SER-005 — Threat Intelligence

**Threat intelligence as decision support**—how organizations interpret external threat knowledge to prioritize action, scope investigation, and communicate urgency. **Not** feed ingestion mechanics, TI platform tours, or MITRE encyclopedias.

SER-005 — Threat Intelligence

Series: SER-005
Volume: VOL-002 Intelligence
Version: 1.0
Fundamental question: How should organizations transform threat intelligence into actionable security decisions?
Pillar: PIL-THREAT-INTEL
Season: SEA-003
Status:Complete — FROZEN (D1 drafts)
Review: Every 6 months (next: 2027-01-03)
Expansion: SER-005 v2.0 only — no new articles in v1.0
Learning path: LP-005
Prerequisite: Volume 1 (minimum: KID-CON-0030, KID-CON-0049)


Purpose

Threat intelligence as decision support—how organizations interpret external threat knowledge to prioritize action, scope investigation, and communicate urgency. Not feed ingestion mechanics, TI platform tours, or MITRE encyclopedias.

Educational flow: Volume 1 analytical foundations → External knowledge → decisions

Authority anchors: KID-GLS-0005, KID-TIN-0001

Foundation for: SER-006 Operational Intelligence · SER-007 Security Intelligence


Reading order

Order KID Article Difficulty Time
Prerequisite: Volume 1
1 KID-GLS-0005 Threat Intelligence (term) 3 min
2 KID-CON-0050 Understanding Threat Intelligence Introductory 9 min
3 KID-CON-0051 Threat Intelligence vs Detection Introductory 8 min
4 KID-CON-0054 Common Misconceptions About Threat Intelligence Introductory 10 min
5 KID-CON-0052 Why Threat Intelligence Changes Priorities Intermediate 8 min
6 KID-CON-0053 Context Matters in Threat Intelligence Intermediate 8 min
7 KID-CON-0055 Using Threat Intelligence for Security Decisions Intermediate 9 min
8 KID-CON-0056 Threat Intelligence in Investigation Intermediate 9 min
9 KID-GLS-0024 Intelligence Confidence (term) 3 min
10 KID-GLS-0025 Threat Indicator (term) 3 min
11 KID-CON-0057 When Threat Intelligence Is Not Enough Intermediate 8 min
12 KID-CON-0058 Threat Intelligence as Decision Support Intermediate 10 min

Practitioner questions answered

Question Primary KID
What is threat intelligence? KID-CON-0050, KID-GLS-0005
Is TI the same as detection? KID-CON-0051
Why did priority change after TI? KID-CON-0052
How much should I trust this report? KID-CON-0053, KID-GLS-0024
What mistakes do teams make? KID-CON-0054
What decisions should TI drive? KID-CON-0055
How use TI in investigation? KID-CON-0056
When is TI insufficient? KID-CON-0057
What is the core thesis? KID-CON-0058

Glossary (series terms)

KID Term Status
KID-GLS-0005 Threat Intelligence ✅ shared
KID-GLS-0024 Intelligence Confidence
KID-GLS-0025 Threat Indicator

FAQs (attached)

KID Question Primary parent
KID-FAQ-0026 What is threat intelligence? KID-CON-0050
KID-FAQ-0027 Does TI replace detection? KID-CON-0051
KID-FAQ-0028 How does TI help prioritization? KID-CON-0052
KID-FAQ-0029 When ignore threat intelligence? KID-CON-0057
KID-FAQ-0030 Does TI prove an attack? KID-CON-0056

Not in scope (v1.0)

  • Feed ingestion and platform configuration
  • STIX/TAXII protocol tutorials
  • Standalone MITRE ATT&CK technique encyclopedia
  • ISAC membership or sharing agreements

Publishable bundle (debt)

ID Component Status
DEBT-S5-001 Pillar hub PIL-THREAT-INTEL
DEBT-S5-002 Concept map MAP-TI-DECISIONS
DEBT-S5-003 Learning path LP-005 formal INDEX
DEBT-S5-004 D2 human review batch

Collection statistics

Asset type Count
Educational articles 9
Glossary terms (series) 3
FAQ attachments 5
New KIDs this collection 14
Cumulative registered KIDs 120


Related Articles