Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Marketplace Contribution] MISP - Indicator Sharing #38870

Open
wants to merge 1 commit into
base: contrib/xsoar-contrib_Galp-Csirt-Team-contrib-MISP-IndicatorSharing
Choose a base branch
from

Conversation

xsoar-bot
Copy link
Contributor

Status

  • In Progress
  • Ready
  • In Hold - (Reason for hold)

Contributor

@Galp-Csirt-Team

Description

MISP Indicator Sharing - Boosting Portuguese Cybersecurity - Together, we can build a Safer Digital Future

In our ongoing efforts to enhance cybersecurity across Portugal, we are excited to share our comprehensive playbook designed to enable the sharing cybersecurity indicators via MISP. This playbook is a valuable resource for organizations of all sizes, providing standardized practices and actionable insights to improve incident response and overall cybersecurity posture.

  • This content pack incluides:

    • Introduction to Cybersecurity Indicator Sharing
      Understanding the importance of cybersecurity indicators and how they can help in identifying, managing, and mitigating cyber threats.
      The concept of Predefinied Tags enables the default propagation of several tags that are consumed by MISP like Country, Company Sector, CSIRT-Aliance, this can be definied on the task.

    • Portuguese National Taxonomy: A playbook to classifiy the incident according to CNCS taxonomy

    • ENISA Taxonomy: A playbook to classify the incident according to the ENISA taxonomy

    The previous playbooks ensure the incident classification to a format that enables a direct mapping to MISP tags via RSIT aligning with international standards to ensure consistency and interoperability.

Even though the main focus is the indicator sharing for Portuguese Companies the use of ENISA standards allows the use of this playbook for non portuguese companies.
This playbook builds from the "Phishing" content pack since it uses some of its incident fields allowing for an easier use in cases of phishing email information sharing.
We encourage all organizations to review and integrate these guidelines to strengthen our collective cybersecurity efforts.

Notes

This content pack is an update according to previous meet that we had regarding a previous submission:
[Marketplace Contribution] MISP - Indicator Sharing - PT (PR #36778)
We consolidated the 3 submissions into a single one and created the marketplace documentation as well as documentation for the contribution page.

Thanks for the support.

Auto-Generated Documentation Requiring Modification

Video Link

Short demo video of the Pack usage. Speeds up the review. Optional but recommended. Use a video sharing service such as Google Drive or YouTube.

@content-bot content-bot added Contribution Thank you! Contributions are always welcome! External PR Community Support Level Indicates that the contribution is for Community supported pack labels Mar 3, 2025
@content-bot content-bot changed the base branch from master to contrib/xsoar-contrib_Galp-Csirt-Team-contrib-MISP-IndicatorSharing March 3, 2025 15:24
@content-bot
Copy link
Collaborator

Thank you for your contribution. Your generosity and caring are unrivaled! Rest assured - our content wizard @ilaredo will very shortly look over your proposed changes.
For your convenience, here is a link to the contributions SLAs document.

@content-bot
Copy link
Collaborator

Thanks for contributing to the XSOAR marketplace. To receive credit for your generous contribution, please ask the reviewer to update your information in the pack contributors file. See more information here link

@content-bot content-bot added the Contribution Form Filled Whether contribution form filled or not. label Mar 3, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Community Support Level Indicates that the contribution is for Community supported pack Contribution Form Filled Whether contribution form filled or not. Contribution Thank you! Contributions are always welcome! External PR Security Review
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants