Zero Trust Engineering — Threat intelligence acquisition and enrichment

securityv1

/01 Views

Capability definition and hierarchyarchimate
Operational activity sequencesecurity
Exception and recovery activity sequencesecurity
Conformant decision branchsecurity
Denied, conditional or degraded branchsecurity
Identity-scoped information exchangec4
Context and decision inputsecurity
Policy authority and evaluationsecurity
Decision distribution and resource mediationsecurity
Enforcement decision evidencesecurity
Policy ownershiparchimate
Security control and protected resourcesecurity
Control and failure risksecurity
Conformance obligationarchimate
Capability assurancearchimate
Resource trust boundarysecurity
Activity-to-capability realizationarchimate
Logical service capability realizationarchimate
Source contractsecurity
Consumer, receipt and acknowledgementsecurity
Idempotent exchange evidencesecurity

/02 About

Visibility and analytics engineering reference for threat intelligence acquisition and enrichment, including policy, logical interfaces, recovery and assurance.

Purpose: Threat intelligence acquisition and enrichment. Domain: Visibility and analytics. Family: exchange. Scenario trigger: Consume new actionable threat indicator or report. Input assurance: Source credibility, provenance, relevance and expiration. Evaluation: Assess threat applicability to enterprise assets and behaviors. Governing policy: Threat intelligence sharing, scoring and retention policy. Resource-side obligation: Publish validated indicators with confidence and expiry. Protected concern: Enterprise security detection enrichment service. Logical interface: Indicator type issuer confidence valid interval affected asset and finding. Evidence: Indicator source attribution matching and lifecycle evidence. Failure: Poisoned indicator or irrelevant malicious attribution. Required recovery: Quarantine untrusted intelligence and revert affected matches. Architectural invariant: External intelligence cannot be promoted to truth without corroboration Adoption: replace reference roles with concrete owner-controlled services. Specify exact provider/consumer identities, schema fields and classifications, signal provenance and freshness, idempotency, authorization lifetime, timeout/retry limits, observation and tamper evidence. A denied or failed operation must not silently become a permitted one. Scope: original vendor-neutral, implementation-agnostic technical reference model. Illustrative logical components and behaviors are neither a deployed system nor evidence of regulatory compliance. Package identities remain stable within the package; cross-package semantic reconciliation requires separate explicit registry support.

Curated · other · unspecified · Published by Lattix · 29 elements · 34 relationships · validated on publish

/03 Contents

Capability
Visibility and analytics, Threat intelligence acquisition and enrichment
Role
Visibility and analytics owner
Business Actor
Interoperating security service
Activity
Consume new actionable threat indicator or report, Verify: Source credibility, provenance, relevance and expiration, Assess: Assess threat applicability to enterprise assets and behaviors, Execute: Publish validated indicators with confidence and expiry, Exception: Poisoned indicator or irrelevant malicious attribution, Recover: Quarantine untrusted intelligence and revert affected matches
Application Component
Source credibility, provenance, relevance and expiration, Assess threat applicability to enterprise assets and behaviors, Publish validated indicators with confidence and expiry, Authenticated exchange producer, Authorized exchange consumer, Receipt and replay reconciliation
Application
Enterprise security detection enrichment service
Policy
Threat intelligence sharing, scoring and retention policy
API
Threat intelligence acquisition and enrichment logical interface
Message/Event Schema
Indicator type issuer confidence valid interval affected asset and finding, Exchange acknowledgement and receipt
Data Store
Indicator source attribution matching and lifecycle evidence
Control
Threat intelligence acquisition and enrichment enforcement assurance
Risk
Poisoned indicator or irrelevant malicious attribution risk
Requirement
External intelligence cannot be promoted to truth without corroboration
Measure
Threat intelligence acquisition and enrichment assurance completeness
Trust Boundary
Threat intelligence acquisition and enrichment authority boundary
State
Authorized information transfer, Exchange blocked or deferred