NEW2CTI | Bling-Up CTI Requirements with Diamond Model

NEW2CTI | Bling-Up CTI Requirements with Diamond Model

Source: YouTube · SANS Digital Forensics and Incident Response · published Apr 2, 2026 · 27:10

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

BLUF: Sherman Chu, former NYC cyber security lead and current BlackRock CTI lead, discusses integrating existing frameworks into cyber threat intelligence programs and building robust organizational capabilities. 1:00

Key Takeaways:
• Chu outlines his background as a US Army veteran and former lead for New York City’s cyber security agency, where he established the city's full cyber threat intelligence program. 0:00
• He emphasizes the importance of marrying existing frameworks with cyber threat intelligence to create effective strategies rather than building from scratch. 0:46
• The discussion covers practical advice for organizations looking to build out their incident response teams, vulnerability disclosure programs, and CTI functions. 0:21

Closing Statement: Chu’s insights provide a foundational approach for leaders aiming to strengthen their cyber defense posture by leveraging established methodologies and professional experience.

Sources:

  • 0:00 Introduction of Sherman Chu and his professional background.
  • 0:46 Core topic: Integrating frameworks with cyber threat intelligence.
  • 0:21 Consulting experience helping organizations build CTI and response teams.

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

My name is Sherman Chu. I am currently the cyber threat intelligence lead for Black Rockck. Uh prior to Black Rockck, I was actually um um also the lead for New York City um cyber security agency where I built out their uh um the full cyber threat intelligence program for the city itself. Uh and in between um I also did a lot of uh sort of um consulting and managing of um helping other organizations build out their sock, their instant response team um their vulnerability disclosure as well as a CTI team. Um and prior to all that I am a US Army veteran and uh yeah and here I am a little catchy uh title here called bling up your intelligence requirements but let's really focus on the core here which is you know the marriage of you know uh existing um uh frameworks in cyber threat intelligenc…