ABCDEFGHIJKLMNOPQRSTUVWXYZ
1
2
Priority Intelligence Requirements Worksheet
3
4
Follow these steps to develop priority intel requirements for your CTI program using the Red Hat process.
5
Please hit "FILE" and "MAKE A COPY" and then you'll be able to edit and use it for yourself.
6
Please share with us your feedback.
7
8
STEP 1
Extract the essence of your organization into ELEMENTS and their FUNCTION
9
1a) ELEMENTS -> keywords, topics, short statements represing the organization, its strategy, mission and vision from high-level documents.
10
1b) FUNCTION -> What it is about the element that needs to be secured from information security perspective.
11
12
STEP 2
Research and map supporting ASSETS and technology which support each ELEMENT.
13
You can be as specific as including assets from a Configuration Management database or you can keep it high level.
14
Document your assets in the Assets sheet and then assign them to each element.
15
16
STEP 3
Map the Types of Adversarial Operations to your elements
17
Select 2 most impactful adversarial operations which are threats to an ELEMENT [1, 2]
18
19
STEP 4
Risk assesment - Likelihood and Impact
20
1a) LIKELIHOOD -> Define and assess the appeal of the ELEMENT and supporting ASSET for attackers in worst case scenario.
21
1b) IMPACT -> Define and assess the worst case scenario of an impact to organization in succesful attack on supporting ASSET.
22
23
STEP 5
PIRs customization
24
Now you can access your PIRs sorted by Risk Score in the PIRs auto generated list.
25
Should you need to customize them for operationalization purposes - use PIRs manually edited list.
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100