Cyber Threat Intelligence: The No-Nonsense Guide for Cisos and Security Managers (Paperback)
暫譯: 網路威脅情報:CISO與安全管理者的實用指南 (平裝本)
Roberts, Aaron
買這商品的人也買了...
-
$2,040$1,938 -
$550$495 -
$505虛擬化技術實踐指南:面向中小企業的高效、低成本解決方案
-
$480$379 -
$203無線網絡技術 原理、安全及實踐
-
$474$450 -
$1,782Open Source Intelligence Techniques: Resources for Searching and Analyzing Online Information, 7/e (Paperback)
-
$480$379 -
$534$507 -
$620$489 -
$650$514 -
$359$341
相關主題
商品描述
Understand the process of setting up a successful cyber threat intelligence (CTI) practice within an established security team. This book shows you how threat information that has been collected, evaluated, and analyzed is a critical component in protecting your organization's resources. Adopting an intelligence-led approach enables your organization to nimbly react to situations as they develop. Security controls and responses can then be applied as soon as they become available, enabling prevention rather than response.
There are a lot of competing approaches and ways of working, but this book cuts through the confusion. Author Aaron Roberts introduces the best practices and methods for using CTI successfully. This book will help not only senior security professionals, but also those looking to break into the industry. You will learn the theories and mindset needed to be successful in CTI.
This book covers the cybersecurity wild west, the merits and limitations of structured intelligence data, and how using structured intelligence data can, and should, be the standard practice for any intelligence team. You will understand your organizations' risks, based on the industry and the adversaries you are most likely to face, the importance of open-source intelligence (OSINT) to any CTI practice, and discover the gaps that exist with your existing commercial solutions and where to plug those gaps, and much more.
What You Will Learn
- Know the wide range of cybersecurity products and the risks and pitfalls aligned with blindly working with a vendor
- Understand critical intelligence concepts such as the intelligence cycle, setting intelligence requirements, the diamond model, and how to apply intelligence to existing security information
- Understand structured intelligence (STIX) and why it's important, and aligning STIX to ATT&CK and how structured intelligence helps improve final intelligence reporting
- Know how to approach CTI, depending on your budget
- Prioritize areas when it comes to funding and the best approaches to incident response, requests for information, or ad hoc reporting
- Critically evaluate services received from your existing vendors, including what they do well, what they don't do well (or at all), how you can improve on this, the things you should consider moving in-house rather than outsourcing, and the benefits of finding and maintaining relationships with excellent vendors
Who This Book Is For
Senior security leaders in charge of cybersecurity teams who are considering starting a threat intelligence team, those considering a career change into cyber threat intelligence (CTI) who want a better understanding of the main philosophies and ways of working in the industry, and security professionals with no prior intelligence experience but have technical proficiency in other areas (e.g., programming, security architecture, or engineering)
商品描述(中文翻譯)
了解在已建立的安全團隊內設立成功的網路威脅情報 (CTI) 實務的過程。本書展示了收集、評估和分析的威脅資訊是保護您組織資源的關鍵組成部分。採用以情報為主導的方法使您的組織能夠靈活地應對不斷發展的情況。安全控制和應對措施可以在可用時立即應用,從而實現預防而非反應。
有許多競爭的方法和工作方式,但本書能夠清晰地闡明這些混亂。作者 Aaron Roberts 介紹了成功使用 CTI 的最佳實踐和方法。本書不僅將幫助資深安全專業人員,還將幫助那些希望進入該行業的人。您將學習在 CTI 中取得成功所需的理論和心態。
本書涵蓋了網路安全的混亂局面、結構化情報數據的優點和局限性,以及如何使用結構化情報數據作為任何情報團隊的標準實踐。您將根據行業和最有可能面對的對手了解您組織的風險,了解開源情報 (OSINT) 對任何 CTI 實務的重要性,並發現您現有商業解決方案中存在的差距以及如何填補這些差距,還有更多內容。
您將學到的內容:
- 知道各種網路安全產品及其風險和盲目與供應商合作的陷阱
- 理解關鍵的情報概念,如情報循環、設定情報需求、鑽石模型,以及如何將情報應用於現有的安全資訊
- 理解結構化情報 (STIX) 及其重要性,並將 STIX 與 ATT&CK 對齊,以及結構化情報如何幫助改善最終的情報報告
- 根據預算了解如何接近 CTI
- 在資金方面優先考慮領域,以及最佳的事件響應、資訊請求或即時報告的方法
- 批判性地評估來自現有供應商的服務,包括他們做得好的地方、做得不好的地方(或根本不做的地方)、您如何改善這些問題、應考慮內部處理而非外包的事項,以及尋找和維持與優秀供應商關係的好處
本書適合的讀者:
負責網路安全團隊的資深安全領導者,考慮成立威脅情報團隊的人,考慮轉職進入網路威脅情報 (CTI) 的人,想要更好地理解行業中的主要理念和工作方式,以及沒有先前情報經驗但在其他領域(例如程式設計、安全架構或工程)具有技術能力的安全專業人員。
作者簡介
Aaron Roberts is an intelligence professional specializing in Cyber Threat Intelligence (CTI) and Open-Source Intelligence (OSINT). He is focused on building intelligence-led cyber capabilities in large enterprises and conducting online investigations and research. He has worked within several the public and private sectors as well as the British Military. As such he understands how intelligence can and should be utilized within a range of environments and the fundamental approach that businesses must take to get the maximum value out of their cyber threat intelligence program.
作者簡介(中文翻譯)
是一位專注於網路威脅情報 (Cyber Threat Intelligence, CTI) 和開源情報 (Open-Source Intelligence, OSINT) 的情報專業人士。他專注於在大型企業中建立以情報為導向的網路能力,並進行線上調查和研究。他曾在多個公共和私營部門以及英國軍方工作。因此,他了解情報在各種環境中如何被利用以及企業必須採取的基本方法,以從其網路威脅情報計畫中獲得最大價值。