| By Bob Gourley | Article Rating: |
|
| March 13, 2013 02:05 PM EDT | Reads: |
400 |
By Ryan Kamauff
The Software Engineering Institute (SEI) at Carnegie Mellon University (CMU) has recently released their summary of key findings on their Cyber Intelligence Tradecraft Project (CITP). Last year, six government agencies partnered with twenty academic and industry organizations to determine best practices in cyber intelligence tradecraft. This study has found that organizations use a range of approaches to gather this information. They have found that “pockets of excellence exist where organizations excel at cyber intelligence by effectively balancing the need to protect network perimeters with the need to look beyond them for strategic insights.”
This document is broken down into the following categories:
- State of the Practice in Cyber Intelligence
- Applying a strategic lens to cyber intelligence analysis
- Information sharing isn’t bad; it’s broken
- Environment
- Understanding threats to the software supply chain
- Determining where cyber intelligence belongs organizationally
- Data Gathering
- Data hoarding
- Lack of standards for open source intelligence data taxes resources
- Functional Analysis
- Adopting a common cyber lexicon and tradecraft
- Filtering critical cyber threats out of an abundance of data
- Strategic Analysis
- No industry standard for cyber intelligence education and training
- Adapting traditional intelligence methodologies to the cyber landscape
- Stakeholder Reporting and Feedback
- Communicating “cyber” to leadership
- Difficulty capturing return on investment
The document can be found on SEI’s website, and can do a great deal to inform cyber decision makers on best practices and share information. Find it here.

Read the original blog entry...
Published March 13, 2013 Reads 400
Copyright © 2013 SYS-CON Media, Inc. — All Rights Reserved.
Syndicated stories and blog feeds, all rights reserved by the author.
More Stories By Bob Gourley
Bob Gourley, former CTO of the Defense Intelligence Agency (DIA), is Founder and CTO of Crucial Point LLC, a technology research and advisory firm providing fact based technology reviews in support of venture capital, private equity and emerging technology firms. He has extensive industry experience in intelligence and security and was awarded an intelligence community meritorious achievement award by AFCEA in 2008, and has also been recognized as an Infoworld Top 25 CTO and as one of the most fascinating communicators in Government IT by GovFresh.
- Cloud People: A Who's Who of Cloud Computing
- Basho Announces Open Source Riak CS and General Availability of Riak CS Enterprise v1.3
- Session Topics: 12th Cloud Expo / Cloud Expo New York
- MicroStrategy Announces General Availability of MicroStrategy 9.3.1
- CollabNet And UC4 Announce General Availability Of Joint Enterprise DevOps Platform
- MicroStrategy Announces General Availability of MicroStrategy 9.3.1
- Project Floodlight Grows to the World’s Largest SDN Ecosystem; Global Users, Contributors and Partners Innovating Using Open Source SDN
- Mobility News Weekly – Week of March 17, 2013
- The Software Freedom Conservancy – Fundraising Campaign: Non-Profit Accounting Software
- Midokura Announces General Availability of Disruptive Network Virtualization Technology
- Remote Controlling a Car over the Web. Ingredients: Smartphone, WebSocket, and Raspberry Pi.
- Social Business Intelligence Book Industry’s First Executive SBI Guide
- Cloud People: A Who's Who of Cloud Computing
- SUSE Receives Common Criteria Security Certifications
- Basho Announces Open Source Riak CS and General Availability of Riak CS Enterprise v1.3
- Appeon Mobile Beta2 - 48 Hours
- Session Topics: 12th Cloud Expo / Cloud Expo New York
- MicroStrategy Announces General Availability of MicroStrategy 9.3.1
- CollabNet And UC4 Announce General Availability Of Joint Enterprise DevOps Platform
- MicroStrategy Announces General Availability of MicroStrategy 9.3.1
- Project Floodlight Grows to the World’s Largest SDN Ecosystem; Global Users, Contributors and Partners Innovating Using Open Source SDN
- Antenna to "Myth-Bust" Common Mobile App Development Misconceptions in Upcoming Webinar
- Mobility News Weekly – Week of March 17, 2013
- The Software Freedom Conservancy – Fundraising Campaign: Non-Profit Accounting Software
- Java Developer's Journal Exclusive: 2006 "JDJ Editors' Choice" Awards
- The i-Technology Right Stuff
- Creating Web Applications with the Eclipse Web Tools Project
- Eclipse Special: Remote Debugging Tomcat & JBoss Apps with Eclipse
- Where Are RIA Technologies Headed in 2008?
- The Next Programming Models, RIAs and Composite Applications
- SYS-CON Webcast: Eclipse IDE for Students, Useful Eclipse Tips & Tricks
- How to Bring Eclipse 3.1, J2SE 5.0, and Tomcat 5.0 Together
- Eclipse: The Story of Web Tools Platform 0.7
- The Top 250 Players in the Cloud Computing Ecosystem
- "Eclipse 3.0 is a Great Leap Forward," Says JDJ's Dudney
- Developing an Eclipse BIRT Report Item Extension


























