RS.AN-03.324
Does your organization utilize cyber deception technologies to gather intelligence on attacker behavior and tactics?
Explanation
Cyber deception technologies (such as honeypots, honeyfiles, or decoy systems) can provide valuable insights into attacker methodologies, tools, and objectives by monitoring how adversaries interact with fake assets. These technologies act as early warning systems and can reveal attacker patterns that might otherwise go undetected in your actual production environment. Evidence could include: documentation of deployed deception technologies, reports generated from these systems showing attacker behavior analysis, integration of threat intelligence gathered from deception technologies into security operations, or procedures for reviewing and acting upon intelligence collected from deception systems.
Implementation Example
Check any cyber deception technology for additional information on attacker behavior
ID: RS.AN-03.324
Context
- Function
- RS: RESPOND
- Category
- RS.AN: Incident Analysis
- Sub-Category
- Analysis is performed to establish what has taken place during an incident and the root cause of the incident

