Threat forecasting
Up until this point, we have only been working with current data and making decisions addressing present vulnerabilities and issues. Threat forecasting takes that information and attempts to improve the overall organizational security position over time using a phased approach. The way this is accomplished is through three phases, defined as follows:
- Phase 1 – Research
- Phase 2 – Implementation and analysis
- Phase 3 – Information sharing and building
Let’s understand each of these phases.
Phase 1 - Research
In this phase, we attempt to apply what we have learned from previous assessments, audits, and even security incidents. We are not necessarily looking at specific flaws or vulnerability characteristics but looking at larger issues and ideas. This might include items such as: can we detect these types of vulnerabilities ourselves, can the channels of communication be improved or modified in some way, or are...