公開済みEvidenceをIdentity / Capability / Credibility / Use Case / Constraints・Current Statusの軸で機械的に集約したものです(新規の主張・推測は含みません)。
Identity
NIST公式Glossary(CSRC)は、cyber threat intelligenceを「Cyber threat information that has been aggregated, transformed, analyzed, interpreted, or enriched to provide the necessary context for decision-making processes(意思決定に必要な文脈を提供するために集約・変換・分析・解釈・強化されたサイバー脅威情報)」と定義している(出典: NIST SP 800-61r3 under cyber threat intelligence from NIST SP 800-150)。検証待ちCyber Threat Intelligence - Glossary | CSRC
OASIS Open(国際標準化団体)公式のofficial standards-body press release announcing standard approval(https://www.oasis-open.org/2021/07/14/new-versions-of-stix-and-taxii-approved-as-oasis-standards-to-enable-automated-exchange-of-cyber-threat-intelligence/)は、Threat Intelligenceの連携・相互運用性に関する公的記録である。既存Referenceは脅威インテリジェンスの定義・活用例・重要性をカバーしているが、それを組織間でどう標準化された形式で共有するかという実務上の枠組み(STIX/TAXII)には触れておらず、相互運用性という新しい観点を追加する。具体的には「The STIX standard defines a JSON-based language for sharing structured threat intelligence in a consistent, machine-readable manner / The TAXII standard defines a transport protocol which supports the exchange of STIX data over Hyper Text Transfer Protocol Secure (HTTPS). / Both STIX v2.1 and TAXII v2.1 received approval as official OASIS Standards on July 14, 2021.」といった記載がある。ただし、対応状況は変更されうるため、この内容は取得時点のものです。 本ソースは2021年のOASIS標準承認時点のプレスリリースであり、2026年時点でのSTIX/TAXIIの普及率・最新バージョンの有無は別途確認が必要。STIX/TAXIIはMITREが主導しOASISへ移管された経緯があり、単一企業の製品ではなくオープンスタンダードである点に留意。2026年08月24日に同Sourceを取得し、この内容を確認した。検証待ちThreat Intelligence連携・相互運用性に関する公開情報
Credibility
公開Evidence未整備
Use Case
Google Cloud公式サイト(Mandiant)によれば、Mandiantの専門家は「extensive incident response experience with real-time threat intelligence(豊富なインシデント対応経験とリアルタイムの脅威インテリジェンス)」を組み合わせて侵害の痕跡を発見するとされ、Threat Intelligenceの実装例の一つである。検証待ちMandiant Cybersecurity Consulting | Google Cloud
Recorded Future公式サイトによれば、同社のIntelligence Graph®は「indexes, organizes, and analyzes data from over a million sources(100万以上の情報源からデータをインデックス化・整理・分析する)」ことで「real-time, and unbiased threat intelligence(リアルタイムで偏りのない脅威インテリジェンス)」を提供するとされ、Threat Intelligenceの実装例の一つである。検証待ちIntelligence Platform | Recorded Future
Constraints / Current Status
NIST公式Glossary(CSRC)は、threat informationを「Analytical insights into trends, technologies, or tactics of an adversarial nature affecting information systems security(情報システムセキュリティに影響する敵対的な傾向・技術・戦術に関する分析的洞察)」(CNSSI 4009由来)と定義しており、これは未加工の脅威情報であり、集約・分析・文脈化を経たThreat Intelligenceとは区別される段階にある。検証待ちthreat information - Glossary | CSRC