How to Prioritize Cyber Threat Intelligence

355 views
β€’
February 25, 2020
by
RSAC Cybersecurity
YouTube video player
How to Prioritize Cyber Threat Intelligence

TL;DR

Start threat prioritization by identifying stakeholders, the decisions they make, and the intelligence they need. Convert those requirements into an adaptable collection plan, then combine skilled human analysts with suitable tools, data access, and enough time to interpret threats and produce actionable support for security operations and the wider business.

Transcript

All right, our final talk of the day is going to be a panel called Prioritizing Threats: What Would Threat Researchers Do? Uh, I'll let AJ Nash introduce his panelists, but, uh, yeah, the whole team can come on up. Little energy left. I know we're getting near the end of the day, right? All right, so... Is this working? Yeah. Good. Uh, we're short ... Read More

Key Insights

  • Intelligence requirements are the foundation of a threat intelligence program because they connect collection and analysis to stakeholder needs, operational decisions, and information gaps encountered during incidents or investigations.
  • Threat intelligence is most useful when it is integrated with security operations and the wider business, rather than functioning as an isolated discipline that produces information without direct operational connections.
  • A collection plan is the method for obtaining information that answers established intelligence requirements, and it must be reassessed whenever stakeholders introduce new requirements or their decision-making needs change.
  • Effective requirements are more specific than broad requests to find threats in sectors such as healthcare or aerospace, because analysts need a focused area of inquiry before they can locate relevant advanced or targeted activity.
  • Human analysts are essential because automated appliances can flag suspicious conditions, but people must understand the information, interpret its significance, and transform it into intelligence that others can act upon.
  • Staffing decisions are driven by requirements because the organization may need analysts with particular threat expertise, including experience with nation-state, criminal, or hacktivist activity and relevant linguistic capabilities.
  • Intelligence capability depends on talent, access, and time: skilled people need suitable tools and source material, along with sufficient time to analyze what they collect and produce meaningful results.
  • Tools and infrastructure cannot independently deliver effective intelligence, but talented analysts without appropriate access and technical support face the same limitation, making both human and technical capabilities necessary.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: How should an organization prioritize cyber threats?

An organization should begin by identifying its stakeholders and understanding the decisions they must make during security operations, incidents, and investigations. Those decision needs should become explicit intelligence requirements. The organization can then build a collection plan around the required information and assign analysts, tools, access, infrastructure, and time according to the threats and business functions being supported.

Q: What are intelligence requirements in cybersecurity?

Intelligence requirements are defined statements of what stakeholders need to know to make operational or business decisions. They can originate from information that responders wished they had while handling an incident or investigating an event. These requirements guide the intelligence program by determining what information should be collected, which capabilities are needed, and what analysis will provide useful support.

Q: Why should threat intelligence integrate with security operations?

Threat intelligence should integrate with security operations because security practitioners are among the customers who must use intelligence to make decisions. If intelligence and operations remain separate, collected information may not address real operational needs. Direct integration helps analysts understand incidents, investigations, and stakeholder questions, allowing their collection and analysis to produce information that can support practical action.

Q: How do you build a threat intelligence collection plan?

A collection plan begins with established intelligence requirements. For each requirement, the team determines how it can obtain the information needed to answer the stakeholder's question. The plan should account for available sources, tools, analysts, and access. It is not a one-time document, because new or revised requirements require corresponding adjustments to collection activities and supporting capabilities.

Q: Why are human analysts necessary for threat intelligence?

Human analysts are necessary because an automated appliance may indicate that something is bad without explaining what the signal means in its operational context. Analysts interpret the available information, connect it to stakeholder requirements, and determine whether it can support action. They also investigate advanced or targeted situations that cannot be discovered simply by pushing a button or reading an alert.

Q: How do intelligence requirements affect hiring decisions?

Intelligence requirements help define the people an organization needs to hire or assign. If stakeholders need coverage of nation-state, criminal, or hacktivist activity, the intelligence team needs personnel whose expertise matches those subjects. Requirements can also reveal a need for particular linguistic capabilities. Staffing therefore becomes part of the collection framework rather than a separate decision made without reference to business needs.

Q: What resources are required for effective threat intelligence?

Effective threat intelligence requires talent, access, and time. Talent means analysts who can understand and interpret threat information. Access includes appropriate tools, infrastructure, source material, and opportunities to collect relevant information. Time allows analysts to perform the work necessary to turn collected material into useful intelligence. Weakness in any of these areas limits the program's ability to deliver results.

Q: Can threat intelligence be fully automated?

The panel's discussion indicates that threat intelligence cannot be reduced to automation alone. Tools can collect information and produce alerts, but they do not replace the human ability to understand meaning and operational relevance. A functioning program combines technology and infrastructure with analysts who can interpret findings, investigate targeted threats, and convert raw information into actionable support for stakeholders.

Summary & Key Takeaways

  • Effective intelligence programs begin with planning and direction. Teams must identify their stakeholders, understand the operational decisions those stakeholders face, and translate those needs into clear intelligence requirements. Intelligence should support security practitioners and business functions directly, rather than operating separately from the people expected to use its findings.

  • Requirements provide the foundation for collection planning, staffing, and technical capabilities. A collection plan defines how analysts obtain the information needed to answer stakeholder questions, and it must change when requirements change. Requirements can also identify necessary analyst experience, threat specialization, and linguistic capabilities for the organization or client group being supported.

  • Threat intelligence depends on the combined contribution of people, access, tools, infrastructure, and time. Automated appliances may identify suspicious activity, but human analysts must interpret what the information means and determine whether it is actionable. Organizations must balance technical collection capabilities with analysts who can understand targeted threats and relevant operational contexts.


Read in Other Languages (beta)

Share This Summary πŸ“š

Explore More Summaries from RSAC Cybersecurity πŸ“š