惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Engineering at Meta
Engineering at Meta
Microsoft Azure Blog
Microsoft Azure Blog
I
InfoQ
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
人人都是产品经理
人人都是产品经理
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
T
Tailwind CSS Blog
MongoDB | Blog
MongoDB | Blog
Google DeepMind News
Google DeepMind News
WordPress大学
WordPress大学
量子位
美团技术团队
大猫的无限游戏
大猫的无限游戏
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Last Week in AI
Last Week in AI
博客园 - 司徒正美
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
小众软件
小众软件
C
Check Point Blog
博客园 - 三生石上(FineUI控件)
N
Netflix TechBlog - Medium
Recent Announcements
Recent Announcements
有赞技术团队
有赞技术团队
月光博客
月光博客

Intel 471 Blog

TeamPCP Supply Chain Attacks Turning Geopolitical Tension into Actionable Intelligence CVE-2025-68613: Zerobot botnet exploits critical vulnerability impacting n8n AI orchestration platform Introducing Cyber Threat Exposure Bundle: A Unified Approach to External Risk CVE-2026-20127: Critical Cisco SD-WAN vulnerability exploited in wild Handala Threat Group OpenClaw: A viral AI assistant and a magnet for infostealer malware and ClickFix trickery Israeli, US strikes against Iran triggers a surge in hacktivist activity CVE-2026-1731: Finding a critical RCE in an age of AI-driven vulnerability research Born to bypass MFA: Taking down Tycoon 2FA The UK Cyber Security Resilience Bill How AI and the human advantage beat tomorrow’s threats Winter Olympics 2026: Hacktivism Surges Ahead of Protests and Suspected Sabotage How Threat Hunting and “Good” Metrics Help The Business Likely fake ransomware operator 0APT causes panic — Our analysis Hunting APTs: from state policy to TTPs CrazyHunter Ransomware DevMan Ransomware Introducing HUNTER Tuning: a New Tool for Driving Behavioral Threat Hunt Detections Battling check fraud in the U.S. Gootloader Malware Update Shai-Hulud Worm 2.0 New FvncBot Android banking trojan targets Poland White Paper Preview: Black "Fraud Day” and Beyond — The Key Cyber Threats Facing the Retail Sector this Holiday Season Threat hunting case study: Detecting IAB activity Using deception to extract cyber threat intelligence Lynx Ransomware Qilin Ransomware Group ClickFix: Tricking users into installing infostealers Cybercrime Takedowns: Trust, Partnerships and Focus
Introducing the CTI Capability Maturity Model, a resource...
Intel 471 · 2024-08-06 · via Intel 471 Blog

Today’s rapidly evolving digital threat environment has made it more critical than ever to use insights from cyber threat intelligence (CTI) to anticipate threats and defend against them. But building a successful, mature CTI program that aligns with an organization’s core objectives and key outcomes is no easy feat. That’s why we at Intel 471 have sponsored and led the development of the CTI Capability Maturity Model (CTI-CMM), an easy to use, vendor-neutral model that promotes a “stakeholder-first” approach to building a mature CTI program, evaluating its progress, and continuously improving it during the CTI maturity journey.

The model aims to help decision-makers, leaders, and practitioners navigate the complexities of building a mature CTI program and bridge the gap between technical capabilities and strategic objectives. It adopts the view that a CTI program exists to support the people who make decisions and take actions to protect your organization, which include stakeholders from senior management, security operations, incident response, forensics, legal and risk management professionals.

The all-volunteer team of 28 experts consist of members and advisors from the CTI community representing a wide range of sectors, geographic regions, backgrounds, and experiences, including practitioners and leaders at Intel 471, IBM, Kroger, Venation, Mandiant, IntL8, Reqfast, Trellix, Autodesk, Centre for Cybersecurity Belgium (CCB), Northwave Cyber Security, Workday, Marsh McLennan, Signify, Tidal Cyber, DeepSeas, BP, Gojek, SANS Institute and more.

The CTI-CMM is also built to align with industry best practices and the concepts and format of a recognized cybersecurity maturity model, the U.S. Department of Energy’s Cybersecurity Capability Maturity Model (C2M2). The C2M2 contains contributions from experts representing a range of private and public sector organizations. It is aligned with other internationally recognized cyber standards and best practices, including the National Institute of Standards and Technology (NIST) Special Publication 800-53 and the NIST Cybersecurity Framework (CSF).

The C2M2 is designed to help measure the maturity of a cybersecurity program by focusing on the capabilities of domains found within most organizations, such as risk management and vulnerability management. Coincidentally, the C2M2 domains represent stakeholders commonly supported by CTI programs, creating a natural reference point for the CTI-CMM to align to.

The CTI-CMM’s vendor-neutral approach is similarly designed to foster collaboration among stakeholders that advances the field for the benefit of all. It also aims to reduce risk by promoting a comprehensive understanding of CTI’s role in safeguarding the organization’s assets and reputation.

Organizations can use this CTI-CMM framework to assess their current CTI maturity level and as a blueprint for making continuous improvements that help organizations realize their CTI program’s full potential across tactical, operational, and strategic intelligence practices.

“Unlocking the full potential of your CTI program requires alignment with the capabilities of each stakeholder it supports, and a tangible measurement of success synchronized with organizational priorities,” said Michael DeBolt, Chief Intelligence Officer at Intel 471, program creator and lead of the CTI-CMM.

“The CTI Capability Maturity Model is designed to support CTI teams in building their capabilities by aligning to defined practices for stakeholder business domains unique to each organization. The model establishes shared values and principles across the industry to empower organizations to take a holistic approach to cyber threat intelligence with stakeholders and business outcomes as the centerpiece focus.”

CTI-CMM program co-lead, Colin Connor, CTI Services Manager at IBM X-Force said: “Advising numerous clients globally, I have observed a consistent need for an outcome-focused model for cyber intelligence programs. The CTI-CMM bridges the gap to help CTI programs create impactful and demonstrable value for their organization.”

The CTI-CMM provides users with key CTI maturity indicators to evaluate practices that support each stakeholder domain, which are contextualized with the CTI Mission, such as reducing the attack surface using CTI about the threat environment, CTI Use Cases, and CTI Data Sources, such as vulnerability intelligence, dark web intelligence, and breach intelligence. Key domains covered in the CTI-CMM include:

  • Asset, Change, and Configuration Management.
  • Threat and Vulnerability Management
  • Risk Management
  • Identity and Access Management
  • Situational Awareness
  • Event and Incident Response, Continuity of Operations
  • Third-Party Risk Management
  • Workforce Management
  • Cybersecurity Architecture
  • Cybersecurity Program Management

Contributing CTI experts defined the following values and principles to support the CTI community:

Shared Values

  • Intelligence provides value through collaboration with our stakeholders and supporting their decision-making process.
  • Intelligence is never completed. Improvement is continuous. This also applies to adoption. Constant improvement is crucial for success and distinguishing from other models who failed to keep up with the time.
  • Intelligence is not proprietary, nor is it prescriptive. Therefore, the model should never be claimed by a single commercial party.

Shared Principles

  • Contextualizing threat intelligence within risk
  • Continuous self-assessment and improvement
  • Actionable intelligence based on stakeholder needs
  • Quantitative and qualitative measurement of intelligence
  • Collaborative and iterative intelligence processes

The work of continuous improvement is never over. The CTI-CMM team is already planning for future enhancements and additions to the model, including adding a FRAUD domain and developing a tool to help guide the user through the maturity assessment process. If you would like to get involved, provide feedback, or simply learn more about new developments, join the community at cti-cmm.org!