Volume 2 — Intelligence

Volume 2 teaches how organizations turn **intelligence** — external and internal — into **actionable security decisions**. It continues the Volume 1 decision-support thread: intelligence informs judgment; it does not replace it.

Volume 2 — Intelligence

Volume: VOL-002
Version: 1.2
Status:Complete — series frozen v1.0 · coherence PASS WITH OBSERVATIONS
Publishable level: V1 (curriculum) · V2 (coherence) · V3 bundle pending
Review: Every 6 months (next: 2027-01-03)
Prerequisite: Volume 1 — Analytical Foundations (minimum: KID-CON-0030, KID-CON-0049)


Overview

Volume 2 teaches how organizations turn intelligence — external and internal — into actionable security decisions. It continues the Volume 1 decision-support thread: intelligence informs judgment; it does not replace it.

This volume is not a threat feed catalog, SIEM feature guide, or MITRE encyclopedia. It is practitioner curriculum on operationalizing intelligence for better decisions.


Reader outcome

After Volume 2, a practitioner can:

  1. Transform threat intelligence into prioritized, contextual action — not feed consumption
  2. Use operational intelligence from internal telemetry and workflows to improve daily decisions
  3. Integrate external threat knowledge and internal operational knowledge without contradiction
  4. Recognize when intelligence misleads, conflicts with evidence, or is insufficient alone

The intelligence arc

External knowledge          Internal knowledge          Integration
(SER-005 Threat Intel)  →   (SER-006 Operational Intel) → (SER-007 Security Intelligence)
        ↓                              ↓                              ↓
   TI → decisions                  OI → decisions            TI + OI → decisions

Continuity with Volume 1:

Evidence → Investigation → Risk → Attack Paths → Threat Intel → Operational Intel → Security Intel

Every step asks: What decision does this improve?


Series (planned reading order)

Order Series Fundamental question Status
1 SER-005 Threat Intelligence How should organizations transform threat intelligence into actionable security decisions? ✅ frozen
2 SER-006 Operational Intelligence How should organizations transform operational knowledge into better security decisions? ✅ frozen
3 SER-007 Security Intelligence How should organizations integrate external and internal intelligence into a unified security decision process? ✅ frozen

SER-005 authoring principles

Before writing SER-005 articles, apply these constraints (aligned with Volume 1 and SER-004):

Do Do not
Teach interpretation and decision use of TI Teach feed ingestion mechanics
Reference MITRE/ATT&CK as frameworks, not product maps Product-specific TI module tours
Connect TI to risk context (KID-CON-0030) and investigation (KID-CON-0019) Standalone TI lifecycle deep dive as series opener
Include Common Misconceptions About Threat Intelligence Confuse TI with detection rules
Close with synthesis article (TI as decision support) Treat TI as automatic prioritization

Authority anchors: KID-GLS-0005, KID-TIN-0001

Suggested article themes (to be finalized at SER-005 index creation):

  • Understanding Threat Intelligence (decision lens)
  • Threat Intelligence vs Detection
  • Why Threat Intelligence Changes Priorities
  • Context Matters in Threat Intelligence
  • Common Misconceptions About Threat Intelligence
  • Using Threat Intelligence for Security Decisions
  • Threat Intelligence in Investigation
  • When Threat Intelligence Is Not Enough
  • Threat Intelligence as Decision Support

Article KIDs: KID-CON-0050+ — assigned at authoring.


SER-006 scope (preview)

Internal knowledge — what the organization knows from its own operations: telemetry patterns, queue dynamics, attention points, investigation outcomes, control effectiveness signals.

Fundamental question: How should organizations use operational intelligence to improve security decisions?

Authority anchors: KID-GLS-0006, KID-OIN-0001

Not in scope: SIEM query language, dashboard configuration, vendor analytics features.


SER-007 scope (preview)

Integration — how external threat knowledge and internal operational knowledge combine into unified security intelligence for prioritization, investigation scope, and stakeholder communication.

Fundamental question: How should organizations integrate threat and operational intelligence into security decisions?

Renamed from: SER-007 Security Decision Making (editorial alignment — Volume 2 synthesis series).

Not in scope: Generic decision theory; enterprise GRC; compliance frameworks.


Glossary (expected volume terms)

KID Term Status
KID-GLS-0005 Threat Intelligence ✅ shared
KID-GLS-0006 Operational Intelligence ✅ shared
KID-GLS-0023 Decision Support ✅ shared (VOL-001)
KID-GLS-0024 Intelligence Confidence ✅ SER-005
KID-GLS-0025 Threat Indicator ✅ SER-005
KID-GLS-0026 Operational Signal ✅ SER-006
KID-GLS-0027 Operational Context ✅ SER-006
KID-GLS-0028 Security Intelligence ✅ SER-007

Volume 2 completion criteria

Criterion Required for V1
SER-005 frozen v1.0
SER-006 frozen v1.0
SER-007 frozen v1.0
Volume coherence assessment (KACA-VOL2) ✅ PASS w/ obs
Publishable bundle debt — not blocking Volume 3

Assessment: KNOWLEDGE_ARCHITECTURE_COHERENCE_ASSESSMENT_VOLUME2.md


Foundation for

Volume 3 — Security Entities — the fundamental concepts analysts reason about (assets, identities, applications).



Related Articles