1、SurveySANS 2022 Cyber Threat Intelligence SurveyWritten by Rebekah Brown and Pasquale StirparoFebruary 20222022 SANS Institute2SANS 2022 Cyber Threat Intelligence SurveyExecutive SummaryTwo major cybersecurity events that showcased the role of cyber threat intelligence(CTI)in network security operat
2、ions bookended this years survey.The SolarWinds software supply chain attack1 broke as we finished up the 2021 survey,and the Log4j vulnerability response process2 was in full swing as we worked to wrap up the 2022 survey.Both events highlighted the need to rapidly gain situational awareness,context
3、ualize vast amounts of shared information,and prioritize remediation of significant threats.The 2022 SANS CTI survey shows that many CTI programs can meet the challenge.While some programs are just getting started due to increased cybersecurity needs and a growing,complex threat environment brought
4、on by the rapid shift to remote work,organizations can rely on CTI providers and information-sharing groups to fill in gaps as their programs mature.Key takeaways:More organizations are beginning to develop their CTI capabilities,with an increasing number of respondents reporting that they are early
5、 on their CTI journey and still developing processes and going through the same growing pains that many robust CTI programs previously faced.Several promising trends from past years,such as collaboration between CTI teams and business operations groups,have been in decline since the shift to remote
6、work in response to the COVID-19 pandemic.It takes effort to build bridges,and organizations may find coordination that was already not as intuitive or ingrained when organizations were primarily in person even more difficult now.Quite an important percentage of respondents,21%,said that they could