000 | 03285cam a2200229Ii 4500 | ||
---|---|---|---|
020 | _a148427220X | ||
020 | _a9781484272206 | ||
020 | _a9781484272190 | ||
082 | 0 | 4 | _aLCTK105.59 .R63 2021: DDC:005.8 |
100 | 1 | _aRoberts, Aaron, | |
245 | 1 | 0 |
_aCyber threat intelligence : _bthe no-nonsense guide for CISOs and Security Managers / _cAaron Roberts |
264 | 1 |
_aBerkeley, CA : _bApress, _c2021 |
|
300 |
_axv, (207 pages) _billustrations; |
||
500 | _aIncludes index | ||
520 | _aUnderstand the process of setting up a successful cyber threat intelligence (CTI) practice within an established security team. This book shows you how threat information that has been collected, evaluated, and analyzed is a critical component in protecting your organizations resources. Adopting an intelligence-led approach enables your organization to nimbly react to situations as they develop. Security controls and responses can then be applied as soon as they become available, enabling prevention rather than response. There are a lot of competing approaches and ways of working, but this book cuts through the confusion. Author Aaron Roberts introduces the best practices and methods for using CTI successfully. This book will help not only senior security professionals, but also those looking to break into the industry. You will learn the theories and mindset needed to be successful in CTI. This book covers the cybersecurity wild west, the merits and limitations of structured intelligence data, and how using structured intelligence data can, and should, be the standard practice for any intelligence team. You will understand your organizations risks, based on the industry and the adversaries you are most likely to face, the importance of open-source intelligence (OSINT) to any CTI practice, and discover the gaps that exist with your existing commercial solutions and where to plug those gaps, and much more. You will: Know the wide range of cybersecurity products and the risks and pitfalls aligned with blindly working with a vendor Understand critical intelligence concepts such as the intelligence cycle, setting intelligence requirements, the diamond model, and how to apply intelligence to existing security information Understand structured intelligence (STIX) and why its important, and aligning STIX to ATT&CK and how structured intelligence helps improve final intelligence reporting Know how to approach CTI, depending on your budget Prioritize areas when it comes to funding and the best approaches to incident response, requests for information, or ad hoc reporting Critically evaluate services received from your existing vendors, including what they do well, what they dont do well (or at all), how you can improve on this, the things you should consider moving in-house rather than outsourcing, and the benefits of finding and maintaining relationships with excellent vendors | ||
650 | 0 | _aComputer security. | |
856 | 4 | 0 | _uhttps://rave.ohiolink.edu/ebooks/ebc2/9781484272206 |
856 | 4 | 0 | _uhttps://go.ohiolink.edu/goto?url=https://link.springer.com/10.1007/978-1-4842-7220-6 |
856 | 4 | 0 | _uhttps://link.springer.com/10.1007/978-1-4842-7220-6 |
856 | 4 | 0 | _uhttps://learning.oreilly.com/library/view/~/9781484272206/?ar |
942 |
_2lcc _cBK |
||
999 |
_c14297 _d14297 |