ASOM-Fedv6.1Open the explorer
CE-2 · Cycle Execution and Assurance

Priority Intelligence Requirements

Control Statement

Each cycle shall begin with a defined set of priority intelligence requirements that drive collection and hunting.

Purpose. To direct analytic effort at named questions, so that collection and hunting answer what the accountable authority needs rather than processing what arrives.

Discussion

Hunting without a requirement is sampling, and sampling an estate of federal scale returns whatever the analyst already expected to find. The tracking requirement is what separates this from a wish list: requirements that are recorded, never answered, and silently carried forward for four cycles describe an intelligence function that is busy rather than one that is directed. A requirement should close — as answered, as no longer relevant, or as unanswerable with current collection, which is itself a finding about visibility.

Goals and Metrics

A metric that cannot come out badly is not a metric. Each of these is capable of reporting that the control is not working.

Each cycle opens with a defined set of requirements.
  • Number of intelligence requirements set and the number answered by cycle close
  • Proportion of hunting effort traceable to a stated requirement

Accountability

Exactly one role is accountable, and every other role carries at least Informed — no control in the published catalog leaves a role with zero relationship to it. That is a stated property of how these were authored, not a coincidence, and not a claim that every role's work is worth equal attention here.

AOCTISOCHUNTPLATISSO
Authorizing Official / CISO: AccountableCyber Threat Intelligence cell: ResponsibleSOC / Defensive Operations: ConsultedHunt team: ConsultedPlatform and product owners: InformedGovernance / RMF / ISSO: Informed

AO Authorizing Official / CISOCTI Cyber Threat Intelligence cellSOC SOC / Defensive OperationsHUNT Hunt teamPLAT Platform and product ownersISSO Governance / RMF / ISSO

  • AccountableAuthorizing Official / CISO
  • ResponsibleCyber Threat Intelligence cell
  • ConsultedSOC / Defensive Operations
  • ConsultedHunt team
  • InformedPlatform and product owners
  • InformedGovernance / RMF / ISSO

Inputs and Outputs

Consumes

Produces

Activities

  1. L2Define the priority intelligence requirements for the cycle before collection begins.
  2. L2Record each requirement with a status of open, watching or answered.
  3. L2Direct collection and hunting activity against the open requirements.
  4. L3Derive requirements from the defensive intent (CG-1), the declared phase (CG-2) and the current threat courses of action, rather than from analyst preference.
  5. L3State for each requirement what an answer would look like, so it can be recognized when obtained.
  6. L3Close requirements explicitly, including closure as unanswerable with current collection — which is raised as a visibility finding rather than dropped.
  7. L3Carry unanswered requirements forward with a recorded reason rather than by default.
  8. L4Measure the proportion of requirements answered per cycle and the age of the oldest open requirement.
  9. L4Measure the proportion of hunting effort attributable to a named requirement, since unattributed effort is sampling.
  10. L5Revise the requirement-setting method where answered requirements repeatedly fail to change any decision, since a requirement that changes nothing was the wrong question.

Measurement

Outcome

Percentage of cycle requirements closed with a recorded disposition.

Performance

Percentage of hunting effort attributable to a named requirement.

Evidence and Assessment

Evidence expected

Intelligence requirement register with status and closure dispositions; visibility findings raised from unanswerable requirements.

Assessment procedure

Examine the register; test that collection or hunting activity addressed a sample of open requirements; examine the age of the oldest open item.

Related Guidance

Inherits
  • PM-16
  • RA-10
  • SI-5
Satisfies
  • ID.RA-02
  • DE.AE-07

Position in the Chain

Derived from the other controls’ own declarations, so the two directions cannot disagree.

Where This Control Is Used

Derived, in every case, from the declaration at the other end: the forms whose techniques name this control, the artifacts whose producing and consuming controls include it, the layers whose control lists name it, and the roles its own accountability chart puts to work. Nothing here is authored on this page, so the sheet cannot claim an edge the other end does not.

Forms of Maneuver It Assesses

  • M5AmbushTrade space for information and time, and impose cost.10 of 13 techniques — M5.01, M5.02, M5.03, M5.04, M5.05, M5.06, M5.07, M5.08, M5.11, M5.12
  • M1Screen / GuardGain early warning and buy reaction time before the adversary touches key terrain.6 of 15 techniques — M1.04, M1.05, M1.06, M1.07, M1.08, M1.10
  • M9Spoiling AttackDisrupt adversary staging before the attack is launched.5 of 9 techniques — M9.01, M9.03, M9.05, M9.08, M9.09
  • M7CounterattackSeize the initiative and evict before the adversary reaches the objective.3 of 17 techniques — M7.01, M7.14, M7.16
  • M3EnvelopmentMake identity, not network location, the decisive plane — surround the adversary with policy.2 of 20 techniques — M3.17, M3.18
  • M4Obstacle / CanalizationForce the adversary onto ground you own and watch.2 of 17 techniques — M4.04, M4.08
  • M10Exploitation & PursuitConvert contact into durable advantage rather than closing the ticket.1 of 7 techniques — M10.04

Terrain It Is Named On

  • TXCross-CuttingPriority intelligence requirements are what turn collection from a license question into a tasking question.

Artifacts It Stands On

  • producesPriority Cyber Intelligence RequirementsThree to seven questions the cycle will try to answer, each naming the decision it informs, the collection source expected to answer it, and an individual owner.
  • producesThreat course-of-action sketchTwo courses of action, most likely and most dangerous, drawn against the decisive points already designated. Each is a route across ground the estate really has, not a category of threat.
  • producesIndicators and signpostsFor each surviving hypothesis, the observable events that would confirm or kill it, handed to collection. The mechanism that makes this cycle’s analysis into next cycle’s requirements.
  • consumesDefensive intent paragraphOne signed paragraph stating what the defense exists to protect, what may be degraded to protect it, and the acceptable risk. The commander’s-intent analog, and the citation every downstream designation rests on.
  • consumesCycle cadence and calendarThe declared length of a cycle, its close date, and the refresh intervals that inherit from it. Makes “per cycle” a measurable unit rather than a figure of speech.
  • consumesAvenue-of-approach analysisThe enumerated routes an adversary could take toward each decisive point, including physical, supplier and maintenance routes, with unassessed routes recorded as intelligence gaps rather than as absence of risk.

Roles It Puts to Work