Certified Information Security Manager (CISM)Information Security Risk ManagementMedium

An organization is evaluating its current threat landscape. The information security manager is analyzing recent attack patterns, including zero-day exploits and advanced persistent threats (APTs). To effectively manage these evolving threats, which of the following actions should be prioritized?

  1. ADeveloping comprehensive security policies and procedures for all employees.
  2. BEstablishing a robust threat intelligence program to gather and analyze relevant threat data.
  3. CUpgrading all network firewalls to the latest generation with advanced filtering capabilities.
  4. DImplementing regular vulnerability scanning and penetration testing of all external-facing systems.
Show answer & explanation

Correct answer: B. Establishing a robust threat intelligence program to gather and analyze relevant threat data.

To effectively combat evolving threats like zero-days and APTs, an organization needs proactive intelligence. A threat intelligence program provides the necessary insights into attacker methodologies, indicators of compromise (IoCs), and emerging vulnerabilities, enabling more informed and timely defensive strategies.

Why the other options are wrong

  • A. Security policies are foundational but do not directly address the dynamic nature of advanced threats without intelligence feeding their updates.
  • C. Firewall upgrades are technical controls; without intelligence on what to block or detect, their effectiveness against unknown threats is limited.
  • D. While important, vulnerability scanning and penetration testing are reactive to known weaknesses; they may not identify zero-day exploits or APTs.

Threat Intelligence

Knowledge about existing or emerging threats, including their capabilities, infrastructure, and motivations, used to anticipate and prevent attacks.

  • Proactive defense strategy.
  • Informs security decisions.
  • Helps detect unknown threats.

Memory trick: Intelligence is the eye that sees the unseen threat.

More Information Security Risk Management questions