1、Building Cyber Threat Resilience with STRATA new Methodology for Cyber Threat IntelligenceWho We AreChandler McClellanScott J RobertsWhere Were FromWhere Were FromThe ProblemCyber Threat Intelligence is useful for 3 things:Situational Awareness Detection Engineering MarketingBuilding Resilience Shou
2、ld be NextSetting the StageA BRIEF INTRODUCTION TO SYSTEMS THINKINGA BRIEFER INTRODUCTION TO RESILIENCEAPPLYING STRAT TO CYBER RESILIENCESystems Thinking for Cyber DefenseWhat is Systems ThinkingA structured approach for thinking about complex interactionsMapping attacker approaches to defensive app
3、roachesWhy Think in SystemsANTICIPATING 2ND&3RD ORDER EFFECTSINTEGRATES RISK MODELING,SYSTEM DESIGN,AND THREAT INTELLIGENCE TO IMPROVE RESILIENCELAST OF ALLSystems Thinking Concepts:Stock&FlowSystems Thinking Concepts:Causal Loop DiagramIntroduction to ResilienceResilienceA systems ability to recove
4、r or adapt to disturbancesResistanceThe ability of the system to prevent the threat from impacting the systemRetentionThe ability of the system to maintain its core function after being impacted by the threatRecoveryThe ability of the system to recover some baseline level of core function after impa
5、ct from a threatResurgenceThe systems ability to improve a9er a threatHow do we build resilience?Redundancy Diversity Centralization or Decentralization Adaptability Imaging Alignment Stakeholder engagement Self-organization CommunicationThe STRAT MethodologyUsing Systems Thinking to turn Intelligen
6、ce into ResilienceWhat is STRAT?The System-Centric Threat and Resilience Assessment Tool(STRAT)is a methodology for practitioners across various fields to identify and build resilience in systems including both human and material components Developed by Dr Jeffery Taylor at Utah State University for