RS.AN-03.324

Does your organization utilize cyber deception technologies to gather intelligence on attacker behavior and tactics?

Explanation

Cyber deception technologies (such as honeypots, honeyfiles, or decoy systems) can provide valuable insights into attacker methodologies, tools, and objectives by monitoring how adversaries interact with fake assets. These technologies act as early warning systems and can reveal attacker patterns that might otherwise go undetected in your actual production environment.

Evidence could include: documentation of deployed deception technologies, reports generated from these systems showing attacker behavior analysis, integration of threat intelligence gathered from deception technologies into security operations, or procedures for reviewing and acting upon intelligence collected from deception systems.

Implementation Example

Check any cyber deception technology for additional information on attacker behavior

ID: RS.AN-03.324

Context

Function
RS: RESPOND
Category
RS.AN: Incident Analysis
Sub-Category
Analysis is performed to establish what has taken place during an incident and the root cause of the incident

Related questions