
NEW2CTI | Bling-Up CTI Requirements with Diamond Model
Source: YouTube · SANS Digital Forensics and Incident Response · published Apr 2, 2026 · 27:10
BLUF: Sherman Chu, former NYC cyber security lead and current BlackRock CTI lead, discusses integrating existing frameworks into cyber threat intelligence programs and building robust organizational capabilities. 1:00
Key Takeaways:
• Chu outlines his background as a US Army veteran and former lead for New York City’s cyber security agency, where he established the city's full cyber threat intelligence program. 0:00
• He emphasizes the importance of marrying existing frameworks with cyber threat intelligence to create effective strategies rather than building from scratch. 0:46
• The discussion covers practical advice for organizations looking to build out their incident response teams, vulnerability disclosure programs, and CTI functions. 0:21
Closing Statement: Chu’s insights provide a foundational approach for leaders aiming to strengthen their cyber defense posture by leveraging established methodologies and professional experience.
Sources:
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
My name is Sherman Chu. I am currently the cyber threat intelligence lead for Black Rockck. Uh prior to Black Rockck, I was actually um um also the lead for New York City um cyber security agency where I built out their uh um the full cyber threat intelligence program for the city itself. Uh and in between um I also did a lot of uh sort of um consulting and managing of um helping other organizations build out their sock, their instant response team um their vulnerability disclosure as well as a CTI team. Um and prior to all that I am a US Army veteran and uh yeah and here I am a little catchy uh title here called bling up your intelligence requirements but let's really focus on the core here which is you know the marriage of you know uh existing um uh frameworks in cyber threat intelligenc…