A security operations analyst is categorizing threat intelligence sources to build a tiered threat data pipeline. Match each threat intelligence source classification on the left with its primary operational characteristic on the right.
- Open-Source Intelligence (OSINT)Unclassified, publicly accessible information gathered from web scraping, social media, and security research blogs without subscription fees.
- Information Sharing and Analysis Center (ISAC)Trusted sector-specific communities facilitating non-profit, peer-to-peer threat indicator sharing among member organizations.
- Commercial / Proprietary Threat IntelligenceFee-based subscription services delivering curated threat actor profiling, finished strategic reporting, and dark web monitoring.
- Vulnerability Databases (e.g., NVD / CVE)Standardized public repositories providing technical flaw metrics, remediation references, and CVSS severity scoring.
Answer
Open-Source Intelligence (OSINT) matches unclassified, publicly accessible web data. Information Sharing and Analysis Center (ISAC) matches trusted sector-specific peer indicator sharing. Commercial / Proprietary Threat Intelligence matches fee-based subscriptions for dark web and actor profiling. Vulnerability Databases match standardized public repositories providing CVSS scores and CVE flaw metrics.
Each threat intelligence source corresponds directly to its operational delivery model: Open-Source Intelligence relies on publicly available data without cost; ISACs provide sector-restricted peer collaboration; Commercial/Proprietary feeds deliver paid tailored analytics and dark web visibility; and Vulnerability Databases offer standardized flaw listings with CVSS scoring.
Step-by-Step Solution
Key Concept
Categorization and Characteristics of Threat Intelligence Sources