An enterprise financial institution plans to automate the ingestion of machine-readable threat indicators specifically sourced from peer sector organizations while standardizing automated indicator transport into its Security Orchestration, Automation, and Response (SOAR) platform. Which of the following solutions should the cybersecurity team implement to achieve these specific objectives? (Select TWO.)
- Financial Services Information Sharing and Analysis Center (FS-ISAC) subscriptionCevap
- Trusted Automated eXchange of Intelligence Information (TAXII) feed integrationCevap
- CNational Vulnerability Database (NVD) data feeds
- DStrategic threat intelligence executive briefings
- EManual Open Source Intelligence (OSINT) RSS blog scrapers
Cevap
The cybersecurity team should implement a Financial Services Information Sharing and Analysis Center (FS-ISAC) subscription and a Trusted Automated eXchange of Intelligence Information (TAXII) feed integration.
To fulfill the requirements, the organization needs both a sector-specific community threat source and an automated protocol for machine-readable ingestion. Subscribing to an Information Sharing and Analysis Center (specifically FS-ISAC for financial entities) supplies specialized threat data from peer institutions. Integrating a TAXII feed provides the standardized, machine-to-machine RESTful transport protocol needed to automatically ingest structured threat data directly into security orchestration platforms.
Adım Adım Çözüm
Anahtar Kavram
Threat Intelligence Sharing Architectures (ISACs and TAXII)