Describe Intelligence-led Security Testing
Understanding the range of scenarios in which threat intelligence can be used within an organisation.
Importance of Intelligence-led Testing
Helps organisations understand the threat they face and ensures they are defending themselves against threats specific to them.
Purpose of Intelligence-led Testing
Understand the threat to protect yourself from it.
CTI Component in Testing Frameworks
Ensures organisations are tested on their ability to prevent, detect and respond to realistic, contemporary and accurate attacks.
What is CBEST?
Part of the Bank of England and PRA’s toolkit to assess cyber resilience of firms’ important business services.
What is TIBER-NL?
Threat Intelligence Based Ethical Red-teaming for the Dutch financial sector.
TBEST
Framework for the UK telecoms sector.
TIBER-EU
Framework for the European financial sector.
iCAST
Intelligence-led Cyber Attack Simulation Testing for Hong Kong’s financial sector.
GBEST
Framework for UK government departments.
ATTEST
Framework for the UK aviation industry.
Risk Formula
Risk = Vulnerability x Threat x Impact.
Definition of Threat
The intent and capability of an adversary to target an asset.
Threat Understanding
Organisations need to know who is likely to target what assets, where, when, how and why to defend themselves.
Risk Assessment
Combine threat understanding with cyber defence maturity to calculate likelihood of an incident.
Risk Score
Likelihood X Impact.