Chapter 4: Cyber Threat Intelligence Tradecraft and Standards

Like any other program, cyber threat intelligence (CTI) requires methods and skills to help security analysts achieve their desired objectives. To ensure a cooperative response to cyber threats, the cybersecurity community develops techniques (tradecraft) and standards that organizations can follow to allow a degree of uniformity in the CTI process. CTI tradecraft provides the methods and skills to conduct intelligence assessment, and standards provide a common approach (known as a norm) to react to threats. This chapter uses the two terms to refer to a common CTI language.

This chapter looks at CTI's analytic tradecraft and popular standards that help create a service-level model ...

Get Mastering Cyber Intelligence now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.