Reference no: EM133957984
Assignment:
Scenario Based Activity Investigating Threat Data and Intelligence Sources
You work for a development company that provides specialized software and ATM firmware to financial services companies. Your company is transitioning from use of private, locally hosted network services to cloud-based solutions. In this context, you also want to review your security procedures and use of security tools and technologies, and threat intelligence capability specifically.
1. What are your strategic, operational, and tactical requirements for threat intelligence?
2. As a relatively small company, with no dedicated SOC, what is the main risk from deploying a threat intelligence feed?
3. Review the open-source feeds available at misp-project.org/feeds. What type of threat intelligence do these provide?
4. Review the CTI produced by the Financial Services ISAC at fsisac.com/what-we-do/intelligence. What additional types of information are provided?
5. Review the platform provided by a commercial solution, such as fireeye.com/solutions/cyberthreat-intelligence.html, noting the market review provided by Forrester. What are some of the differentiators from an open-source feed?