
Media & Entertainment
Information Sharing & Analysis Center
WHAT — The ME-ISAC is a trusted member-driven community that serves as a central focal point for the collection, analysis, and dissemination of risk and threat information among its members.
WHY — All Media and Entertainment companies are facing common threats. What attacks one of us, will eventually attack all of us. By working together and sharing information about observed threats, the industry as a whole can create a herd immunity to threats and better defend itself. We are stronger together.
HOW — Operating as an initiative within the CDSA for the benefit of the TPN, the ME-ISAC will provide members bidirectional sharing of intelligence on incidents, threats, risks, vulnerabilities, and associated remediations in the form of alerts, threat intelligence feeds, newsletters, forums, best practices, training, and similar services.
The ME-ISAC will engage in cooperative partnerships with trade associations, government, law enforcement, and other cross-sector sharing forums on behalf of its members in order to deliver timely, relevant, and actionable intelligence received from multiple disparate sources into a single curated stream.
ME-ISAC products will be tagged with a data classification to identify the releasability of the data based on the sensitivity of the data and source. These classifications follow international best practices established by FIRST known as the Traffic Light Protocol.
TLP: | EXPLANATION: |
---|---|
WHITE: Unlimited | Subject to standard copyright rules, WHITE information may be distributed freely, without restriction. |
GREEN: Community Wide | Information in this category can be circulated widely within a particular community. However, the information may not be published or posted publicly on the Internet, nor released outside of the community. |
AMBER: Limited Distribution | The recipient may share AMBER information with others within their organization, but only on a ‘need-to-know’ basis. The originator may be expected to specify the intended limits of that sharing. |
RED: Named Recipients Only | In the context of a meeting, for example RED information is limited to those present at the meeting. In most circumstances, RED information will be passed verbally or in person. |
ME-ISAC Products
ME-ISAC products and services include the following:
Threat Intel Platform — The ME-ISAC operates a Threat Intel Platform (TIP) that members may access to receive and research threat indicators, such as known-malicious IP addresses, domains, or email addresses. This platform also provides a machine-readable feed enabling members to receive information directly into their existing security operations tools. Sign up here: ME-ISAC ThreatConnect
Alerts — The ME-ISAC extracts Threat Intel from the TIP into regular curated Threat Summaries and ad-hoc Alerts when appropriate and necessary. These alerts will be distributed via email. These messages will include actionable indicators (such as domains, IP addresses, email addresses, etc.) that have been observed exhibiting malicious activity that members can use to enhance their security posture. Sign up here: ME-ISAC Alerts
Community Chat — The ME-ISAC manages a Slack workspace with multiple channels focused on specific topic. This platform provides community collaboration, enabling members to discuss and share topics of interest to the industry. Sign up here: ME-ISAC Slack