Communicating threats is vital for the defense of organizations from cybersecurity threats. This communication assists in every stage of the incident handling chain, which will involve multiple organizations and stakeholders. The VERIS framework provides a common language for describing security incidents, split into four elements: actor, action, asset, and attributes. These elements (and their sub-elements) guide operators through the process, with multi-selectable options to aid their classification.
A common vocabulary, used consistently, allows organizations to share information, and research the threat environment and threat history. This allows them to work proactively, benefiting from the lessons learned by others.
In Chapter 7, Roles and Responsibilities During an Incident, we looked at the Incident Response Life Cycle. In this chapter, we looked at the phases...