Tactical Threat Intelligence Requirements

Module 8 consists of a single video but it's a comprehensive overview of the requirements for putting a properly run CTI program in place. Dean goes over the procedures for handling incident response. Events may come from devices such as an IDS or SEIM device. Sysadmins raise the alert flag but it's important that CTI analysts follow proper incident response procedures. The last thing any organization wants or needs is to waste time and money responding to false positives. Senior leadership must be involved. This includes not only being in the notification chain but also being an advocate for the CTI program within the organization. Open lines of communication are critical and regular and ad hoc meetings must be part of the CTI program. The video concludes with a discussion of tools and security products. These resources are essential in support of any CTI program. Dean reviews the various types and offerings.
Recommended Study Material

Recorded Future Cyber Daily



With new threats lurking around every corner, you need to be prepared. Join thousands of your infosec peers and subscribe to the Cyber Daily for free trending threat intelligence insights.



Learn on the go.
The app designed for the modern cyber security professional.
Get it on Google Play Get it on the App Store

Our Revolution

We believe Cyber Security training should be free, for everyone, FOREVER. Everyone, everywhere, deserves the OPPORTUNITY to learn, begin and grow a career in this fascinating field. Therefore, Cybrary is a free community where people, companies and training come together to give everyone the ability to collaborate in an open source way that is revolutionizing the cyber security educational experience.

Cybrary On The Go

Get the Cybrary app for Android for online and offline viewing of our lessons.

Get it on Google Play

Support Cybrary

Donate Here to Get This Month's Donor Badge

Skip to toolbar

We recommend always using caution when following any link

Are you sure you want to continue?