Skip to content

Threat Intelligence Policy

Threat Intelligence Policy

Version history

Version Number Date Description Created By Approved By
0.1 23/Apr/2024 Initial Copy [Name] [Name]
0.2 18/Jun/2024 Approved [Name] [Name] [Name]
0.3 28/Aug/2026 Knowledge kernel, AI/agents, control alignment Knowledge steward [Name]

Introduction

  • The purpose of this policy is to establish guidelines for the collection, analysis, and use of threat intelligence to protect the information assets of the organization.

  • This policy applies to all personnel who have access to information assets.

Scope

  • This Threat Intelligence Policy document extends to tecciance, including all its subsidiaries, across the following products and services.

  • The Threat Intelligence Policy ensures to proactively identify, assess, and respond to potential cybersecurity threats.

  • Clearly outline the scope of the policy, specifying the types of threats it covers and the assets it protects.

Objectives

The Objective of a Threat Intelligence Policy is to empower the organization to proactively identify, assess, and respond to cybersecurity threats effectively, thereby reducing the likelihood and impact of security incidents and safeguarding critical assets and information.

Roles and Responsibilities

  • Identify key stakeholders and their roles in the threat intelligence process, including analysts, incident responders, IT administrators, and management.

  • Clearly define responsibilities for threat detection, analysis, response, and communication.

Collection of Threat Intelligence

  • The organization shall collect threat intelligence from a variety of sources, including but not limited to, open-source intelligence, commercial intelligence feeds, and internal data sources.

  • The collection of threat intelligence shall comply with all applicable laws and regulations.

  • The organization shall establish a process for reviewing and validating the accuracy and reliability of the collected threat intelligence.

Analysis of Threat Intelligence

  • The organization shall analyze the collected threat intelligence to identify potential threats and vulnerabilities to its information assets.

  • The analysis shall be performed on a regular basis or as necessary to address specific threats or vulnerabilities.

  • The analysis shall be conducted by qualified personnel who have been trained in threat intelligence analysis.

Use of Threat Intelligence

  • The organization shall use the analysis of threat intelligence to develop and implement appropriate measures to mitigate identified threats and vulnerabilities.

  • The organization shall establish procedures for the dissemination of threat intelligence to appropriate personnel in a timely manner.

  • The organization shall maintain a record of the use of threat intelligence and the actions taken to mitigate identified threats and vulnerabilities.

  • Threat intelligence should be analyzed and later used:

  • by implementing processes to include information gathered from threat intelligence sources into the organization’s information security risk management processes.

  • as additional input to technical preventive and detective controls like firewalls, intrusion detection systems, or anti malware solutions.

  • as input to the information security test processes and techniques.

Management of Threat Intelligence

  • The organization shall establish a process for the ongoing management of the threat intelligence program, including periodic review and assessment of the program’s effectiveness.

  • The organization shall maintain appropriate documentation to support the threat intelligence program.

  • The organization shall establish a process for the disposal of threat intelligence that is no longer relevant or necessary.

Training and Awareness

  • The organization shall provide training to personnel who have access to information assets on the importance of threat intelligence and how to use it.

  • The organization shall provide awareness training to all personnel on the potential threats and vulnerabilities to the information assets of the organization.

Conclusion

  • This policy establishes the guidelines for the collection, analysis, and use of threat intelligence to protect the information assets of the organization.

  • Compliance with this policy is mandatory for all personnel who have access to information assets.

Terms & Definitions

  • Threat Intelligence: Information that is used to identify and analyze potential threats and vulnerabilities to the organization’s information assets.

  • Information Assets: All information owned, used, processed, or stored by the organization.