Source Evaluation

Source Evaluation: Assessment of a source’s reliability, relevance, timeliness, and potential bias. Effectiveness depends on reliable data, defined ownership, measurable criteria, and regular tuning.

How it works and where it fits

Source Evaluation structures knowledge about potential adversaries, their objectives, capabilities, infrastructure, and observed behavior. Individual indicators are short-lived and easy to change, while behavioral patterns and technical relationships often have greater analytical value. Reporting should distinguish observed facts, assessments, and assumptions.

Practical security relevance

Practical use depends on source quality, timeliness, and relevance to the organization’s own attack surface. Information is prioritized, correlated with internal data, and converted into searches, detections, or safeguards. Investigation feedback continuously improves the assessment. Confidentiality and permitted sharing are as important as technical exchange formats.

  • Cyber Threat IntelligenceCyber Threat IntelligenceProcessed information regarding threat actors, tactics, indicators, and risks.: Processed information regarding threat actors, tactics, indicators, and risks.
  • Open Source IntelligenceOpen Source IntelligenceGathering and analyzing publicly available information for security assessments.: Gathering and analyzing publicly available information for security assessments.
  • Data SourceData SourceA system, sensor, log, or repository that supplies data for security analysis and decisions.: A system, sensor, log, or repository that supplies data for security analysis and decisions.
  • Information SharingInformation SharingThe structured distribution of security information to people and systems that can act on it.: The structured distribution of security information to people and systems that can act on it.