Reference no: EM133337696
Case: Your task is to develop an OSINT report which provides information about the characteristics of an emerging application of technology and the threats / attacks to which it may be vulnerable. The consumers of this report have an interest in developing suitable countermeasures to prevent attacks by a broad spectrum of attackers from hobbyists to quasi-professionals and criminal entities to well organized, nation-state sponsored groups. When possible, your OSINT should explore the types and identities of known attackers who are likely to target users and usages of the technology covered by your report.
The basic question that must be answered in your OSINT report is:what are the cybersecurity implications (good or bad) of a specific emerging application of technology?
For this assignment, your role is that of a threat intelligence research intern working for a threat intelligence provider (private company). Your audience for this report will be subscribers to a cybersecurity threat intelligence reporting service provided by your employer. These subscribers are primarily senior managers and executives in businesses and government organizations.
The high-level visibility for your deliverable means that, in addition to easily accessed web sources and social media, your research must also include research-based journal articles, papers published in conference proceedings, and doctoral dissertations. Threat research and intelligence reports published by mainstream companies, e.g. Verizon, Forrester, Deloitte, etc., should also be considered for use as primary sources for your OSINT report. See step #3 under Conduct Your OSINT Research (below) for additional information about how many sources are required and what types of sources are allowed.
The following information needs, previously identified by your company's threat researchers, must be met by the deliverable for this assignment.
- Identification and description (characteristics) of the technology,
- Potential or known uses of the technology to support or improve business operations of companies and government agencies; this includes development of products which incorporate the technology and potential or known uses of the technology to support or improve cybersecurity, i.e.
- uses of the technology to reduce or manage risk
- uses of the technology to increase resistance to threats/attacks
- uses of the technology to decrease vulnerabilities in an existing technology application
- potential or known uses or exploitation of the technology by attackers, criminals, terrorists, etc. to accomplish their goals.