JH
6 posts

JH retweetet

Come join @CTIAdvisory and @IamMaskedFox at the @sansforensics CTI Summit next week where they plan to present on #cti program maturity and how to use the #cticmm framework to improve traction with #cybersecurity and #risk stakeholders.
If you are planning to attend in person, stop by and say hello to some of our other #cticmm members to include @gertjanbruggink and @_John_Doyle.

English
JH retweetet

We are happy to announce the release of #cticmm version 1.1, which includes a new domain for Fraud teams as CTI stakeholders and a beta version of an assessment tool for benchmarking organizational reach and impact. With this release, we have also updated our website to include some enablement material, explanative guides, and ways to provide feedback and get involved.
🎯On the near term horizon, expect the following from us:
--📝A poll soliciting thoughts on where we should prioritize our efforts for version 1.2
--🧙♂️Additional enablement material on how to improve maturity levels within each domain
--😺John Holland and Alex Perez Palma presenting on how to implement CTI CMM during their @sansforensics #ctisummit25 talk as the first of a series of 2025 small roadshow talks at various conference and industry forums
Head over to cti-cmm.org to download your copy of version 1.1.
Shout outs to our friends over at @socradar, @cosiveco, and #morado #threatnote for publishing content on CTI-CMM usage; to @Intel471Inc for its sponsorship of the #cticmm project; and to each and everyone of you #cti practitioners for all you do. #bettertogether #infosec

English
JH retweetet

This is a simple framework I've used for many years to help guide clients to a proper conceptualization of the role and value of intelligence. I hope you find it usefull...
linkedin.com/pulse/3-tenets… via
@LinkedIn
#cybersecurity #threatintelligence #intelligence #InfoSec #CISO
English

@HackingButLegal @invisig0th Thanks Jackie!
Just to clarify on your comment regarding “continuous monitoring,” I assume you’re referring to commercial monitoring services like credit reporting, criminal/traffic, etc; right?
English

@invisig0th This is a very good v1! I like the organization and structure. They should consider hiring some contractors on Fiverr to create infographics which summarize visually.
My first thought is that continuous monitoring is missing from CTI3/Workforce Management use cases.
English

I'm commonly critical of "maturity models" and assessment frameworks (most of them are abstract to the point of not being useful) but the CTI-CMM seems like a solid codification.
It's practical and well organized. A solid start. 👍
cti-cmm.org
English
