| name | managing-intelligence-lifecycle |
| description | Manages the end-to-end cyber threat intelligence lifecycle from planning and direction through collection, processing, analysis, dissemination, and feedback to ensure intelligence products meet stakeholder requirements and continuously improve. Use when establishing or maturing a CTI program, defining intelligence requirements with business stakeholders, or building feedback loops between intelligence consumers and producers. Activates for requests involving CTI program maturity, intelligence requirements, PIRs, or intelligence lifecycle management.
|
| domain | cybersecurity |
| subdomain | threat-intelligence |
| tags | ["CTI","intelligence-lifecycle","PIR","NIST-SP-800-150","threat-intelligence-program","NIST-CSF"] |
| version | 1.0.0 |
| author | team-cybersecurity |
| license | Apache-2.0 |
| nist_csf | ["ID.RA-01","ID.RA-05","DE.CM-01","DE.AE-02"] |
Managing Intelligence Lifecycle
When to Use
Use this skill when:
- Establishing a formal CTI program and defining its operational model
- Conducting quarterly intelligence requirements reviews with business stakeholders
- Evaluating CTI program maturity against established frameworks (FIRST CTI-SIG maturity model)
Do not use this skill for day-to-day IOC triage or incident-specific intelligence tasks — those use operational intelligence workflows, not lifecycle management.
Detection Gaps & Validation
- Collection without direction: subscribing to every feed without PIRs yields volume, not answers. Validate that each collection source traces to a documented PIR before counting it as coverage.
- Unanswered-PIR blind spots: a PIR with no matching collection source is a coverage gap that produces low-confidence guesswork. Document and escalate the gap rather than fabricating an estimate.
- Tactical-only drift: overweighting IOC bulletins starves strategic and operational products that inform investment and risk decisions. Confirm all three intelligence levels are produced on cadence.
- Stale processing rules: dedup and confidence-scoring logic that is never retuned silently drops or over-merges indicators. Re-baseline against known test IOCs each quarter.
- No feedback = unmeasured value: without structured feedback within 5 business days, products drift from stakeholder needs. Track PIR coverage rate, IOC true-positive rate, and time-to-disseminate.
- How to validate: run a quarterly review confirming every PIR is either answered with cited confidence or flagged as a gap, and verify metrics (TP rate, satisfaction) trend over time rather than relying on output volume.
Prerequisites
- Executive sponsorship and defined CTI team structure (1+ dedicated analysts)
- Stakeholder map identifying intelligence consumers (SOC, IR, executive team, vulnerability management)
- Existing feed subscriptions or ISAC memberships for collection baseline
- CTI platform (MISP, ThreatConnect, OpenCTI) for lifecycle management
Workflow
Step 1: Planning and Direction
Define Priority Intelligence Requirements (PIRs) with stakeholders:
- Interview SOC leads, IR team, CISO, risk management, and product security
- Document PIRs in structured format: "What is the current capability and intent of [threat actor] to attack [critical asset] using [technique]?"
- Prioritize 5–10 PIRs for the quarter, reviewed monthly
Example PIR: "Is ransomware group Cl0p currently targeting organizations in our sector using MoveIT or GoAnywhere vulnerabilities?"