Indicator of Compromise
What is Indicator of Compromise?
Forensic artifacts such as file hashes, IP addresses, domain names, or registry keys that indicate a system has been breached or infected.
Frameworks that govern indicator of compromise
What the standards actually require on indicator of compromise
Requirements naming indicator of compromise across 5 standards, quoted from the control text.
Indicators of compromise must be shared across the space community to enable collective defense.
TI-3 · Indicator of Compromise Sharing →FIRST CSIRT Services Framework v2.1 Service Area 4 - Situational Awareness. SCOPE: maintaining + sharing operational + tactical + strategic awareness of the cyber threat landscape relevant to the constituency.
FIRST-CSIRTF-SA4-SituationalAwareness · Service Area 4 - Situational Awareness and Threat Intelligence →ISMAP Cloud Operations covers the day-to-day security operations of cloud services. (1) Cloud Security Monitoring and Logging: 24x7 Security Operations Center (SOC) + SIEM Security Information and Event Management (Splunk + Microsoft Sentinel + IBM QRadar + Su...
ISMAP-CloudOperations-Monitoring-Logging-IncidentResponse-NISC-Reporting-Vulnerability-Change-SLA · ISMAP Cloud Operations - Security Monitoring + SIEM + Logging + Incident Response + NISC Reporting + Vulnerability Management + Penetration Testing + Change Management + SLA Management →Continuous security monitoring + 24x7 SOC operations are expected per FSA Cybersecurity Guidelines particularly for Tier 2/3 institutions. (1) SOC Operating Models: (a) Internal SOC - dedicated team + tooling;
JP-FSA-CYB-Security-Monitoring-SOC-Operations-SIEM-EDR-MDR-XDR-24x7-Detection-Alert-Triage · Japan FSA Cybersecurity Security Monitoring + SOC 24x7 Operations + SIEM + EDR + MDR + XDR + Detection + Alert Triage + Threat Hunting + Incident Response Integration + Threat Intelligence Integration + UEBA →Handle cloud, third-party, and supply chain incidents and integrate threat intelligence per NIST SP 800-61 Rev 2 supplemented by NIST SP 800-150 (Cyber Threat Information Sharing) + NIST SP 800-161 (Supply Chain Risk Management).
NISTSP61-8 · Cloud, Third-Party, and Supply-Chain Incident Handling and Threat Intelligence Integration →Questions people ask about indicator of compromise
What is Indicator of Compromise?
Why is Indicator of Compromise important for compliance?
Which compliance frameworks address Indicator of Compromise?
Where can I learn more about Indicator of Compromise?
See how Indicator of Compromise applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.