Four levels
Strategic intelligence describes trends and threat actors for management decisions. Operational intelligence covers specific campaigns, such as a group targeting a sector. Tactical intelligence describes attacker techniques, usually mapped to the MITRE ATT&CK framework. Technical intelligence is the raw data, called indicators of compromise: malicious IP addresses, domains and file hashes.
Where it comes from
Sources include commercial feeds, security vendors, open source research, national CERTs such as INCIBE-CERT and CCN-CERT, sector sharing groups and the annual threat landscape reports from ENISA. Information that is not relevant to the business, or that nobody acts on, adds noise rather than value.
How it is used
Feeds of indicators are loaded into the SIEM, EDR and firewalls to block or alert on known threats. Tactical intelligence helps the SOC write detections for the techniques attackers actually use. News of an actively exploited zero day tells the team what to patch first.
Where it shows up in compliance
Threat intelligence became a control in ISO 27001:2022 (Annex A 5.7). NIS2 encourages information sharing between entities, and DORA includes threat information sharing as one of its five pillars.




