Cyber Threat Intelligence
What is Cyber Threat Intelligence?
Evidence-based knowledge about existing or emerging cyber threats that can be used to inform decisions regarding the organisation's response to those threats. CTI includes indicators of compromise, threat actor profiles, and attack patterns.
Terms that appear alongside cyber threat intelligence
Each of these is named in at least one of the same controls as cyber threat intelligence. The number is how many controls name both.
- cyber threat 16 shared controls
- threat intelligence 16 shared controls
- cybersecurity 6 shared controls
- incident response 5 shared controls
- information sharing 4 shared controls
- vulnerability 3 shared controls
- resilience 3 shared controls
- cyber incident 3 shared controls
Frameworks that govern cyber threat intelligence
What the standards actually require on cyber threat intelligence
Requirements naming cyber threat intelligence across 6 standards, quoted from the control text.
Cyber threat intelligence is received from information sharing forums and sources
NIST-CSF-ID.RA-02 · Cyber threat intelligence is received from information sharing forums and sources →Participate in NATO cyber threat intelligence sharing via Malware Information Sharing Platform (MISP) instances operated by NCIRC + Cyber Threat Assessment Cell (CTAC) at SHAPE + bilateral channels with NATO Cooperative Cyber Defence Centre of Excellence (CCDC...
NATO-NCIRC-4 · Cyber Threat Intelligence Sharing and Coordinated Vulnerability Disclosure →Article 3 establishes the European Cybersecurity Alert System: a pan-EU interconnected network of National Cyber Hubs (Article 4) and Cross-Border Cyber Hubs (Article 5) operating as advanced security operations centres for detection of significant cyber threa...
CSA-Art.3 · Establishment of the European Cybersecurity Alert System (Article 3) →Threat intelligence integration. Implements CyFun ID.RA-2: cyber threat intelligence is received from information-sharing forums and sources and integrated into risk processes.
BE-CF-16 · Threat intelligence integration →Article 32 establishes the ADVANCED CYBERSECURITY CONTROLS that critical-impact entities must implement IN ADDITION TO the Article 30 minimum controls.
NCCS-Art.32_33_34 · Advanced cybersecurity controls (NCCS Articles 32-34) - for critical-impact entities →FAA + NTSB cyber-incident reporting requirements + processes: (a) cybersecurity incidents affecting aircraft + air traffic control + safety of flight must be reported to the FAA per AC 119-1 + the operator OpsSpec + per FAA Order 1370.123A for FAA systems;
FAA-CSA-Operator-Cyber-IR · Aviation Cyber Incident Response and Reporting to FAA and NTSB →Questions people ask about cyber threat intelligence
What is Cyber Threat Intelligence?
Why is Cyber Threat Intelligence important for compliance?
Which compliance frameworks address Cyber Threat Intelligence?
Where can I learn more about Cyber Threat Intelligence?
See how Cyber Threat Intelligence applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.