Case study 2 – CTI for Level 2 organizations
Level 2 organizations are those that possess a maturing threat intelligence program. They have passed the Level 1 stage and are ready to make CTI part of their culture. We assume that Level 2 organizations have a CTI team in place that regularly monitors threat groups.
Objective
The intelligence objective of Level 2 organizations is to self-map intelligence analysis to specific framework models (such as the MITRE ATT&CK or Cyber Kill Chain model). The objectives can be achieved easily by leveraging threat intelligence frameworks.
Strategy
Level 2 organizations can integrate a CTI program by following these strategic steps:
- Execute the Level 1 process from the preceding section to understand the adversaries' techniques and collect internal logs and other external data.
- Map the analysis output (or the report) to the chosen framework. For example, to map a security report to MITRE ATT&CK, the CTI...