Threat intelligence and data sharing frameworks
Sharing frameworks are frameworks that intend to share threat intelligence indicators or observable data or intelligence. While many frameworks can be leveraged for sharing, we will cover the three primary frameworks.
Traffic light protocol
Traffic light protocol (TLP) is a model that's used for classifying information into the appropriate categories to facilitate intelligence and data sharing. TLP is a scheme that helps the original data holder designate a level for appropriate sharing, ensuring that the data isn't shared errantly.
TLP is a color-based model, ranging from TLP:RED, which facilitates the most granular and restrictive level of sharing, to TLP:WHITE, which facilitates the broadest level of sharing:
TLP is often used with threat intelligence information, such as contextual information about an attack, including attribution or threat intelligence observables and artifact information...