1
00:00:06,450 --> 00:00:07,380
- [Instructor] In this segment,

2
00:00:07,380 --> 00:00:08,970
we're gonna take a closer look

3
00:00:08,970 --> 00:00:11,550
at how to design a threat
intelligence program

4
00:00:11,550 --> 00:00:14,220
and the associated workflow.

5
00:00:14,220 --> 00:00:17,040
You know, almost every
organization I work with

6
00:00:17,040 --> 00:00:20,280
says, yes, threat intelligence
is really important

7
00:00:20,280 --> 00:00:23,010
and yet they treat it like it's not.

8
00:00:23,010 --> 00:00:27,270
Threat intelligence programs
are often very disorganized,

9
00:00:27,270 --> 00:00:30,750
they're disjointed, they're decentralized,

10
00:00:30,750 --> 00:00:33,390
or worse, just totally ad hoc.

11
00:00:33,390 --> 00:00:35,640
So what do I mean by ad hoc?

12
00:00:35,640 --> 00:00:37,860
Well, ad hoc describes a situation

13
00:00:37,860 --> 00:00:39,840
where everyone is acting on their own,

14
00:00:39,840 --> 00:00:42,960
determining what sources
that they wanna use,

15
00:00:42,960 --> 00:00:47,960
how often to review it, how
to analyze, and when to act.

16
00:00:48,660 --> 00:00:51,930
This isolated approach
is fraught with danger,

17
00:00:51,930 --> 00:00:55,860
it's inconsistent, and
it's very duplicative.

18
00:00:55,860 --> 00:00:58,290
And there is a better way.

19
00:00:58,290 --> 00:01:00,990
First, an organization
needs to clearly define

20
00:01:00,990 --> 00:01:05,010
the types of threat intelligence
they want and the sources.

21
00:01:05,010 --> 00:01:08,670
And one of the best ways to
start that planning discussion

22
00:01:08,670 --> 00:01:12,580
is to bring together a
cross section of personnel

23
00:01:15,360 --> 00:01:20,280
Be they InfoSec, IT,
HR, accounting, fraud,

24
00:01:20,280 --> 00:01:24,600
risk management, physical
security, legal and compliance.

25
00:01:24,600 --> 00:01:28,140
And let's find out, what are they using?

26
00:01:28,140 --> 00:01:31,230
What feeds do they subscribe to?

27
00:01:31,230 --> 00:01:33,900
what bulletins do they receive?

28
00:01:33,900 --> 00:01:36,750
What information sharing organizations

29
00:01:36,750 --> 00:01:40,320
are they part of,
solicited and unsolicited?

30
00:01:40,320 --> 00:01:42,570
And then make a master list.

31
00:01:42,570 --> 00:01:44,520
And often what you're going to find

32
00:01:44,520 --> 00:01:47,070
is they're duplicated and triplicates,

33
00:01:47,070 --> 00:01:49,230
and then you're gonna rate the usefulness.

34
00:01:49,230 --> 00:01:54,090
And really importantly,
identify what might be missing.

35
00:01:54,090 --> 00:01:57,543
Next, you wanna assign a
threat intelligence librarian.

36
00:01:58,710 --> 00:02:02,160
Now this sounds like an expensive
proposition, but it's not.

37
00:02:02,160 --> 00:02:03,900
This is really a cost savings

38
00:02:03,900 --> 00:02:06,120
even for the smallest of companies.

39
00:02:06,120 --> 00:02:08,010
Instead of having multiple people

40
00:02:08,010 --> 00:02:09,720
spending time on collection,

41
00:02:09,720 --> 00:02:12,090
consolidate the effort.

42
00:02:12,090 --> 00:02:15,060
Generally, this turns into
about an hour or so a day.

43
00:02:15,060 --> 00:02:17,820
The librarian will
collect the intelligence

44
00:02:17,820 --> 00:02:20,130
and they'll store the intelligence

45
00:02:20,130 --> 00:02:23,400
in a central location that's accessible

46
00:02:23,400 --> 00:02:25,773
to all interested parties.

47
00:02:28,290 --> 00:02:30,900
Now the librarian should
also be responsible

48
00:02:30,900 --> 00:02:34,380
for disseminating the
information to the right people.

49
00:02:34,380 --> 00:02:35,820
Now, who are the right people?

50
00:02:35,820 --> 00:02:37,260
Well, you'll figure that out

51
00:02:37,260 --> 00:02:39,540
as part of your planning process.

52
00:02:39,540 --> 00:02:41,869
Analysis can be centralized
or decentralized

53
00:02:41,869 --> 00:02:44,730
based on the size and
structure of the organization.

54
00:02:44,730 --> 00:02:46,948
And of course, any action that's taken

55
00:02:46,948 --> 00:02:49,463
should definitely,
definitely be documented

56
00:02:49,463 --> 00:02:51,390
and shared with others

57
00:02:51,390 --> 00:02:56,280
so everyone who needs to be
kept in the loop is in the loop.

58
00:02:56,280 --> 00:02:58,230
If you follow this workflow,

59
00:02:58,230 --> 00:03:01,470
you will have a really well-formed,

60
00:03:01,470 --> 00:03:05,100
well-organized threat
intelligence program.

61
00:03:05,100 --> 00:03:07,293
And that my friends, is a closer look.
