1.2 Introduction to the Intelligence Lifecycle
Join over 3 million cybersecurity professionals advancing their career
Sign up with
Required fields are marked with an *
Already have an account? Sign In »
4 hours 42 minutes
Hello. This is Lisa British. Welcome again to the advance of Cyber Threat Intelligence Course. This is the second part off the introduction
fully dedicated to the intelligence life cycle.
In this video, we will learn the files of he behind using the intelligence cycle in order to build and organize the advance of Cyber Threat Intelligence Course we will learn what is intelligence cycle,
then the different steps off the intelligence cycle. And why are we even introduced on this cycle
in cyber threat intelligence context?
So let me ask a quick question. Do you think the intelligence cycle was created for cyber threat intelligence context?
The answer is false.
The traditional intelligence cycle was built for government and military context, like multiple cyber threat intelligence concepts.
Before introducing the intelligence cycle, I want to emphasize that data is different from intelligence
and through the whole course, we mean by intelligence. The results off analyzes and data the results off collection.
Now let's move to our main focus off this video. The intelligence life cycle. According to the Federation off American Scientists, the intelligence cycle is the process off development row information in to finish it intelligence for policymakers to use in decision making and action.
So basically, the intelligence cycle
is an effective way off process and information and turning it into a relevant and actionable intelligence. The intelligence cycle is also called the intelligence process by the US Department of Defense and there any form it surfaces.
The intelligence cycle is made of five steps
starting from the planning and direction, then the collection off data, then processing, then analyzes and protection, and finally, the dissemination.
So let's start with the first phase off the intelligence cycle, planning and direction. This face involves setting goals for the Threat Intelligence program. It is the beginning envy. End of the cycle
beginning because it consists off defining the requirements for the collection. Face
the end because finish it intelligence will support decision makers in order to make new requirements.
Thesis, step planning and direction also includes seven priorities.
The second phase is collection
in response to the requirements. The collection is the gathering off data needed to produce a Finnish intelligence that will be used to provide enough context so actions can be taken.
Gathering data can procure from very different off sources like, for example, logs from the internal i T infrastructure. It can be firewall logs, I PS logs and point clogs, et cetera.
Thread that defeats from the industry. You can automate receiving feeds from, ah, different paid or public free sources and bubble publicly available information that can be reports, forums, um bastes,
et cetera. Keep in mind that the data collected will be a combination off finish. It'd intelligence like reports and row data like logs or malware signatures. The third phase is processing. Processing
is the transformation of collected data
into a format that will be usable by the organization.
In some cases, collecting data from different sources requires different ways off process in to get a normalized set of information.
Technically, processing will require extracting IOC's or indicators off compromise from threat reports, e mails or threat feats.
If you don't know the term IOC's or indicators off compromise, I highly recommend you to go back to the course. In true to the Cyber Threat Intelligence.
The fourth step is analyzes and production.
This phase involves the evaluation and enrichment off the processes information in order to understand it.
The analysis face is all about thinking about the information collected and apply in different lenses in order to the drive, meaning
this face concludes by drawing conclusion
from the available information and providing assessment in the form off advice or recommendations.
The final phase is dissemination.
Dissemination involves getting the Finnish intelligence and assessment distributed to the appropriate at the audience.
This includes the frequency off providing this output.
I know that you know the intelligence cycle and it's the steps why I re particularly interested in introducing vis cycle in city I context
to answer this question. There is this diagram created by recorded future that I really like.
It explains how intelligence cycle can be not on Lee. Apply it to the traditional intelligence but also in a cyber threat intelligence environment. For this reason, we wanted to build and organize our course. Basically inspired by this cycle
in order to make each of the module
be ecological continuation off the previous wants.
Now I will summarize what we've seen so far in this video.
We started by defining what is the intelligence cycle. Then we've learned of the different steps off the intelligence cycle
and finally we explain it how this process can also be applied in cyber threat, intelligence, environment and how we were inspired by the intelligence cycle in order to make our course.
I hope you like this video and the full introduction to this course. In the next video, we'll start the first module data collection.
See you later.