Volume 2 — Intelligence
Volume 2 teaches how organizations turn **intelligence** — external and internal — into **actionable security decisions**. It continues the Volume 1 decision-support thread: intelligence informs judgment; it does not replace it.
Volume 2 — Intelligence
Volume: VOL-002
Version: 1.2
Status: ✅ Complete — series frozen v1.0 · coherence PASS WITH OBSERVATIONS
Publishable level: V1 (curriculum) · V2 (coherence) · V3 bundle pending
Review: Every 6 months (next: 2027-01-03)
Prerequisite: Volume 1 — Analytical Foundations (minimum: KID-CON-0030, KID-CON-0049)
Overview
Volume 2 teaches how organizations turn intelligence — external and internal — into actionable security decisions. It continues the Volume 1 decision-support thread: intelligence informs judgment; it does not replace it.
This volume is not a threat feed catalog, SIEM feature guide, or MITRE encyclopedia. It is practitioner curriculum on operationalizing intelligence for better decisions.
Reader outcome
After Volume 2, a practitioner can:
- Transform threat intelligence into prioritized, contextual action — not feed consumption
- Use operational intelligence from internal telemetry and workflows to improve daily decisions
- Integrate external threat knowledge and internal operational knowledge without contradiction
- Recognize when intelligence misleads, conflicts with evidence, or is insufficient alone
The intelligence arc
External knowledge Internal knowledge Integration
(SER-005 Threat Intel) → (SER-006 Operational Intel) → (SER-007 Security Intelligence)
↓ ↓ ↓
TI → decisions OI → decisions TI + OI → decisions
Continuity with Volume 1:
Evidence → Investigation → Risk → Attack Paths → Threat Intel → Operational Intel → Security Intel
Every step asks: What decision does this improve?
Series (planned reading order)
| Order | Series | Fundamental question | Status |
|---|---|---|---|
| 1 | SER-005 Threat Intelligence | How should organizations transform threat intelligence into actionable security decisions? | ✅ frozen |
| 2 | SER-006 Operational Intelligence | How should organizations transform operational knowledge into better security decisions? | ✅ frozen |
| 3 | SER-007 Security Intelligence | How should organizations integrate external and internal intelligence into a unified security decision process? | ✅ frozen |
SER-005 authoring principles
Before writing SER-005 articles, apply these constraints (aligned with Volume 1 and SER-004):
| Do | Do not |
|---|---|
| Teach interpretation and decision use of TI | Teach feed ingestion mechanics |
| Reference MITRE/ATT&CK as frameworks, not product maps | Product-specific TI module tours |
Connect TI to risk context (KID-CON-0030) and investigation (KID-CON-0019) |
Standalone TI lifecycle deep dive as series opener |
| Include Common Misconceptions About Threat Intelligence | Confuse TI with detection rules |
| Close with synthesis article (TI as decision support) | Treat TI as automatic prioritization |
Authority anchors: KID-GLS-0005, KID-TIN-0001
Suggested article themes (to be finalized at SER-005 index creation):
- Understanding Threat Intelligence (decision lens)
- Threat Intelligence vs Detection
- Why Threat Intelligence Changes Priorities
- Context Matters in Threat Intelligence
- Common Misconceptions About Threat Intelligence
- Using Threat Intelligence for Security Decisions
- Threat Intelligence in Investigation
- When Threat Intelligence Is Not Enough
- Threat Intelligence as Decision Support
Article KIDs: KID-CON-0050+ — assigned at authoring.
SER-006 scope (preview)
Internal knowledge — what the organization knows from its own operations: telemetry patterns, queue dynamics, attention points, investigation outcomes, control effectiveness signals.
Fundamental question: How should organizations use operational intelligence to improve security decisions?
Authority anchors: KID-GLS-0006, KID-OIN-0001
Not in scope: SIEM query language, dashboard configuration, vendor analytics features.
SER-007 scope (preview)
Integration — how external threat knowledge and internal operational knowledge combine into unified security intelligence for prioritization, investigation scope, and stakeholder communication.
Fundamental question: How should organizations integrate threat and operational intelligence into security decisions?
Renamed from: SER-007 Security Decision Making (editorial alignment — Volume 2 synthesis series).
Not in scope: Generic decision theory; enterprise GRC; compliance frameworks.
Glossary (expected volume terms)
| KID | Term | Status |
|---|---|---|
| KID-GLS-0005 | Threat Intelligence | ✅ shared |
| KID-GLS-0006 | Operational Intelligence | ✅ shared |
| KID-GLS-0023 | Decision Support | ✅ shared (VOL-001) |
| KID-GLS-0024 | Intelligence Confidence | ✅ SER-005 |
| KID-GLS-0025 | Threat Indicator | ✅ SER-005 |
| KID-GLS-0026 | Operational Signal | ✅ SER-006 |
| KID-GLS-0027 | Operational Context | ✅ SER-006 |
| KID-GLS-0028 | Security Intelligence | ✅ SER-007 |
Volume 2 completion criteria
| Criterion | Required for V1 |
|---|---|
| SER-005 frozen v1.0 | ✅ |
| SER-006 frozen v1.0 | ✅ |
| SER-007 frozen v1.0 | ✅ |
| Volume coherence assessment (KACA-VOL2) | ✅ PASS w/ obs |
| Publishable bundle | debt — not blocking Volume 3 |
Assessment: KNOWLEDGE_ARCHITECTURE_COHERENCE_ASSESSMENT_VOLUME2.md
Foundation for
Volume 3 — Security Entities — the fundamental concepts analysts reason about (assets, identities, applications).