Scenario
Apply controls according to your ONTAP release, license, risk model, and change process. Feature availability differs by platform and version.
Before you change production
Commands and screens can differ by release and platform. Replace example names and documentation IP addresses. Check prerequisites, impact, current health and rollback with your change owner.
1. Reduce administrative exposure
- Inventory cluster and SVM administrators, external authentication, management LIF reachability, SSH/HTTPS settings and unused services. Use least privilege and named accounts.
- Configure supported MFA and audit logging. Restrict management interfaces to approved networks; verify a break-glass recovery path before changing authentication.
Verify
Named roles, auditable access and an approved emergency login test.
2. Protect the data and the backups
- Review snapshot policy, off-cluster replication and backup retention. Add immutable or tamper-resistant controls where supported and required.
- Evaluate Autonomous Ransomware Protection and multi-admin verification for sensitive actions. Pilot on representative workloads and document alert response before broad rollout.
Read-only inventory
security login show
volume snapshot show
snapmirror show
system health alert show3. Exercise incident response
- Create an isolated restore test, verify application consistency and permissions, and measure RTO/RPO.
- For a suspected ransomware incident, preserve evidence and isolate affected clients through the incident team. Avoid deleting suspect snapshots or approving mass changes before the forensic and recovery decision.
Verify
Restorable off-cluster recovery point and documented incident owner.
If validation fails
- If an administrator loses access after an authentication change, use the documented break-glass method rather than weakening controls broadly.
- If ransomware protection raises a suspect event, preserve snapshots and logs, identify impacted clients and follow the incident team decision tree.
- If a restore drill fails, investigate backup completeness, permissions and application consistency. A successful copy operation alone is not recovery evidence.
Verify
Re-run the original validation and record the observed result, exact error, time, and corrective action.