Not all intelligence serves the same audience or the same decision. The levels of intelligence describe how CTI products vary in scope, time horizon, and detail depending on who will use them. A board member weighing investment in security needs a very different product from an analyst tuning a detection rule, even when both outputs trace back to the same underlying activity. Thinking in terms of levels helps a program match each finding to the right consumer, pitch its reporting at a useful altitude, and avoid drowning executives in technical detail or starving responders of the specifics they need.
The levels of intelligence described in this area include the following.
- Strategic intelligence: high level analysis of threat trends, actor motivations, and risk, written for executives and board members who set direction and allocate resources.
- Operational intelligence: insight into specific campaigns, actor behavior, and likely future activity, consumed by security leaders and incident response planners.
- Tactical intelligence: detail on adversary tactics, techniques, and procedures, used by defenders to shape detection, hunting, and response.
- Technical intelligence: granular, often short lived indicators such as addresses, hashes, and domains, consumed by analysts and automated tooling.
References#
- MITRE ATT&CK, attack.mitre.org
- SANS, The Sliding Scale of Cyber Security