A threat and vulnerability awareness program that includes a cross organization information-sharing capability shall be implemented.
Guidance
A threat and vulnerability awareness program should include ongoing contact with security groups and associations to receive security alerts and advisories. (Security groups and associations include, for example, special interest groups, forums, professional associations, news groups, and/or peer groups of security professionals in similar organizations).This contact can include the sharing of information about potential vulnerabilities and incidents. This sharing capability should have an unclassified and classified information sharing capability.
It shall be identified where automated mechanisms can be implemented to make security alert and advisory information available to relevant organization stakeholders.
Organization carries out threat intelligence by gathering information about information security threats related to its operations and how to protect against them. The goal is to increase awareness of the threat environment, so that own security level can be better evaluated and adequate control measures implemented.
When collecting threat intelligence, all three levels must be taken into account:
Principles related to threat intelligence should include:
The organization has defined policies that regularly collect up-to-date and reliable information about malware. Such can be e.g. mailing lists, magazines, blogs from security software vendors, or security news sites.
The purpose of the data sources is to verify the information on malware, to distinguish the scams from real malware and to ensure that the warnings received are truthful and informative.
The organization shall actively maintain contacts with stakeholders relevant to the organization's operations and other relevant actors related to the organization's operations and security.
The goal is especially to:
Organization should share threat intelligence information actively with other organizations to improve its own threat awareness.