Cyber Intelligence Planning

Responsible for developing intelligence plans to satisfy cyber operation requirements. Identifies, validates, and levies requirements for intelligence collection and analysis. Participates in targeting selection, validation, synchronization, and execution of cyber actions. Synchronizes intelligence activities to support organization objectives in cyberspace.

  • T0630: Incorporate intelligence equities into the overall design of cyber operations plans
  • T0718: Identify intelligence gaps and shortfalls
  • T0734: Issue requests for information
  • T1020: Determine the operational and safety impacts of cybersecurity lapses
  • T1023: Identify critical technology procurement requirements
  • T1033: Support cyber operations
  • T1035: Determine how threat activity groups employ encryption to support their operations
  • T1036: Integrate leadership priorities
  • T1037: Develop operations strategies
  • T1038: Integrate organization objectives in intelligence collection
  • T1043: Determine staffing needs
  • T1044: Review course of action analysis results
  • T1045: Review exercise analysis results
  • T1046: Assess operation performance
  • T1047: Assess operation impact
  • T1048: Synchronize operational assessment procedures and critical information requirement processes
  • T1054: Scope analysis reports to various audiences that accounts for data sharing classification restrictions
  • T1456: Determine the impact of threats on cybersecurity
  • T1457: Implement threat countermeasures
  • T1637: Coordinate intelligence support to operational planning
  • T1638: Recommend cyber operation targets
  • T1639: Assess target vulnerabilities and operational capabilities
  • T1644: Develop cyber operations indicators
  • T1647: Develop priority information requirements
  • T1649: Synchronize intelligence support plans across partner organizations
  • T1650: Develop cybersecurity success metrics
  • T1657: Develop a diverse program of information materials
  • T1661: Assess all-source data for intelligence or vulnerability value
  • T1678: Develop cyber operations crisis action plans
  • T1679: Develop organizational decision support tools
  • T1684: Communicate information requirements to collection managers
  • T1685: Assess capability to satisfy assigned intelligence tasks
  • T1686: Identify intelligence requirements
  • T1687: Draft intelligence sections of cyber operations plans
  • T1688: Identify strategies to counter potential target actions
  • T1702: Integrate intelligence guidance into cyber operations planning activities
  • T1705: Provide intelligence guidance to cyber operations requirements
  • T1712: Recommend potential courses of action
  • T1717: Recommend changes to planning policies and procedures
  • T1718: Implement changes to planning policies and procedures
  • T1727: Develop cyber intelligence collection and production requirements
  • T1728: Implement collection operation plans
  • T1729: Synchronize intelligence planning activities with operational planning timelines
  • T1738: Determine cyber operations partner intelligence capabilities and limitations
  • T1739: Develop intelligence collection requirements
  • T1741: Designate priority information requirements
  • T1750: Identify intelligence environment preparation derived production needs
  • T1752: Develop courses of action based on threat factors
  • T1756: Interpret environment preparation assessments
  • T1761: Determine if changes to the operating environment require review of the plan
  • T1779: Coordinate strategic planning efforts with internal and external partners
  • T1791: Provide cyber recommendations to intelligence support planning
  • T1800: Recommend changes to operational plans
  • T1815: Develop cyber intelligence plans
  • T1835: Determine if intelligence requirements and collection plans are accurate and up-to-date
  • T1836: Document lessons learned during events and exercises