Threat Intelligence Detection and Response Time Modelling
摘要
Threat Intelligence Detection & Response Time (TIDRT) is the sum of IIDRT and EIDRT. With this TIDRT formula, the activity time of a Security Operation Center (SOC) can be measured in accordance with three variables; the number of security systems to be enrolled (S), the amount of internal cyber threat intelligence (X), and the amount of external cyber threat intelligence (Y). This activity modelling method will be very useful to determine how many people must work against cyber threats in a SOC. Furthermore, this modelling method can be used to measure the improvement of a SOC’s situation after adding a security investment.