per bloccare traffico verso destinazioni sospette</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>PRESERVARE EVIDENZE:</strong> Acquisire log, memoria, traffico di rete</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>ATTIVARE TEAM:</strong> Notificare IR Team, DPO, Legal</div>
|
||
</div>
|
||
</div>
|
||
</div>
|
||
|
||
<div class="output-section">
|
||
<div class="output-section-title">FASE 2: Valutazione Impatto (30-120 minuti)</div>
|
||
<div class="checklist">
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>IDENTIFICARE DATI COMPROMESSI:</strong> Determinare tipologia e volume dati esfiltrati</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>CLASSIFICARE DATI:</strong> Personali comuni / Particolari (art.9 GDPR) / Giudiziari / Proprietari</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>CONTARE INTERESSATI:</strong> Numero di persone i cui dati sono stati compromessi</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>VALUTARE RISCHI:</strong> Rischio per diritti e libertà degli interessati</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>DETERMINARE OBBLIGHI:</strong> Notifica GPDP (72h) e/o comunicazione interessati richiesta?</div>
|
||
</div>
|
||
</div>
|
||
</div>
|
||
|
||
<div class="output-section">
|
||
<div class="output-section-title">FASE 3: Notifiche Obbligatorie</div>
|
||
<div class="info-box warning-box">
|
||
<div class="info-box-title">⏰ TEMPISTICHE CRITICHE</div>
|
||
<div class="info-box-content">
|
||
<strong>Garante Privacy (GPDP):</strong> Entro 72 ore dalla conoscenza della violazione<br>
|
||
<strong>CSIRT Italia:</strong> Entro 24h (preallarme) se incidente significativo<br>
|
||
<strong>Interessati:</strong> Senza ingiustificato ritardo se alto rischio
|
||
</div>
|
||
</div>
|
||
<div class="checklist" style="margin-top: 16px;">
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>NOTIFICA GPDP:</strong> Compilare e inviare notifica tramite portale Garante</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>NOTIFICA CSIRT:</strong> Se incidente significativo, notificare CSIRT Italia</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>COMUNICAZIONE INTERESSATI:</strong> Se alto rischio, informare direttamente le persone coinvolte</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>ALTRE AUTORITÀ:</strong> Notificare autorità settoriali se applicabile</div>
|
||
</div>
|
||
</div>
|
||
</div>
|
||
|
||
<div class="output-section">
|
||
<div class="output-section-title">FASE 4: Investigazione Forense</div>
|
||
<div class="checklist">
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>ANALISI FORENSE:</strong> Condurre analisi approfondita per ricostruire l'attacco</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>IDENTIFICARE VETTORE:</strong> Come l'attaccante ha ottenuto accesso</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>TIMELINE COMPLETA:</strong> Ricostruire tutti gli accessi e azioni dell'attaccante</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>VERIFICARE ESFILTRAZIONE:</strong> Confermare quali dati sono stati effettivamente esfiltrati</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>ATTRIBUTION:</strong> Tentare identificazione attaccante (se possibile)</div>
|
||
</div>
|
||
</div>
|
||
</div>
|
||
|
||
<div class="output-section">
|
||
<div class="output-section-title">FASE 5: Rimediazione</div>
|
||
<div class="checklist">
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>CHIUDERE VULNERABILITÀ:</strong> Patchare o mitigare la vulnerabilità sfruttata</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>RESET CREDENZIALI:</strong> Forzare cambio password per tutti gli account potenzialmente compromessi</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>IMPLEMENTARE MFA:</strong> Abilitare autenticazione multi-fattore dove mancante</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>RAFFORZARE MONITORAGGIO:</strong> Implementare alert per rilevare accessi simili in futuro</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>SERVIZI PROTEZIONE:</strong> Offrire credit monitoring agli interessati se applicabile</div>
|
||
</div>
|
||
</div>
|
||
</div>
|
||
|
||
<div class="info-box" style="margin-top: 16px;">
|
||
<div class="info-box-title">📋 Contenuti Notifica GPDP</div>
|
||
<div class="info-box-content">
|
||
La notifica al Garante deve contenere:<br>
|
||
• Natura della violazione<br>
|
||
• Categorie e numero approssimativo di interessati<br>
|
||
• Categorie e numero approssimativo di registrazioni<br>
|
||
• Conseguenze probabili della violazione<br>
|
||
• Misure adottate o proposte per rimediare<br>
|
||
• Nome e contatti del DPO o punto di contatto
|
||
</div>
|
||
</div>
|
||
</div>
|
||
<div class="output-actions">
|
||
<button class="btn btn-danger" onclick="alert('Playbook attivato')">🚨 Attiva Playbook</button>
|
||
<button class="btn btn-interactive" onclick="alert('Genera notifica GPDP')">📤 Notifica GPDP</button>
|
||
<button class="btn" onclick="closeOutput()">Chiudi</button>
|
||
</div>
|
||
`;
|
||
}
|
||
|
||
function generatePlaybookDDoS() {
|
||
return `
|
||
<div class="output-header">
|
||
<div class="output-title">⚡ Playbook DDoS Attack</div>
|
||
<div class="output-subtitle">Procedura per attacchi Denial of Service distribuiti</div>
|
||
</div>
|
||
<div class="output-body">
|
||
<div class="info-box danger-box">
|
||
<div class="info-box-title">⚠️ ATTIVAZIONE IMMEDIATA</div>
|
||
<div class="info-box-content">
|
||
Attivare in caso di:<br>
|
||
• Servizi web/applicazioni irraggiungibili<br>
|
||
• Traffico di rete anomalo (volume, pattern)<br>
|
||
• Alert IDS/IPS per flood attack<br>
|
||
• Saturazione banda o risorse server<br>
|
||
• Segnalazioni massive utenti su indisponibilità servizi
|
||
</div>
|
||
</div>
|
||
|
||
<div class="output-section">
|
||
<div class="output-section-title">FASE 1: Conferma e Classificazione (0-15 minuti)</div>
|
||
<div class="checklist">
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>CONFERMARE DDOS:</strong> Verificare che non sia problema tecnico legittimo</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>IDENTIFICARE TIPO:</strong> Layer 3/4 (volumetrico) o Layer 7 (applicativo)</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>MISURARE VOLUME:</strong> Quantificare Gbps/Mpps dell'attacco</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>IDENTIFICARE TARGET:</strong> Quali servizi/IP sono sotto attacco</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>ATTIVARE TEAM:</strong> Notificare Network Team, ISP, DDoS mitigation provider</div>
|
||
</div>
|
||
</div>
|
||
</div>
|
||
|
||
<div class="output-section">
|
||
<div class="output-section-title">FASE 2: Mitigazione Immediata (15-60 minuti)</div>
|
||
<div class="checklist">
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>ATTIVARE CLOUDFLARE/AKAMAI:</strong> Redirigere traffico verso servizio anti-DDoS</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>CONTATTARE ISP:</strong> Richiedere black-hole routing o scrubbing se necessario</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>RATE LIMITING:</strong> Implementare limiti di rate su firewall/load balancer</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>BLOCCARE IP SORGENTE:</strong> Blacklist IP attaccanti (se volume gestibile)</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>GEO-BLOCKING:</strong> Bloccare paesi da cui origina l'attacco (se non legittimi)</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>SCALING:</strong> Aumentare risorse cloud per assorbire traffico (se Layer 7)</div>
|
||
</div>
|
||
</div>
|
||
</div>
|
||
|
||
<div class="output-section">
|
||
<div class="output-section-title">FASE 3: Monitoraggio e Adattamento</div>
|
||
<div class="checklist">
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>MONITORARE EFFICACIA:</strong> Verificare se mitigazioni stanno funzionando</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>ADATTARE REGOLE:</strong> Modificare filtri in base all'evoluzione dell'attacco</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>COMUNICARE STATUS:</strong> Aggiornare status page e stakeholder ogni 30 minuti</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>RACCOGLIERE PCAP:</strong> Catturare campioni traffico per analisi</div>
|
||
</div>
|
||
</div>
|
||
</div>
|
||
|
||
<div class="output-section">
|
||
<div class="output-section-title">FASE 4: Post-Attack</div>
|
||
<div class="checklist">
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>ANALIZZARE ATTACCO:</strong> Studiare pattern, vettori, botnet utilizzate</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>NOTIFICARE AUTORITÀ:</strong> Segnalare a Polizia Postale e CSIRT se significativo</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>RAFFORZARE DIFESE:</strong> Implementare miglioramenti basati su lezioni apprese</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>DOCUMENTARE:</strong> Creare report dettagliato dell'incidente</div>
|
||
</div>
|
||
</div>
|
||
</div>
|
||
|
||
<div class="info-box" style="margin-top: 16px;">
|
||
<div class="info-box-title">🛡️ Difese Preventive</div>
|
||
<div class="info-box-content">
|
||
<strong>Raccomandazioni permanenti:</strong><br>
|
||
• Utilizzare CDN con protezione DDoS integrata<br>
|
||
• Mantenere contratto con DDoS mitigation provider<br>
|
||
• Implementare rate limiting a livello applicativo<br>
|
||
• Over-provisioning capacità di banda<br>
|
||
• Architettura distribuita e ridondante<br>
|
||
• Piano di comunicazione crisi pre-approvato
|
||
</div>
|
||
</div>
|
||
</div>
|
||
<div class="output-actions">
|
||
<button class="btn btn-danger" onclick="alert('Playbook attivato - Mitigazione in corso')">🚨 Attiva Mitigazione</button>
|
||
<button class="btn btn-interactive" onclick="alert('ISP contattato')">📞 Contatta ISP</button>
|
||
<button class="btn" onclick="closeOutput()">Chiudi</button>
|
||
</div>
|
||
`;
|
||
}
|
||
|
||
function generatePlaybookPhishing() {
|
||
return `
|
||
<div class="output-header">
|
||
<div class="output-title">🎣 Playbook Phishing/BEC</div>
|
||
<div class="output-subtitle">Procedura per attacchi phishing e Business Email Compromise</div>
|
||
</div>
|
||
<div class="output-body">
|
||
<div class="info-box danger-box">
|
||
<div class="info-box-title">⚠️ ATTIVAZIONE</div>
|
||
<div class="info-box-content">
|
||
Attivare in caso di:<br>
|
||
• Utente segnala email sospetta<br>
|
||
• Credenziali inserite in sito phishing<br>
|
||
• Bonifico fraudolento richiesto/eseguito (BEC)<br>
|
||
• Account email compromesso<br>
|
||
• Campagna phishing massiva rilevata
|
||
</div>
|
||
</div>
|
||
|
||
<div class="output-section">
|
||
<div class="output-section-title">FASE 1: Contenimento (0-30 minuti)</div>
|
||
<div class="checklist">
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>BLOCCARE ACCOUNT:</strong> Disabilitare immediatamente account compromesso</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>RESET PASSWORD:</strong> Forzare cambio password account vittima</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>REVOCARE SESSIONI:</strong> Terminare tutte le sessioni attive</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>BLOCCARE EMAIL:</strong> Quarantena email phishing su tutti i mailbox</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>BLOCCARE URL:</strong> Blacklist URL phishing su proxy/firewall</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>BLOCCARE BONIFICO:</strong> Se BEC, contattare immediatamente banca per bloccare trasferimento</div>
|
||
</div>
|
||
</div>
|
||
</div>
|
||
|
||
<div class="output-section">
|
||
<div class="output-section-title">FASE 2: Valutazione Impatto</div>
|
||
<div class="checklist">
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>VERIFICARE ACCESSI:</strong> Controllare log per accessi non autorizzati</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>CONTROLLARE REGOLE EMAIL:</strong> Verificare forwarding rules, filtri sospetti</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>ANALIZZARE EMAIL INVIATE:</strong> Verificare se l'attaccante ha inviato email da account compromesso</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>IDENTIFICARE VITTIME:</strong> Quanti utenti hanno ricevuto/cliccato email phishing</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>VALUTARE DANNI FINANZIARI:</strong> Se BEC, quantificare importo trasferito</div>
|
||
</div>
|
||
</div>
|
||
</div>
|
||
|
||
<div class="output-section">
|
||
<div class="output-section-title">FASE 3: Eradicazione e Ripristino</div>
|
||
<div class="checklist">
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>RIMUOVERE REGOLE MALEVOLE:</strong> Eliminare forwarding rules e filtri creati dall'attaccante</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>ABILITARE MFA:</strong> Forzare MFA su account compromesso</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>SCANSIONE MALWARE:</strong> Se allegato scaricato, scansione completa endpoint</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>RIPRISTINARE ACCESSO:</strong> Riabilitare account dopo verifica pulizia</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>NOTIFICARE CONTATTI:</strong> Se email inviate da account compromesso, avvisare destinatari</div>
|
||
</div>
|
||
</div>
|
||
</div>
|
||
|
||
<div class="output-section">
|
||
<div class="output-section-title">FASE 4: Prevenzione Futura</div>
|
||
<div class="checklist">
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>AWARENESS TRAINING:</strong> Sessione formativa immediata per utenti coinvolti</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>AGGIORNARE FILTRI:</strong> Aggiungere IoC a filtri anti-spam/phishing</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>IMPLEMENTARE DMARC:</strong> Configurare SPF, DKIM, DMARC se mancanti</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>BANNER ESTERNI:</strong> Aggiungere warning banner su email esterne</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>PROCESSO BONIFICI:</strong> Rafforzare processo approvazione bonifici (doppia verifica)</div>
|
||
</div>
|
||
</div>
|
||
</div>
|
||
|
||
<div class="info-box warning-box" style="margin-top: 16px;">
|
||
<div class="info-box-title">💰 Procedura BEC Specifica</div>
|
||
<div class="info-box-content">
|
||
Se bonifico fraudolento eseguito:<br>
|
||
<strong>1. IMMEDIATO (entro 15 min):</strong> Contattare banca per blocco urgente<br>
|
||
<strong>2. Denuncia (entro 24h):</strong> Presentare denuncia Polizia Postale<br>
|
||
<strong>3. Banca destinataria:</strong> Contattare banca beneficiaria per recupero fondi<br>
|
||
<strong>4. Legal:</strong> Coinvolgere ufficio legale per azioni di recupero<br>
|
||
<strong>5. Assicurazione:</strong> Notificare compagnia assicurativa (cyber insurance)
|
||
</div>
|
||
</div>
|
||
</div>
|
||
<div class="output-actions">
|
||
<button class="btn btn-danger" onclick="alert('Playbook attivato')">🚨 Attiva Playbook</button>
|
||
<button class="btn btn-interactive" onclick="alert('Account bloccato')">🔒 Blocca Account</button>
|
||
<button class="btn" onclick="closeOutput()">Chiudi</button>
|
||
</div>
|
||
`;
|
||
}
|
||
|
||
function generatePlaybookMalware() {
|
||
return `
|
||
<div class="output-header">
|
||
<div class="output-title">🦠 Playbook Malware Infection</div>
|
||
<div class="output-subtitle">Procedura per infezioni malware generalizzate</div>
|
||
</div>
|
||
<div class="output-body">
|
||
<div class="info-box danger-box">
|
||
<div class="info-box-title">⚠️ ATTIVAZIONE</div>
|
||
<div class="info-box-content">
|
||
Attivare in caso di:<br>
|
||
• Alert antivirus/EDR per malware<br>
|
||
• Comportamento anomalo endpoint<br>
|
||
• Propagazione malware nella rete<br>
|
||
• Trojan/backdoor rilevati<br>
|
||
• Cryptominer o botnet identificati
|
||
</div>
|
||
</div>
|
||
|
||
<div class="output-section">
|
||
<div class="output-section-title">FASE 1: Contenimento (0-30 minuti)</div>
|
||
<div class="checklist">
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>ISOLARE ENDPOINT:</strong> Disconnettere sistemi infetti dalla rete</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>BLOCCARE C&C:</strong> Blacklist domini/IP command & control</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>QUARANTENA AUTOMATICA:</strong> Attivare quarantena automatica su EDR</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>ACQUISIRE SAMPLE:</strong> Raccogliere campione malware per analisi</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>SCANSIONE RETE:</strong> Lanciare scansione completa su tutti gli endpoint</div>
|
||
</div>
|
||
</div>
|
||
</div>
|
||
|
||
<div class="output-section">
|
||
<div class="output-section-title">FASE 2: Analisi Malware</div>
|
||
<div class="checklist">
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>IDENTIFICARE FAMIGLIA:</strong> Determinare tipo e famiglia malware</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>ANALISI STATICA:</strong> Hash, strings, metadata del file</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>ANALISI DINAMICA:</strong> Esecuzione in sandbox per behavior analysis</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>IDENTIFICARE IoC:</strong> Estrarre indicatori di compromissione</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>DETERMINARE CAPACITÀ:</strong> Cosa fa il malware (keylogger, backdoor, ecc.)</div>
|
||
</div>
|
||
</div>
|
||
</div>
|
||
|
||
<div class="output-section">
|
||
<div class="output-section-title">FASE 3: Eradicazione</div>
|
||
<div class="checklist">
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>RIMOZIONE MALWARE:</strong> Eliminare malware da tutti i sistemi infetti</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>ELIMINARE PERSISTENZE:</strong> Rimuovere registry keys, scheduled tasks, servizi</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>AGGIORNARE SIGNATURE:</strong> Aggiornare definizioni antivirus con nuovi IoC</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>PATCHING:</strong> Applicare patch per vulnerabilità sfruttate</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>VERIFICA PULIZIA:</strong> Scansione completa per confermare rimozione</div>
|
||
</div>
|
||
</div>
|
||
</div>
|
||
|
||
<div class="output-section">
|
||
<div class="output-section-title">FASE 4: Ripristino e Hardening</div>
|
||
<div class="checklist">
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>RICONNETTERE SISTEMI:</strong> Gradualmente riportare online sistemi puliti</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>MONITORAGGIO INTENSIVO:</strong> Sorveglianza 48h per rilevare reinfezioni</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>HARDENING:</strong> Implementare configurazioni sicurezza rafforzate</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>AWARENESS:</strong> Formazione utenti su vettore di infezione</div>
|
||
</div>
|
||
</div>
|
||
</div>
|
||
|
||
<div class="info-box" style="margin-top: 16px;">
|
||
<div class="info-box-title">🔍 Risorse Analisi Malware</div>
|
||
<div class="info-box-content">
|
||
• <strong>VirusTotal:</strong> https://www.virustotal.com<br>
|
||
• <strong>Hybrid Analysis:</strong> https://www.hybrid-analysis.com<br>
|
||
• <strong>ANY.RUN:</strong> https://any.run<br>
|
||
• <strong>Joe Sandbox:</strong> https://www.joesandbox.com<br>
|
||
• <strong>MalwareBazaar:</strong> https://bazaar.abuse.ch
|
||
</div>
|
||
</div>
|
||
</div>
|
||
<div class="output-actions">
|
||
<button class="btn btn-danger" onclick="alert('Playbook attivato - Sistemi in quarantena')">🚨 Attiva Playbook</button>
|
||
<button class="btn btn-interactive" onclick="alert('Scansione rete avviata')">🔍 Scansione Rete</button>
|
||
<button class="btn" onclick="closeOutput()">Chiudi</button>
|
||
</div>
|
||
`;
|
||
}
|
||
|
||
function generatePlaybookAccess() {
|
||
return `
|
||
<div class="output-header">
|
||
<div class="output-title">🔓 Playbook Unauthorized Access</div>
|
||
<div class="output-subtitle">Procedura per accessi non autorizzati a sistemi critici</div>
|
||
</div>
|
||
<div class="output-body">
|
||
<div class="info-box danger-box">
|
||
<div class="info-box-title">⚠️ ATTIVAZIONE</div>
|
||
<div class="info-box-content">
|
||
Attivare in caso di:<br>
|
||
• Login da location/IP anomalo<br>
|
||
• Accesso con credenziali rubate<br>
|
||
• Privilege escalation rilevata<br>
|
||
• Accesso a sistemi critici fuori orario<br>
|
||
• Alert SIEM per comportamento anomalo account
|
||
</div>
|
||
</div>
|
||
|
||
<div class="output-section">
|
||
<div class="output-section-title">FASE 1: Blocco Immediato (0-15 minuti)</div>
|
||
<div class="checklist">
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>TERMINARE SESSIONE:</strong> Killare immediatamente sessione attiva sospetta</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>BLOCCARE ACCOUNT:</strong> Disabilitare account compromesso</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>BLOCCARE IP:</strong> Blacklist IP sorgente dell'accesso</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>ISOLARE SISTEMA:</strong> Se accesso a sistema critico, isolare dalla rete</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>PRESERVARE LOG:</strong> Acquisire tutti i log di accesso e attività</div>
|
||
</div>
|
||
</div>
|
||
</div>
|
||
|
||
<div class="output-section">
|
||
<div class="output-section-title">FASE 2: Investigazione (15-120 minuti)</div>
|
||
<div class="checklist">
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>ANALIZZARE LOG:</strong> Ricostruire tutte le azioni dell'attaccante</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>IDENTIFICARE VETTORE:</strong> Come ha ottenuto accesso (credenziali rubate, vulnerabilità, ecc.)</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>VERIFICARE DATI ACCESSATI:</strong> Quali dati/sistemi sono stati visualizzati/modificati</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>CERCARE BACKDOOR:</strong> Verificare se l'attaccante ha creato persistenze</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>MOVIMENTO LATERALE:</strong> Controllare se ha acceduto ad altri sistemi</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>ESFILTRAZIONE:</strong> Verificare se dati sono stati esfiltrati</div>
|
||
</div>
|
||
</div>
|
||
</div>
|
||
|
||
<div class="output-section">
|
||
<div class="output-section-title">FASE 3: Rimediazione</div>
|
||
<div class="checklist">
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>RESET CREDENZIALI:</strong> Forzare cambio password account compromesso e correlati</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>RIMUOVERE BACKDOOR:</strong> Eliminare eventuali persistenze create</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>PATCHARE VULNERABILITÀ:</strong> Correggere vulnerabilità sfruttata</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>IMPLEMENTARE MFA:</strong> Abilitare autenticazione multi-fattore</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>RIDURRE PRIVILEGI:</strong> Applicare principio least privilege</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>RAFFORZARE MONITORING:</strong> Implementare alert per rilevare accessi simili</div>
|
||
</div>
|
||
</div>
|
||
</div>
|
||
|
||
<div class="output-section">
|
||
<div class="output-section-title">FASE 4: Notifiche e Follow-up</div>
|
||
<div class="checklist">
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>NOTIFICARE UTENTE:</strong> Informare proprietario account della compromissione</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>NOTIFICARE MANAGEMENT:</strong> Briefing a management su impatto e azioni</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>VALUTARE NOTIFICA CSIRT:</strong> Se significativo, notificare CSIRT Italia</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>VALUTARE NOTIFICA GPDP:</strong> Se dati personali accessati, valutare notifica Garante</div>
|
||
</div>
|
||
<div class="checklist-item">
|
||
<div class="checklist-checkbox"></div>
|
||
<div class="checklist-text"><strong>DENUNCIA AUTORITÀ:</strong> Considerare denuncia a Polizia Postale</div>
|
||
</div>
|
||
</div>
|
||
</div>
|
||
|
||
<div class="info-box" style="margin-top: 16px;">
|
||
<div class="info-box-title">🔍 Indicatori di Accesso Non Autorizzato</div>
|
||
<div class="info-box-content">
|
||
• Login da geolocation anomala (impossibile travel time)<br>
|
||
• Accesso fuori orario lavorativo abituale<br>
|
||
• Multiple failed login attempts seguiti da successo<br>
|
||
• Accesso da IP/device mai visti prima<br>
|
||
• User-agent anomalo o tool automatizzati<br>
|
||
• Privilege escalation non autorizzata<br>
|
||
• Accesso a risorse normalmente non utilizzate dall'utente
|
||
</div>
|
||
</div>
|
||
</div>
|
||
<div class="output-actions">
|
||
<button class="btn btn-danger" onclick="alert('Playbook attivato - Accesso bloccato')">🚨 Blocca Accesso</button>
|
||
<button class="btn btn-interactive" onclick="alert('Analisi forense avviata')">🔍 Analisi Forense</button>
|
||
<button class="btn" onclick="closeOutput()">Chiudi</button>
|
||
</div>
|
||
`;
|
||
}
|
||
|
||
function generateExerciseReport() {
|
||
return `
|
||
<div class="output-header">
|
||
<div class="output-title">📊 Template Report Esercitazione</div>
|
||
<div class="output-subtitle">Report di valutazione post-esercitazione</div>
|
||
</div>
|
||
<div class="output-body">
|
||
<div class="output-section">
|
||
<div class="output-section-title">Informazioni Esercitazione</div>
|
||
<table style="width: 100%; font-size: 13px;">
|
||
<tr>
|
||
<td style="padding: 8px; width: 30%; background-color: var(--bg-tertiary);"><strong>Tipo Esercitazione</strong></td>
|
||
<td style="padding: 8px;">[Tabletop / Walkthrough / Simulation / Full-Scale]</td>
|
||
</tr>
|
||
<tr>
|
||
<td style="padding: 8px; background-color: var(--bg-tertiary);"><strong>Data</strong></td>
|
||
<td style="padding: 8px;">[GG/MM/AAAA]</td>
|
||
</tr>
|
||
<tr>
|
||
<td style="padding: 8px; background-color: var(--bg-tertiary);"><strong>Durata</strong></td>
|
||
<td style="padding: 8px;">[Ore]</td>
|
||
</tr>
|
||
<tr>
|
||
<td style="padding: 8px; background-color: var(--bg-tertiary);"><strong>Scenario</strong></td>
|
||
<td style="padding: 8px;">[Descrizione scenario testato]</td>
|
||
</tr>
|
||
<tr>
|
||
<td style="padding: 8px; background-color: var(--bg-tertiary);"><strong>Facilitatore</strong></td>
|
||
<td style="padding: 8px;">[Nome Cognome - Ruolo]</td>
|
||
</tr>
|
||
</table>
|
||
</div>
|
||
|
||
<div class="output-section">
|
||
<div class="output-section-title">Partecipanti</div>
|
||
<table style="width: 100%; font-size: 12px;">
|
||
<thead>
|
||
<tr style="background-color: var(--bg-tertiary);">
|
||
<th style="padding: 8px;">Nome</th>
|
||
<th style="padding: 8px;">Ruolo</th>
|
||
<th style="padding: 8px;">Dipartimento</th>
|
||
<th style="padding: 8px;">Presenza</th>
|
||
</tr>
|
||
</thead>
|
||
<tbody>
|
||
<tr>
|
||
<td style="padding: 8px;">[Nome Cognome]</td>
|
||
<td style="padding: 8px;">[Ruolo]</td>
|
||
<td style="padding: 8px;">[Dipartimento]</td>
|
||
<td style="padding: 8px;">✅ Presente</td>
|
||
</tr>
|
||
<tr>
|
||
<td style="padding: 8px;" colspan="4">[Aggiungere tutti i partecipanti]</td>
|
||
</tr>
|
||
</tbody>
|
||
</table>
|
||
</div>
|
||
|
||
<div class="output-section">
|
||
<div class="output-section-title">Obiettivi Esercitazione</div>
|
||
<div style="font-size: 13px; line-height: 2;">
|
||
1. [Obiettivo 1]<br>
|
||
2. [Obiettivo 2]<br>
|
||
3. [Obiettivo 3]
|
||
</div>
|
||
</div>
|
||
|
||
<div class="output-section">
|
||
<div class="output-section-title">Valutazione Performance</div>
|
||
<table style="width: 100%; font-size: 12px;">
|
||
<thead>
|
||
<tr style="background-color: var(--bg-tertiary);">
|
||
<th style="padding: 8px;">Area</th>
|
||
<th style="padding: 8px;">Valutazione</th>
|
||
<th style="padding: 8px;">Note</th>
|
||
</tr>
|
||
</thead>
|
||
<tbody>
|
||
<tr>
|
||
<td style="padding: 8px;"><strong>Rilevazione Incidente</strong></td>
|
||
<td style="padding: 8px;"><span style="color: var(--success);">✅ Eccellente</span></td>
|
||
<td style="padding: 8px;">[Note]</td>
|
||
</tr>
|
||
<tr>
|
||
<td style="padding: 8px;"><strong>Comunicazione Interna</strong></td>
|
||
<td style="padding: 8px;"><span style="color: var(--success);">✅ Buono</span></td>
|
||
<td style="padding: 8px;">[Note]</td>
|
||
</tr>
|
||
<tr>
|
||
<td style="padding: 8px;"><strong>Processo Decisionale</strong></td>
|
||
<td style="padding: 8px;"><span style="color: var(--warning);">⚠️ Da Migliorare</span></td>
|
||
<td style="padding: 8px;">[Note]</td>
|
||
</tr>
|
||
<tr>
|
||
<td style="padding: 8px;"><strong>Coordinamento Team</strong></td>
|
||
<td style="padding: 8px;"><span style="color: var(--success);">✅ Buono</span></td>
|
||
<td style="padding: 8px;">[Note]</td>
|
||
</tr>
|
||
<tr>
|
||
<td style="padding: 8px;"><strong>Utilizzo Procedure</strong></td>
|
||
<td style="padding: 8px;"><span style="color: var(--success);">✅ Eccellente</span></td>
|
||
<td style="padding: 8px;">[Note]</td>
|
||
</tr>
|
||
<tr>
|
||
<td style="padding: 8px;"><strong>Gestione Stakeholder</strong></td>
|
||
<td style="padding: 8px;"><span style="color: var(--warning);">⚠️ Da Migliorare</span></td>
|
||
<td style="padding: 8px;">[Note]</td>
|
||
</tr>
|
||
</tbody>
|
||
</table>
|
||
</div>
|
||
|
||
<div class="output-section">
|
||
<div class="output-section-title">Punti di Forza</div>
|
||
<div style="font-size: 13px; line-height: 2;">
|
||
• [Punto di forza 1]<br>
|
||
• [Punto di forza 2]<br>
|
||
• [Punto di forza 3]
|
||
</div>
|
||
</div>
|
||
|
||
<div class="output-section">
|
||
<div class="output-section-title">Aree di Miglioramento</div>
|
||
<div style="font-size: 13px; line-height: 2;">
|
||
• [Area di miglioramento 1]<br>
|
||
• [Area di miglioramento 2]<br>
|
||
• [Area di miglioramento 3]
|
||
</div>
|
||
</div>
|
||
|
||
<div class="output-section">
|
||
<div class="output-section-title">Azioni Correttive</div>
|
||
<table style="width: 100%; font-size: 12px;">
|
||
<thead>
|
||
<tr style="background-color: var(--bg-tertiary);">
|
||
<th style="padding: 8px;">ID</th>
|
||
<th style="padding: 8px;">Azione</th>
|
||
<th style="padding: 8px;">Responsabile</th>
|
||
<th style="padding: 8px;">Deadline</th>
|
||
</tr>
|
||
</thead>
|
||
<tbody>
|
||
<tr>
|
||
<td style="padding: 8px;">EX-001</td>
|
||
<td style="padding: 8px;">[Descrizione azione]</td>
|
||
<td style="padding: 8px;">[Nome]</td>
|
||
<td style="padding: 8px;">[Data]</td>
|
||
</tr>
|
||
<tr>
|
||
<td style="padding: 8px;" colspan="4">[Aggiungere tutte le azioni]</td>
|
||
</tr>
|
||
</tbody>
|
||
</table>
|
||
</div>
|
||
|
||
<div class="output-section">
|
||
<div class="output-section-title">Raccomandazioni</div>
|
||
<div style="font-size: 13px; line-height: 2;">
|
||
1. [Raccomandazione 1]<br>
|
||
2. [Raccomandazione 2]<br>
|
||
3. [Raccomandazione 3]
|
||
</div>
|
||
</div>
|
||
|
||
<div class="output-section">
|
||
<div class="output-section-title">Prossima Esercitazione</div>
|
||
<div style="font-size: 13px;">
|
||
<strong>Data pianificata:</strong> [Data]<br>
|
||
<strong>Tipo:</strong> [Tipo esercitazione]<br>
|
||
<strong>Focus:</strong> [Aree da testare basate su gap identificati]
|
||
</div>
|
||
</div>
|
||
|
||
<div class="output-section">
|
||
<div class="output-section-title">Approvazioni</div>
|
||
<table style="width: 100%; font-size: 13px;">
|
||
<tr>
|
||
<td style="padding: 8px; width: 30%; background-color: var(--bg-tertiary);"><strong>Preparato da</strong></td>
|
||
<td style="padding: 8px;">[Nome] - [Ruolo] - [Data]</td>
|
||
</tr>
|
||
<tr>
|
||
<td style="padding: 8px; background-color: var(--bg-tertiary);"><strong>Approvato da</strong></td>
|
||
<td style="padding: 8px;">[Nome] - [CISO] - [Data]</td>
|
||
</tr>
|
||
</table>
|
||
</div>
|
||
</div>
|
||
<div class="output-actions">
|
||
<button class="btn btn-primary" onclick="alert('Report salvato')">💾 Salva Report</button>
|
||
<button class="btn btn-interactive" onclick="alert('PDF generato')">📄 Genera PDF</button>
|
||
<button class="btn" onclick="alert('Report distribuito')">📧 Distribuisci</button>
|
||
<button class="btn" onclick="closeOutput()">Chiudi</button>
|
||
</div>
|
||
`;
|
||
}
|
||
|
||
// Chiudi modale cliccando fuori
|
||
window.onclick = function(event) {
|
||
const modal = document.getElementById('outputModal');
|
||
if (event.target == modal) {
|
||
closeOutput();
|
||
}
|
||
}
|
||
</script>
|
||
</body>
|
||
</html>
|