An information security manager subscribes to several external threat intelligence feeds but finds that most alerts describe attacks irrelevant to the organisation's technologies and industry, overwhelming the small security team. What should the manager do first to make the threat intelligence genuinely useful for assessing emerging risk?
- AAdd further commercial and open-source feeds to widen coverage and reduce the chance of missing a threat
- BDeploy a security information and event management platform to correlate the incoming feed alerts automatically
- CDefine intelligence requirements aligned to the organisation's assets, sector, and threat profile before consuming feeds Correct
- DEscalate to management that current staffing is insufficient to process the volume of intelligence received
Why A is wrong: More feeds promise broader coverage, which is tempting, but adding sources without requirements multiplies the irrelevant volume and worsens the overload the manager already faces.
Why B is wrong: Correlation tooling can help operationally and sounds efficient, but automating the handling of poorly targeted intelligence still processes the wrong inputs and does not address relevance.
Why C is correct: Defining intelligence requirements tied to the organisation's assets, sector, and threat profile filters out noise so the team can focus on threats that are genuinely relevant to emerging risk.
Why D is wrong: Flagging resource constraints may be legitimate, but seeking more staff to handle unfiltered noise treats a symptom and skips the cheaper, more effective step of scoping what intelligence is actually needed.