Establishing threat intelligence goals and requirements

Establishing threat intelligence goals and requirements will help the threat intelligence team to better allocate and utilize its resources and fine-tune the data types, tools, and methods that will produce the most relevant and useful intelligence about the particular threats to the organization.

Choose an organization
Determine current threat landscape:
Major cybersecurity threats to the organization
Security posture and factors: pressures the organization is under to strengthen its security program
Risk assessment:
Risks related to the industry, legal obligations, customer security requirements
Business risks and impact on revenue, customers, operations, compliance, fines, costs of repairs or mitigation activities

Full Answer Section
  1. Conduct a risk assessment. The next step is to conduct a risk assessment. This will help you to identify the risks that are related to the industry, legal obligations, customer security requirements, and business risks.
  2. Define threat intelligence goals. Once you have completed the risk assessment, you can define threat intelligence goals. These goals should be specific, measurable, achievable, relevant, and time-bound.
  3. Define threat intelligence requirements. Once you have defined threat intelligence goals, you can define threat intelligence requirements. These requirements should specify the data types, tools, and methods that will be used to collect, process, analyze, and disseminate threat intelligence.
Here are some examples of threat intelligence goals and requirements for an organization:
  • Goal: To identify and assess the most significant cybersecurity threats to the organization.
  • Requirement: To collect and analyze threat intelligence from a variety of sources, including open-source, dark web, and commercial sources.
  • Goal: To develop threat intelligence that is relevant to the organization's business and security risks.
  • Requirement: To use threat intelligence to inform the organization's security program and to improve the organization's ability to detect and respond to threats.
Sample Answer Here are some steps on how to establish threat intelligence goals and requirements for an organization:
  1. Choose an organization. The first step is to choose an organization that you want to create threat intelligence goals and requirements for. This could be your own organization, or it could be a competitor or a partner.
  2. Determine the current threat landscape. Once you have chosen an organization, you need to determine the current threat landscape. This includes identifying the major cybersecurity threats to the organization, as well as the security posture and factors that are influencing the organization's security program.