CREST Practitioner Threat Intelligence Analyst (CPTIA) — Study Guide hygiene persists despite greater awareness, with many attacks succeeding through basic, preventable weaknesses. Skills shortages limit the ability of organisations and citizens to manage risks effectively. Legacy and unsupported systems remain common and are often unpatched. Hacking resources and step by step guidance are widely available and are easily misused to compromise victims. Overview This study guide summarizes the United Kingdoms National Cyber Security Strategy for 2016-2021. The strategy recognises that the UKs prosperity and security rest on digital foundations and that cyberspace brings persistent risk. The central vision for 2021 is a UK that is secure and resilient to cyber threats, prosperous and confident in the digital world. To reach that vision the Government organizes its work around three outcomes it calls Defend, Deter and Develop, underpinned by active international action. Exam Tip Be clear on how the strategy classifies cyber crime. It separates cyber-dependent crimes, which exist only through use of information and communications technology such as developing and propagating malware or hacking to steal or damage data, from cyber-enabled crimes, which are traditional offences that the Internet amplifies in scale or reach, such as fraud and data theft. Strategic Context The strategy describes a threat landscape where criminal groups, states and state-sponsored actors, terrorists, hacktivists and less skilled script kiddies all operate at scale. Financially motivated organised groups develop and deploy aggressive malware, including ransomware and distributed denial of service for extortion, and they exploit weak targets. States conduct espionage for political, diplomatic, technological, commercial and strategic advantage and a small number have developed destructive capabilities that threaten critical systems. Terrorist capability is judged low but disruptive activity such as defacements and doxing attracts attention and intimidation. Hacktivists are decentralised and target issues they oppose, often seeking disruption. Insiders, whether malicious or inadvertent, remain a persistent risk because of their privileged access. National Response and Governance The Government states that market forces alone have not delivered the pace or scale of improvement needed. It therefore assumes a more active role while still working in partnership with citizens, businesses, academia and the Devolved Administrations. The strategy sets principles for action, including protecting people and prosperity, treating a cyber attack as seriously as a conventional one, acting in line with law and values, protecting privacy, and sharing responsibility across society. A central institutional change is the creation of the National Cyber Security Centre as the UKs authoritative public face on cyber security. Launched on 1 October 2016, the NCSC brings together capabilities from CESG, CPNI, CERT-UK and the Centre for Cyber Assessment. It The document highlights systemic vulnerabilities that raise overall exposure. The expansion of connected devices into the consumer Internet of Things and into industrial environments creates new cyber-physical risks that can affect essential services. Poor cyber 1 CREST Practitioner Threat Intelligence Analyst (CPTIA) — Study Guide Crime Agency to disrupt serious threats. manages national incidents, provides expertise and advice to government and priority sectors, facilitates information sharing and draws on GCHQs world-class technical capabilities. Exam Tip Active Cyber Defence in this strategy is not a company level toolset. It is a national scale programme that uses government influence and partnerships to block malware command and control, filter known bad infrastructure, reduce successful phishing and secure routing so that commodity attacks become far less effective by default. Remember The strategy commits £1.9 billion over five years to transform national cyber security and explicitly positions the Government to lead where the market has underperformed. The NCSC is designed to unify incident response, guidance and sector support across the UK while remaining closely connected to GCHQ. The strategy aims to build a more secure Internet by making products and services secure by default. Government will lead by deploying secure services that do not rely on the wider Internet being secure, collaborating with industry to embed default security in hardware and software, and adopting technologies such as Trusted Platform Modules and emerging passwordless authentication to improve user experience and security. It also explores security ratings to help consumers choose more secure products and warns users when their actions may compromise security. Defend The Defend pillar concentrates on making UK networks, data and systems resilient across public, commercial and private spheres. The Government articulates Active Cyber Defence as a macro scale application of defensive measures that hardens the entire UK cyberspace. The intended outcomes include defeating high volume low sophistication malware activity, making phishing significantly less effective, securing routing and telecommunications, and hardening citizen facing services and critical systems. Protecting government is described as essential for public trust. The plan moves more services online while ensuring new services are secure by default, addressing legacy and unsupported software, improving resilience through best practice, exercises and automated scanning, and investing in people so that cyber risk awareness and expertise improve. A dedicated Cyber Security Operations Centre in Defence protects MoD cyberspace and works closely with the NCSC. To achieve this, the Government works with communications service providers to block access to malicious domains using Domain Name System filtering, deploys email verification on government networks to reduce spoofing, promotes best practice through multi stakeholder Internet governance bodies, protects citizens from overseas attack infrastructure, and implements controls that secure the routing of government traffic. It also increases the capability of GCHQ, the Ministry of Defence and the National Critical National Infrastructure and other priority sectors receive targeted attention. The Government expects boards to understand their cyber risks, invest proportionately, and maintain tested response plans. The NCSC 2 CREST Practitioner Threat Intelligence Analyst (CPTIA) — Study Guide through NATO and other alliances, and, when judged in the national interest, public attribution. Preventing terrorism concentrates on detecting, investigating and disrupting actors who seek to use cyber to cause publicity and disruption while keeping overall terrorist capability low. provides sectoral guidance, exercises and access to threat information only government can obtain. Regulation is shaped to be outcome focused, agile and harmonised internationally so that UK companies can compete while meeting the national interest. Changing public and business behaviours is central to reducing harm. The strategy continues national messaging that promotes strong passwords and timely software updates, amplifies guidance through trusted voices and market influencers such as insurers and investors, and uses regulatory levers, including data protection, to raise standards where the market fails. Finally, it streamlines incident management through a unified approach led by the NCSC, integrates automated information sharing and ensures Armed Forces support is available in significant incidents. The strategy also invests in sovereign capabilities. Through the National Offensive Cyber Programme, the UK develops the tools, techniques and tradecraft needed to deliver offensive cyber effects in accordance with law, including integrating these capabilities with military operations. In cryptography the aim is to maintain political control over capabilities that protect the most sensitive information by ensuring the availability of assured solutions and a clear understanding of long term cost and skills implications. The document affirms support for encryption as a foundation of a strong Internet economy and explains the legal framework under which, when served with a warrant, companies are required to take reasonable steps to give effect to lawful access to communications they themselves have encrypted. Deter The Deter pillar applies the principles of deterrence to cyberspace. The UK signals that it will use the full spectrum of capabilities to deter adversaries, including making the UK a harder target through resilience, understanding adversary intent and taking action where appropriate. Reducing cyber crime focuses on raising the cost, raising the risk and reducing the reward for offenders. Law enforcement enhances capabilities at national, regional and local levels, targets criminal business models and infrastructure, builds upstream international partnerships and improves victim support through 24 by 7 reporting and triage linked to the NCSC and the National Cyber Crime Unit. Develop The Develop pillar tackles the long term capabilities the UK needs. It sets out a sustained effort to strengthen cyber security skills by defining a long term strategy, establishing a skills advisory group across government, employers and educators, integrating cyber security into education from schools to postgraduate levels, addressing gender imbalance and diversity, and creating clear professional pathways including a profession with Royal Chartered status. Defence develops a Cyber Academy as a centre of excellence and expands collaborative training and exercising. Countering hostile foreign actors requires strategies tailored to specific adversaries, reinforcement of international law and norms, partnership 3 CREST Practitioner Threat Intelligence Analyst (CPTIA) — Study Guide To stimulate growth in the sector the Government supports commercialisation in academia, establishes two innovation centres to accelerate start ups, allocates funding to innovative procurement, provides testing facilities and streamlined assessment for emerging products, and uses the weight of government procurement as an early adopter to spur innovation. The strategy further promotes cyber security science and technology by sponsoring research institutes and doctoral training, publishing a detailed science strategy after consultation, funding a new research institute in a strategic area, and advancing collaboration among academia, industry and government. Finally, it embeds effective horizon scanning so that cyber risk and technological change are integrated into policy making, linking cyber to wider political, economic, legislative, social and environmental trends. The strategy emphasises metrics to ensure investment translates into results. Headline outcomes include enhanced capability to detect and counter adversaries, reduction in the impact of cyber crime, improved incident management, effective active cyber defence at scale, secure by default products and services, resilient and trusted government systems, better management of cyber risk across organisations, a thriving cyber sector, a sustainable pipeline of professionals, global leadership in research and development, mature horizon scanning and stronger international consensus. The conclusion underlines that threats will continue to evolve but that a comprehensive approach can transform future security and safeguard prosperity. Glossary of Terms Active Cyber Defence The principle of implementing security measures at scale to strengthen networks and systems so that the UK cyberspace is harder to attack, defeating high volume low sophistication activity and blocking malicious infrastructure. International Action Because cyberspace is global the UK invests in partnerships that shape a free, open, peaceful and secure environment. The strategy champions multi stakeholder Internet governance, opposes data localisation, builds capacity abroad, strengthens norms of responsible state behaviour and confidence building measures, and works through the United Nations, G20, the European Union, NATO, OSCE, the Council of Europe, the Commonwealth and the development community. It also works closely with non government actors across industry, civil society, academia and the technical community to inform and challenge policy and to strengthen political messages. National Cyber Security Centre The UKs authoritative public facing body for cyber security that manages national incidents, provides expertise and advice, and draws on GCHQ capabilities after bringing together CESG, CPNI, CERT UK and the Centre for Cyber Assessment. Critical National Infrastructure Those elements of infrastructure whose loss or compromise could have a major detrimental impact on essential services or national security, requiring proportionate cyber security and resilience. Cyber dependent crime Criminal activity that can be committed only through the use of information and communications technology where the device is both the Measuring Progress and Looking Beyond 2021 4 CREST Practitioner Threat Intelligence Analyst (CPTIA) — Study Guide tool and the target, such as developing and propagating malware or hacking to steal or damage data. accordance with national and international law. Domain Name System filtering The restriction of access to domains that are known sources of malware so that users and services are protected by default against common attacks. Cyber enabled crime Traditional crime whose scale or reach is increased by computers and networks, including fraud and data theft that exploit the Internet. Secure by default A design and deployment approach in which hardware and software are delivered with security controls activated as the default so that users benefit from the maximum protection unless they actively turn those controls off. Cyber incident An occurrence that actually or potentially poses a threat to a device, system or network or the data processed, stored or transmitted on those systems, requiring actions to mitigate consequences. Phishing Deceptive emails that appear to come from a trusted source to lure recipients into clicking weaponised links or attachments or into disclosing sensitive information to an unknown third party. Ransomware Malicious software that denies a user access to files, computers or devices until a ransom is paid. Encryption The cryptographic transformation of data into a form that conceals its original meaning to prevent unauthorised access; the strategy supports strong encryption while explaining the legal framework for warranted access to company applied encryption. Cyber resilience The overall ability of systems and organisations to withstand cyber events and to recover when harm occurs. Internet of Things The growing collection of devices and systems embedded with electronics, software and sensors that communicate over the Internet, extending cyber risk into homes, cities and industry. Offensive cyber The use of cyber capabilities to disrupt, deny, degrade or destroy computers, networks and Internet connected devices in 5
0
You can add this document to your study collection(s)
Sign in Available only to authorized usersYou can add this document to your saved list
Sign in Available only to authorized users(For complaints, use another form )