Question

Difficulty: MediumThreat Intelligence Sources and Research

A security manager at a retail organization is establishing a threat research and information-sharing strategy. Management wants to receive timely early warnings regarding cyber threats specifically targeting the retail sector and securely exchange anonymized threat telemetry with industry peers. Which of the following sources or mechanisms best fulfills these organizational requirements?

  1. Participating in a retail sector Information Sharing and Analysis Center (ISAC)Answer
  2. B
    Deploying an inline Web Application Firewall (WAF) across perimeter web applications
  3. C
    Establishing a high-interaction honeypot on the external perimeter network
  4. D
    Querying the National Vulnerability Database (NVD) for adversary campaign trends

Answer

Participating in a retail sector Information Sharing and Analysis Center (ISAC)
Participating in a sector-specific Information Sharing and Analysis Center (ISAC) allows organizations within a shared industry (such as retail, financial, or healthcare) to receive targeted threat intelligence alerts and securely exchange anonymized indicators of compromise with peer entities.

Step-by-Step Solution

1
Analyze the organization's requirements
Identified the need for sector-specific (retail) threat intelligence and bi-directional information sharing with industry peers.
The organization needs both tailored early warning data and a mechanism to exchange threat telemetry safely.
2
Evaluate potential intelligence sources against requirements
Recognized that Information Sharing and Analysis Centers (ISACs) cater directly to specific critical infrastructure and commercial sectors.
ISACs provide curated threat alerts, analysis, and anonymized sharing frameworks among member organizations within the same industry sector.
3
Differentiate ISACs from technical controls and general repositories
Selected participating in a retail sector ISAC as the primary mechanism.
Technical controls (WAF, honeypots) and general vulnerability databases (NVD) do not offer peer-to-peer industry threat intelligence exchange.

Key Concept

Information Sharing and Analysis Centers (ISACs)
Rate this question