Chapter 1. Defining Threat Intelligence
Threat intelligence is gaining a more prominent role in running a modern security team. Of course, this prominence means that every security professional and vendor also wants the world to adopt their vision of threat intelligence. This leaves many organizations with two questions: what is threat intelligence, and can it can really help improve security?
The short answer to the second question is: it can and does, when implemented correctly. But, as with any complex system, there is no “Easy Button” for threat intelligence. The goal of this book is to provide an introduction to some of the basic themes of threat intelligence. This book is not designed to be comprehensive; instead, it is designed to start a conversation about building a successful threat intelligence program. This book provides guidelines and exposes pitfalls for any organization that is ready to build a Threat Intelligence Unit for the first time, or is looking to improve their existing intelligence team.
This chapter starts by defining threat intelligence. As silly as this may sound, without a common definition of the term, it is hard to build an effective program. The rest of the book revolves around the definition and the basic tenets of threat intelligence defined in this chapter.
Military Terms
Threat intelligence in information security draws heavily upon years of intelligence experience from the military. Not just because the military has established intelligence ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access