Cyber Threat Intelligence Request for Information (RFI) Protocol
A Framework for Disciplined and Actionable Intelligence Requests
The RFI process manages any time-sensitive, ad-hoc requirement for intelligence needed to support an ongoing event or incident. To ensure speed and quality, a Cyber Threat Intelligence Center (CTIC) requires a standardized protocol for the context and quality of all submitted data.
Data Quality & Formatting Standards
To accelerate the intelligence cycle, all submitted data must adhere to the following core principles. Submissions that fail to meet these standards may be rejected.
Curation & Validation
Data must be fully curated, integrating information from various sources. All data points require rigorous validation and proper citation (APA format) to establish a clear evidence trail.
Standardized Formatting
Submissions must follow a consistent format congruent with your incident response platform. This includes leveraging standards like NIST and analytical models such as the Diamond Model, Kill Chain, and ATT&CK framework.
Historical & Timely Data
Data must be easy to extract and include a historical record for trend analysis. All event and incident activities require specific dates and times, along with standard internal classification and TLP designators.
Source Credibility: The Admiralty Code
Vendor reports and data feeds are treated as raw sources that must be evaluated for credibility and reliability. We mandate the use of the NATO Admiralty Code (or "Admiralty Scoring") to systematically evaluate information. This ensures that every piece of data is weighted according to the reliability of its source and the credibility of the information itself, removing bias and increasing analytical rigor.
Learn more about our CyberIntellipedia knowledgebase →
Essential Intelligence Questions
A comprehensive RFI submission must provide clear and concise answers to the following intelligence requirements:
- The Core Problem
- What is the exact problem or issue, and why is it happening now? Who is the threat actor and what is their intent?
- The "So What?" Factor
- Why do we care? What does this mean for our organization and our clients? What is the impact so far?
- Prognosis & Outlook
- What do we expect to happen next? What is the likely course of action for the adversary?
- Recommendations & Actions
- What supervisory actions were taken? What recommendations were made, which were executed, and what were the results and any unanticipated consequences?
- Organizational Learning
- What opportunities, weaknesses, strengths, and capability gaps (people, process, technology) did this event reveal?
Download the RFI Protocol & Form
Access the complete RFI briefing document and the standardized form to begin submitting high-quality intelligence requests.
Get the RFI Form & Brief