From Security Data to Intelligence
Learn the difference between observations, context, analysis, and decision support.
In this lesson, you will learn to:
- Classify examples as data, information, intelligence, or decision support and explain the transformation between them.
From Security Data to Intelligence
This lesson gives you a precise mental model for intelligence work. You will follow one fictional alert from raw event to defensible judgment and learn why more data does not automatically create better intelligence.
Four Layers of Meaning
A security event is not automatically intelligence. Data is an observation recorded by a system: a timestamp, domain, process name, login result, or alert. Information is data organized with context, such as a set of failed logins grouped by account and time. Analysis is the reasoned interpretation of that information. Intelligence is the resulting judgment prepared for a specific consumer and decision.
Consider a fictional company, Northstar Freight. Its identity platform records 214 failed logins against three accounts from one hosting provider in 18 minutes. That is useful information, but it does not prove an attack. The analyst still needs to ask whether the accounts were exposed, whether the source was a corporate VPN, whether successful logins followed, and what the business should do. Intelligence connects the evidence to a decision while keeping uncertainty visible.
Practice: Write one sentence for each layer using the Northstar example. If your sentence contains a conclusion at the data layer, move that conclusion into the analysis layer. This small discipline prevents assumptions from becoming facts.
Intelligence Exists to Support a Choice
Intelligence is valuable because someone can use it. A report that lists interesting threats but never explains a decision is closer to a news digest than an intelligence product. Start by naming the consumer: an incident responder, SOC lead, vulnerability manager, executive, or product owner. Then identify the choice they need to make and the time available.
For Northstar Freight, an executive may need to decide whether to fund phishing-resistant authentication this quarter. The SOC lead may need to decide which identity telemetry to hunt today. Both consumers can use the same underlying evidence, but they need different products. The executive needs business impact, confidence, and investment options. The SOC lead needs observable behaviors, data sources, and a bounded hunt.
A useful test: remove the final recommendation from your draft. If the remaining text does not make clear who needed the answer and what decision it supports, the requirement is not ready. Intelligence should reduce uncertainty enough to improve a choice, not pretend to eliminate uncertainty entirely.
Resources
- NIST Cybersecurity Framework 2.0 — Use the framework as a vocabulary for connecting intelligence to organizational risk and defensive outcomes.
- CISA Cybersecurity Advisories — Compare public advisory language with the distinction between observations, judgments, and recommended actions.