Location via proxy:   [ UP ]  
[Report a bug]   [Manage cookies]                
SlideShare a Scribd company logo
ENISA CTI-EU Conference 2022
Andreas Sfakianakis
CTI Professional
§ CTI in Financial, Energy, and Technology sectors
§ ENISA, FIRST.org, SANS, European Commission
§ Twitter: @asfakian
Mastodon: @asfakian@infosec.exchange
§ Websites: www.threatintel.eu
www.sandgroup.eu
tilting at windmills
Setting Your CTI Process In Motion - ENISA CTI-EU 2022
Setting the scene Workflow & Case
Management
Basic Ingredients
Problem Statement(s)
Image from gatewaytotheclassics.com
Setting Your CTI Process In Motion - ENISA CTI-EU 2022
Setting Your CTI Process In Motion - ENISA CTI-EU 2022
Setting Your CTI Process In Motion - ENISA CTI-EU 2022
Image from bestofspain.es
Workflow, Coordination
& Collaboration
Knowledge
Management
Metrics
Setting Your CTI Process In Motion - ENISA CTI-EU 2022
§ Tagging
§ Custom Fields
§ Easy searching and filtering
§ Rate your sources
§ Control access
Management
• Time spent per PIR
• CTI assessments per threat
type/threat actor
• CTI assessments(or time
spent) supporting IR
• Quantitative feedback
received per PIR
• Time spent on RFIs per
stakeholder
Team
• Sources mostly used
• CTI deliverables per PIR
• CTI deliverables per
stakeholder
• Average time spent per
CTI deliverable
• CTI analysts’ workload
• Time spent on CTI projects
Image from heritage-history.com
Setting Your CTI Process In Motion - ENISA CTI-EU 2022
Some TIPs
Recommendation is to live off the land (at least at the start of your journey)
Remember
§ Data into buckets
§ Consistency is key
§ Spend time to save time
Request For Information (RFI) Feedback Mechanism
Image from elladocomicodedonquijote.wordpress.com
§A common shortcoming
of CTI teams
§The importance of workflow and
case management
§The basic ingredients
Planning
Collection
Processing
Analysis
Dissemination
Feedback
CTI Process
Andreas Sfakianakis
@asfakian
threatintel.eu / sandgroup.eu
Sharing is caring

More Related Content

Setting Your CTI Process In Motion - ENISA CTI-EU 2022