03.11.01EActive
Because of the constantly changing and increasing sophistication of adversaries, especially the advanced persistent threat (APT), it may be likely that adversaries can successfully breach or compromise organizational systems. One of the techniques that organizations can use to address this concern is to share threat information. This can include the tactics, techniques, and procedures that organizations have experien
03.11.02EActive
Threat hunting is an active means of cyber defense in contrast to traditional protection measures, such as firewalls, intrusion detection and prevention systems, quarantining malicious code in sandboxes, and Security Information and Event Management (SIEM) technologies and systems. Cyber threat hunting involves proactively searching organizational systems, networks, and infrastructure for advanced threats. The object
03.11.03EActive
A properly resourced security operations center (SOC) or computer incident response team (CIRT) may be overwhelmed by the volume of information generated by the proliferation of security tools and appliances unless it employs advanced automation and analytics to analyze the data. Advanced automation and predictive analytics capabilities are typically supported by artificial intelligence concepts and machine learning.
03.11.04EWithdrawn
Withdrawn NIST SP 800-172 Rev. 3 requirement 03.11.04E; use the recorded replacement relationships.
03.11.05EWithdrawn
Withdrawn NIST SP 800-172 Rev. 3 requirement 03.11.05E; use the recorded replacement relationships.
03.11.06EWithdrawn
Withdrawn NIST SP 800-172 Rev. 3 requirement 03.11.06E; use the recorded replacement relationships.
03.11.07EWithdrawn
Withdrawn NIST SP 800-172 Rev. 3 requirement 03.11.07E; use the recorded replacement relationships.
03.11.08EActive
The threat awareness information that is gathered feeds into the organization’s security operations to ensure that procedures are updated in response to the changing threat environment. For example, at higher threat levels, organizations may change the privilege or authentication thresholds required to perform certain operations. This requirement enhances SP 800-171 requirement 03.11.01.
03.11.09EActive
Indicators of compromise (IOCs) are forensic artifacts from intrusions that are identified on organizational systems at the host or network level. IOCs provide valuable information on systems that have been compromised. IOCs can include the creation of registry key values. IOCs for network traffic include universal resource locator (URL) or protocol elements that indicate malicious code command and control servers. T
03.11.10EActive
Organizations conduct a functional decomposition of a system to identify mission-critical functions and system components. The functional decomposition includes the identification of organizational missions supported by the system, the specific functions to perform those missions, and traceability to the hardware, software, and firmware components that implement those functions, including when the functions are share
03.11.11EActive
Discoverable information includes information that adversaries could obtain without compromising or breaching the system, such as by collecting information that the system is exposing or by conducting extensive web searches. Corrective actions include notifying organizational personnel, removing designated information, or changing the system to make the designated information less relevant or attractive to adversarie
03.11.12EActive
To maximize the effectiveness of monitoring and sharing threat intelligence information, it is important to know what threat observables and indicators the sensors need to be searching for. By using well-established frameworks, services, and automated tools, organizations improve their ability to rapidly share and feed the relevant threat detection signatures into monitoring tools. This requirement does not enhance a