Chapter 4: Threat Intelligence Frameworks, Standards, Models, and Platforms
Making use of CTI is a paramount requirement for any effective organizational threat intelligence program. While often considered a drab topic in CTI, threat intelligence frameworks, standards, and platforms should form the foundation of any CTI program.
As we've observed in the previous chapters, creating and adopting an effective CTI program is a diverse and challenging endeavor. Organizations should put acute focus on developing a robust adoption of common industry standards, platforms, and frameworks to ensure CTI is collected, stored, observed, and enriched. When leveraged holistically, frameworks, models, platforms, and standards provide and enable you to collect and produce CTI.
This chapter examines threat intelligence frameworks, standards, models, and platforms, including commonly recognized standards such as STIX and TAXII. This chapter will assist in providing familiarity with and hopefully...