Cyber security intelligence principles

  • Several cyber security intelligence principles exist to guide the different public and private sectors. There are 5 intelligence principles available.

  • (1) Leverage public-private partnerships: With the large spectrum of possible threats and the huge amount of information (e.g., that can be collected through the Internet), regardless of the amount of resources and effort government can allocate to cyber security intelligence, this will not be enough, complete, or comprehensive.

  • Different initiatives should exist to integrate intelligence from different sources using proper methods to ensure that information will reach intended audience within the right time.

  • (2) Acknowledge some of cyber security intelligence challenges that have border- less, interconnected, and global nature of today’s cyber environment. Attackerscan exist anywhere in the world; they can be part of government sponsored agencies, private companies, or even individuals or amateurs.

  • (3) There is a need to adapt, evolve, and respond quickly in this very changing envi- ronment. IT, as a general sector, evolves rapidly with many new and emerging techniques, environments, etc. Additionally, cyber security threats and techniques evolve rapidly as well.

  • (4) Understand risk management and the different mitigation options and activities. Security cannot be complete or comprehensive, and what works well today may not work well tomorrow.

  • What works well in some environment may not work well in another. While taking all possible security measures is important, none theless, risk should be assisted at different levels and mitigation alternatives should be always planned for.

  • (5) The importance of security awareness: The human factor and dimension in any security framework will always be a key factor. Very strong security measures can be bypassed by tricking untrained or ignorant users.

  • Training should consider and accommodate the different skills’ levels of users. Training and aware- ness programs should be frequent and evaluate feedback from previous experiments to improve future training and awareness plans.

