Threat-Informed Defense

Also known as:TID

Threat-Informed Defense: Alignment of controls and tests with specific threats and attack techniques. The term is relevant for the assessment and design of modern security architectures and should be applied within the respective technical and organizational context.

How it works and where it fits

Threat-Informed Defense structures knowledge about potential adversaries, their objectives, capabilities, infrastructure, and observed behavior. Individual indicators are short-lived and easy to change, while behavioral patterns and technical relationships often have greater analytical value. Reporting should distinguish observed facts, assessments, and assumptions.

Practical security relevance

Practical use depends on source quality, timeliness, and relevance to the organization’s own attack surface. Information is prioritized, correlated with internal data, and converted into searches, detections, or safeguards. Investigation feedback continuously improves the assessment. Confidentiality and permitted sharing are as important as technical exchange formats.

  • Threat ModelingThreat ModelingAnalyzes potential attackers, attack vectors, and protective measures during the design phase.: Analyzes potential attackers, attack vectors, and protective measures during the design phase.
  • Cyber Threat IntelligenceCyber Threat IntelligenceProcessed information regarding threat actors, tactics, indicators, and risks.: Processed information regarding threat actors, tactics, indicators, and risks.
  • Threat ActorThreat ActorAn individual, group, or organization that intentionally carries out or supports cyberattacks.: An individual, group, or organization that intentionally carries out or supports cyberattacks.
  • MITRE ATT&CKMITRE ATT&CKStructures known tactics and techniques of real-world cyberattacks.: Structures known tactics and techniques of real-world cyberattacks.