ISAC (Information Sharing and Analysis Center)
Definition
A sector-specific membership organisation that collects, analyses, and redistributes threat intelligence among its members under confidentiality agreements. Examples include FS-ISAC (financial services), H-ISAC (healthcare), and MS-ISAC (state and local government in the US).
- Function
- Collects and redistributes threat intelligence among members
- Structure
- Sector-specific membership organisation
- Examples
- FS-ISAC, H-ISAC, MS-ISAC
- Basis of sharing
- Confidentiality agreements among members
Common questions
Why do ISACs organise by sector rather than as one general threat-sharing body?+
Threats and regulatory context differ significantly between industries, for example financial fraud indicators versus healthcare ransomware patterns, so sector-specific ISACs let members share intelligence that is directly relevant and interpretable within their own operating environment.
How does incident-response work draw on an ISAC in practice?+
During an active incident, a responder can query the relevant ISAC for indicators of compromise already reported by peer organisations facing the same campaign, speeding up attribution and containment without waiting for public disclosure.
Related terms
- IoC (Indicator of Compromise)
- Observable artefact linked to malicious activity. File hashes (MD5, SHA-256, ImpHash, ssdeep, TLSH), IPs, domains, URLs, registry keys, mutex names, named pipes,...
- STIX (Structured Threat Information eXpression)
- An OASIS open standard that defines a JSON-based language for describing cyber threat intelligence. STIX 2.1 defines objects for indicators, threat actors,...
- TAXII (Trusted Automated eXchange of Indicator Information)
- An OASIS open standard that defines an HTTPS-based protocol for transporting STIX content between organisations. A TAXII server exposes collections; clients poll...
- Threat Intelligence
- Processed, analysed information about adversaries, their capabilities, and their current or anticipated activities. Includes strategic intelligence (actor motivations and trends) and tactical...
- Traffic Light Protocol (TLP)
- A standardised colour-coded scheme for marking intelligence sharing restrictions. TLP:RED is for named recipients only; TLP:AMBER is for members' organisations; TLP:GREEN is...