Cybatar Security Hub
Threat Intelligence / Intelligence requirements
Threat-intelligence guide

Cyber Threat Intelligence Requirements & Collection Priorities

How should an organisation decide what cyber threat intelligence it actually needs?

Direct answer

Start with decisions the organisation must make, then define the threat questions that would change those decisions, the assets and business services in scope, acceptable evidence sources, required timeliness, handling rules, owners and review triggers. Intelligence volume is not a substitute for clear requirements.

External reference

National Institute of Standards and Technology (NIST) — SP 800-150 — Guide to Cyber Threat Information Sharing

NIST SP 800-150 is final guidance on cyber threat information sharing. It describes establishing information-sharing goals, identifying sources, scoping activities, defining publication/distribution rules and making effective use of threat information.

Primary source →

Operational method

Step 1

Start from a decision

Define the operational or risk decision intelligence is meant to improve: prioritising exposure, protecting a service, preparing a hunt, responding to an incident or monitoring a threat actor.

Step 2

Write the intelligence question

Express the requirement as a question with scope, time horizon, assets, geography or technology where relevant. Avoid vague objectives such as “collect more indicators.”

Step 3

Define acceptable sources

Identify internal telemetry, incident evidence, trusted external reporting, commercial/community feeds or structured exchanges that could answer the question.

Step 4

Set timeliness and handling rules

Record how current the information must be, who may use or redistribute it, and any confidentiality, contractual or legal handling constraints.

Step 5

Review usefulness

Measure whether the intelligence changed a decision, improved prioritisation or generated a testable hypothesis. Retire requirements that no longer produce operational value.

Relevant Cybatar sources

Claim boundary

Cybatar can organise intelligence records, feeds, IOCs, observations, actors, hunts and related operational context. It does not determine intelligence requirements automatically or guarantee the completeness, timeliness or accuracy of third-party intelligence.

These pages are Cybatar-authored threat-intelligence and threat-hunting guidance. NIST, OASIS and MITRE ATT&CK are external sources. References do not establish certification, endorsement, native STIX/TAXII compatibility, complete threat coverage, attribution certainty or proof that a hunt found all malicious activity.

Related operating resources