Start with decisions the organisation must make, then define the threat questions that would change those decisions, the assets and business services in scope, acceptable evidence sources, required timeliness, handling rules, owners and review triggers. Intelligence volume is not a substitute for clear requirements.
External reference
NIST SP 800-150 is final guidance on cyber threat information sharing. It describes establishing information-sharing goals, identifying sources, scoping activities, defining publication/distribution rules and making effective use of threat information.
Primary source →Operational method
Start from a decision
Define the operational or risk decision intelligence is meant to improve: prioritising exposure, protecting a service, preparing a hunt, responding to an incident or monitoring a threat actor.
Write the intelligence question
Express the requirement as a question with scope, time horizon, assets, geography or technology where relevant. Avoid vague objectives such as “collect more indicators.”
Define acceptable sources
Identify internal telemetry, incident evidence, trusted external reporting, commercial/community feeds or structured exchanges that could answer the question.
Set timeliness and handling rules
Record how current the information must be, who may use or redistribute it, and any confidentiality, contractual or legal handling constraints.
Review usefulness
Measure whether the intelligence changed a decision, improved prioritisation or generated a testable hypothesis. Retire requirements that no longer produce operational value.
Relevant Cybatar sources
Claim boundary
Cybatar can organise intelligence records, feeds, IOCs, observations, actors, hunts and related operational context. It does not determine intelligence requirements automatically or guarantee the completeness, timeliness or accuracy of third-party intelligence.
These pages are Cybatar-authored threat-intelligence and threat-hunting guidance. NIST, OASIS and MITRE ATT&CK are external sources. References do not establish certification, endorsement, native STIX/TAXII compatibility, complete threat coverage, attribution certainty or proof that a hunt found all malicious activity.