Cyber Threat Intelligence cell
Responsible for 20 controls, consulted on 23, accountable for exactly two — fusion and the brief. Both of those are judgment rather than production, which is the point of the role.
What It Is.
Owns. Frame, Map and Fuse. The intelligence requirements, the threat courses of action, and the confidence levels.
Doctrinal origin. The G2, running ATP 2-33.4’s analytic process — screen, analyze, integrate, produce — against priority requirements, and publishing with explicit confidence.
The intelligence cell runs three of the six cycle steps: Frame, Map and Fuse. In control terms that means it holds the terrain overlay (TM-1), asset weighting (TM-3), the connection register (TM-5), decisive-point identification (KT-1), avenue-of-approach analysis (KT-3), reachability (KT-4), the maneuver catalog and main effort (SM-1, SM-4), branches and sequels (SM-5), dwell estimation (TA-2), and the priority cyber intelligence requirements themselves (CE-2).
The two controls where the cell is Accountable rather than Responsible are the two that are pure judgment: fusion and confidence (CE-3), and brief generation (CE-7). Everything else the cell does is production — a map, a register, a score. These two decide what the program believes and how strongly, and then decide what leadership is told. Placing accountability there rather than on the overlay is a statement that the framework’s hardest problem is not collection.
The cell is Responsible for the terrain overlay alongside platform owners, and that co-responsibility is deliberate. Intelligence not anchored to the organization’s own ground is threat trivia: a well-sourced assessment of an adversary’s tradecraft, with no statement of whether that tradecraft crosses any path this estate actually permits, has not answered a question anyone can act on.
Every Control It Touches.
Computed from the RACI each control carries, not written down a second time. If an assignment changes in the manual, this list changes with it.
Accountable0 controls
Answers for the outcome. Exactly one role per control, and it is not delegable.
None. This role holds no accountable assignment anywhere in the framework.
Responsible9 controls
Does the work, or shares it. More than one role may be Responsible for the same control.
Consulted27 controls
Asked before the control is settled, because it holds knowledge the accountable role does not.
Informed42 controls
Told the outcome. Not padding — each of these is a place the role has to be able to reconstruct a decision it did not make.
What It Puts into the Chain.
The outputs declared by every control this role is Accountable or Responsible for, and where each one goes. 27 products across 9 controls.
KT — Key Terrain and Decisive Points
- Designated points requiring a protection floor
- Targets whose approach routes must be enumerated
- Targets for the reachability assessment
- Candidates for main-effort designation
- Route set for formal reachability assessment
- Routes requiring a maneuver to be sited on them
- Intelligence gaps arising from unassessed routes
- The specific barriers holding the line where reachability is prevented
- Reachability result feeding the residual risk picture
- Headline finding for the cycle brief
- Reachable decisive points requiring disposition
SM — Scheme of Maneuver
- Candidate actions for pre-authorization
- Branch actions requiring an authority level in the rules of engagement
TA — Tempo and Temporal Advantage
- Dwell estimate, the numerator of the temporal advantage ratio
- Stated basis reported alongside the posture result
CE — Cycle Execution and Assurance
- Baseline refresh interval for the terrain overlay
- Trigger to set the cycle’s intelligence requirements
- Cycle boundary for the record and trend
- Questions whose answers require fusion and a confidence level
- Requirements identifying the courses of action to pre-plan against
- Requirements answered and outstanding, reported in the brief
- Confidence discipline applied to the dwell estimate
- Conclusions recorded in the cycle record
- Confidence-tagged assessments for the brief
- Evidence informing revision of the defensive intent
- Findings requiring disposition
- Continuous-monitoring evidence for oversight and audit
What It Depends On.
The inputs those same controls declare. Anything sourced from another control is a dependency on another role; anything marked as outside the framework has to be obtained from the wider organization.
KT — Key Terrain and Decisive Points
- Candidate elements and their position
- Defensive weight supporting the designation
- Defensive intent identifying what the campaign exists to protect
- Decisive points to be approached
- Permitted connections forming candidate routes
- Zone boundaries a route must cross
- Threat intelligence on adversary tradecraft and observed campaign behavior
- Enumerated avenues of approach
- Permitted-path graph — denied paths are excluded by definition
SM — Scheme of Maneuver
- Avenues of approach informing likely courses of action
- Priority intelligence requirements identifying what is being watched for
- Threat intelligence on most-likely and most-dangerous adversary behavior
TA — Tempo and Temporal Advantage
- Sector threat reporting, incident history, partner and government intelligence
- Confidence discipline applied to the estimate
CE — Cycle Execution and Assurance
- Defensive intent establishing why the cycle exists
- Declared phase, which may justify a faster cadence
- Cycle start
- Defensive intent identifying what must be protected
- Gaps in avenue-of-approach analysis raising collection needs
- Intelligence requirements to be answered
- Collected telemetry, threat reporting and hunt results
- Terrain overlay
- Reachability result
- Main effort
- Temporal advantage result
- Coverage and residual risk
- Trend across cycles
What the Role Has to Be Good At.
Analysis of competing hypotheses, key-assumptions checks, indicators and signposts. The technique matters less than the habit of writing the alternative down before dismissing it.
A confidence level is a claim about evidence, not an intensifier. “High confidence” has to mean something a reader can test, and it has to be capable of being low.
KT-3 and KT-4 are graph problems over the connection register. An analyst who cannot read a network and identity architecture cannot trace an avenue of approach through it, and will enumerate only the direct edges.
KT-4 requires the reachability answer to be recorded whichever way it comes out. A cell that only publishes when the answer is comfortable has broken the metric and, worse, has broken the trend.
CISA, JCDC and sector ISAC reporting arrives with its own confidence and its own gaps. Fusing it without laundering it into certainty is most of the job (CE-3).
How It Goes Wrong.
Each of these is a way the role can appear to be operating — the artifacts arrive, the chart still shows one accountable party — while producing nothing the defense can use.
The cell degrades into forwarding third-party indicators. Volume goes up, PCIRs stop being answered, and nothing in the terrain picture changes for a year.
Every product asserts high confidence, so the field stops carrying information. Detectable: look for a cycle in which a moderate or low confidence was ever published.
Adversary reporting that never resolves to an element on the overlay. It reads well, it is often true, and no defensive decision can be made from it.
TM-6 exists because a stale overlay is more dangerous than none — a confident picture of ground that has moved. The failure is silent by construction, which is why the refresh interval is a control and not a habit.
Products shaped by what will present well in CE-7 rather than by what CE-2 asked. The tell is a brief with no unanswered requirements in it.
Against the Other Five.
The shared count beside each is derived — how many controls the two roles both appear on. The note is authored: what the relationship is actually for, and where it breaks.
The cell drafts intent and phase for approval, and briefs the result. Its independence on CE-3 is the thing that makes the brief worth reading.
The cell says where the routes are; the SOC sites the moves on them. When SM-2 assignment consistently ignores KT-3, one of the two is wrong and the disagreement is worth having in the open.
The closest working relationship in the framework: hunt is Responsible with the cell on KT-3, KT-4, CE-2 and CE-3. Fuse raises the hypothesis, hunt goes and tests it, and the result comes back into the same control.
Co-responsible for the overlay and the connection register. Platform owners know what is actually deployed; the cell knows what it means positionally. Neither has the whole picture alone.
The cell produces the substance; the ISSO produces the record and the inheritance mapping. The cell should never be the one arguing about which 800-53 control an activity satisfies.