The document is a survey report on cyberthreat intelligence (CTI) conducted by SANS in 2015. Some key findings include:
- 69% of respondents have implemented CTI to some extent, with 64% having a dedicated team for CTI.
- Common tools used for CTI include SIEM (55%), intrusion monitoring (54%), and security analytics platforms (28%).
- Respondents gather intelligence internally (59%) and externally from the security community (76%), vendor CTI feeds (56%), and open source feeds (53%).
- Top areas for future planning include aggregating information from any source (30%) and providing a full picture view of events (29%).