Match each threat intelligence source type to its primary characteristic or operational scope.
- Open-Source Intelligence (OSINT)Publicly accessible security data gathered from security blogs, code repositories, and advisories
- Information Sharing and Analysis Center (ISAC)A sector-specific trust community established to exchange relevant threat indicators among industry peers
- Commercial Threat FeedA paid subscription service providing vetted, high-fidelity threat indicators tailored to subscriber needs
- Vulnerability Database (NVD/CVE)A standardized public catalog detailing known security flaws and associated severity scores
Answer
Open-Source Intelligence (OSINT) pairs with publicly accessible security data gathered from open sources. Information Sharing and Analysis Center (ISAC) pairs with a sector-specific trust community established to exchange relevant threat indicators among industry peers. Commercial Threat Feed pairs with a paid subscription service providing vetted, high-fidelity threat indicators. Vulnerability Database (NVD/CVE) pairs with a standardized public catalog detailing known security flaws.
Each threat intelligence source type is accurately mapped to its core delivery mechanism: OSINT relies on publicly available information; ISACs represent sector-specific peer sharing communities; commercial feeds are paid vendor subscriptions; and vulnerability databases provide public catalogs of known software security flaws.
Step-by-Step Solution
Key Concept
Threat Intelligence Sources and Classification