Integrating Cyber Threat Intelligence Into Your Security Team and Your Organization: Not Just Another Open Source Intelligence How To

No ratings

Presented at TechnoSecurity&DigitalForensics 2019 by

Cyber Threat Intelligence (CTI) can be invaluable to incident response, Security Operations Center (SOC) activities, and general information security. However, there is often a disconnect between CTI tasks and organizational structure. CTI analysts tend to operate as adjuncts to other functions (dotted line on organizational charts) or simply fill-in another title. This session examines the actual work produced by CTI within the scope of the organization’s mission. CTI is integrated with a SOC/IR Team model using a Crisis Management-based IR Plan methodology. This session formalizes the natural fit for CTI observed in many client security teams over the last several years. Using a role-based integration, CTI analysts at varying levels of experience can be integrated into the information security structure. This provides a career path for CTI practitioners without requiring a large department, reducing turnover. Integrating CTI into a continuous improvement model with brief, content-focused input reduces the burden on the analyst and other team members. CTI becomes actionable by owning the integration with other teams. Clarified integrations provide an expectation of the value provided by CTI and focuses CTI on the needs of internal consumers. CTI focuses on the best source of actionable cyber threat intelligence, that generated by the organization itself. Regular interaction with security functions prioritizes threats observed in the immediate environment.