Case study 3 – CTI for Level 3 organizations
Level 3 organizations have advanced security intelligence capabilities and possess adequate security infrastructure, with more resources at their disposal. Levels 1 and 2 are assumed to be part of the business system for advanced organizations. The objective and the focus will differ from level 1 and 2 organizations. Advanced organizations possess more information, both internal and external, and therefore, more data sources. Data sources are covered in Chapter 7, Threat Intelligence Data Sources.
Objective
The intelligence objective of Level 3 organizations is the prioritization of threat and defense techniques. After mapping different information (IOCs, TTPs, reports, external intelligence, and so on) to the framework models, an advanced organization must prioritize TTPs based on their impact on the system.
Strategy
By following these strategic steps, Level 3 organizations can integrate security intelligence into their...