Zero Trust Engineering — Threat intelligence acquisition and enrichment
securityv1/01 Views
/02 About
Visibility and analytics engineering reference for threat intelligence acquisition and enrichment, including policy, logical interfaces, recovery and assurance.
Purpose: Threat intelligence acquisition and enrichment. Domain: Visibility and analytics. Family: exchange. Scenario trigger: Consume new actionable threat indicator or report. Input assurance: Source credibility, provenance, relevance and expiration. Evaluation: Assess threat applicability to enterprise assets and behaviors. Governing policy: Threat intelligence sharing, scoring and retention policy. Resource-side obligation: Publish validated indicators with confidence and expiry. Protected concern: Enterprise security detection enrichment service. Logical interface: Indicator type issuer confidence valid interval affected asset and finding. Evidence: Indicator source attribution matching and lifecycle evidence. Failure: Poisoned indicator or irrelevant malicious attribution. Required recovery: Quarantine untrusted intelligence and revert affected matches. Architectural invariant: External intelligence cannot be promoted to truth without corroboration Adoption: replace reference roles with concrete owner-controlled services. Specify exact provider/consumer identities, schema fields and classifications, signal provenance and freshness, idempotency, authorization lifetime, timeout/retry limits, observation and tamper evidence. A denied or failed operation must not silently become a permitted one. Scope: original vendor-neutral, implementation-agnostic technical reference model. Illustrative logical components and behaviors are neither a deployed system nor evidence of regulatory compliance. Package identities remain stable within the package; cross-package semantic reconciliation requires separate explicit registry support.
Curated · other · unspecified · Published by Lattix · 29 elements · 34 relationships · validated on publish
/03 Contents
- Capability
- Visibility and analytics, Threat intelligence acquisition and enrichment
- Role
- Visibility and analytics owner
- Business Actor
- Interoperating security service
- Activity
- Consume new actionable threat indicator or report, Verify: Source credibility, provenance, relevance and expiration, Assess: Assess threat applicability to enterprise assets and behaviors, Execute: Publish validated indicators with confidence and expiry, Exception: Poisoned indicator or irrelevant malicious attribution, Recover: Quarantine untrusted intelligence and revert affected matches
- Application Component
- Source credibility, provenance, relevance and expiration, Assess threat applicability to enterprise assets and behaviors, Publish validated indicators with confidence and expiry, Authenticated exchange producer, Authorized exchange consumer, Receipt and replay reconciliation
- Application
- Enterprise security detection enrichment service
- Policy
- Threat intelligence sharing, scoring and retention policy
- API
- Threat intelligence acquisition and enrichment logical interface
- Message/Event Schema
- Indicator type issuer confidence valid interval affected asset and finding, Exchange acknowledgement and receipt
- Data Store
- Indicator source attribution matching and lifecycle evidence
- Control
- Threat intelligence acquisition and enrichment enforcement assurance
- Risk
- Poisoned indicator or irrelevant malicious attribution risk
- Requirement
- External intelligence cannot be promoted to truth without corroboration
- Measure
- Threat intelligence acquisition and enrichment assurance completeness
- Trust Boundary
- Threat intelligence acquisition and enrichment authority boundary
- State
- Authorized information transfer, Exchange blocked or deferred