Skip to Content
Threat Intelligence in Practice
book

Threat Intelligence in Practice

by Allan Liska
December 2017
Intermediate to advanced
61 pages
1h 27m
English
O'Reilly Media, Inc.
Content preview from Threat Intelligence in Practice

Chapter 2. The Threat Intelligence Cycle

As established in Chapter 1, threat intelligence is not a data feed. Instead, threat intelligence is a system. Good threat intelligence teams have a process in place that gives them the ability to continuously adjust to new threats and quickly incorporate new data sources into their intelligence process. Almost all threat intelligence organizations use the intelligence cycle model, with some variation in the terms and numbers of phases.

The Intelligence Cycle

The most commonly used threat intelligence model is the intelligence cycle, shown in Figure 2-1, or a variant on this model.

Figure 2-1. The Intelligence Cycle

This is the model that is used by military intelligence, and it consists of five parts, some of which have already been discussed:

  • Planning and Direction
  • Collection
  • Processing
  • Production
  • Dissemination

At the core of the intelligence cycle is the mission. The five components of the intelligence cycle revolve around helping the organization succeed in its mission. Note that no one part of the intelligence cycle is more important than the other parts. In order for a threat intelligence program to be effective, all components of the threat intelligence cycle have to work equally well.

Intelligence Requirements

The flow of the intelligence cycle allows the threat intelligence team to sift through the incredible amounts of data ...

Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.

Read now

Unlock full access

More than 5,000 organizations count on O’Reilly

AirBnbBlueOriginElectronic ArtsHomeDepotNasdaqRakutenTata Consultancy Services

QuotationMarkO’Reilly covers everything we've got, with content to help us build a world-class technology community, upgrade the capabilities and competencies of our teams, and improve overall team performance as well as their engagement.
Julian F.
Head of Cybersecurity
QuotationMarkI wanted to learn C and C++, but it didn't click for me until I picked up an O'Reilly book. When I went on the O’Reilly platform, I was astonished to find all the books there, plus live events and sandboxes so you could play around with the technology.
Addison B.
Field Engineer
QuotationMarkI’ve been on the O’Reilly platform for more than eight years. I use a couple of learning platforms, but I'm on O'Reilly more than anybody else. When you're there, you start learning. I'm never disappointed.
Amir M.
Data Platform Tech Lead
QuotationMarkI'm always learning. So when I got on to O'Reilly, I was like a kid in a candy store. There are playlists. There are answers. There's on-demand training. It's worth its weight in gold, in terms of what it allows me to do.
Mark W.
Embedded Software Engineer

You might also like

Threat Intelligence and Threat Hunting

Threat Intelligence and Threat Hunting

Aamir Lakhani
Operationalizing Threat Intelligence

Operationalizing Threat Intelligence

Kyle Wilhoit, Joseph Opacki
Threat Hunting

Threat Hunting

Michael Collins

Publisher Resources

ISBN: 9781492049302