CS0-004 · Security Operations · Updated July 26, 2026
Rating Threat Intelligence: Timeliness, Relevancy, Accuracy, and the Admiralty System
Threat intelligence is only as good as your confidence in it, and analysts grade that confidence along three core qualities: timeliness (did it arrive while it could still change a decision), relevancy (does it apply to your environment), and accuracy (is it factually correct). To make those judgments repeatable, many teams use the Admiralty system, also called the NATO rating system, which assigns a letter (A–F) for source reliability and a number (1–6) for information credibility, combining them into a two-character grade such as B2. Intelligence that fails any one of the three qualities loses operational value even if the other two are excellent.
The three qualities that determine intelligence value
Cyber threat intelligence (CTI) is evaluated before it is acted on. A Security Operations Center (SOC) cannot afford to task hunters, tune detections, or block indicators based on feeds it has not graded. Three attributes drive the grade.
Timeliness measures whether the intelligence arrived while it was still actionable. Attacker infrastructure has a short shelf life: domains are abandoned, command-and-control (C2) servers rotate, and phishing campaigns wrap up in days or weeks. If a feed delivers indicators for a campaign whose infrastructure was dismantled months earlier, the indicators may be perfectly accurate and squarely aimed at your industry — but they can no longer prevent anything. Timeliness is the quality that decays fastest, which is why indicator-heavy tactical intelligence ages worse than strategic reporting about actor motivations.
Relevancy measures whether the intelligence applies to your organization: your technology stack, your industry, your geography, your threat model. A prompt, well-sourced report about attacks against a brand of industrial programmable logic controller (PLC) is worthless to an organization that owns none of that hardware. Relevancy failures are common with broad commercial feeds, and they carry a hidden cost — every irrelevant indicator loaded into a Security Information and Event Management (SIEM) platform consumes correlation cycles and analyst attention.
Accuracy measures whether the intelligence is factually correct right now. Accuracy failures often come from stale attribution: an IP address flagged as hosting ransomware may have been reassigned to an innocent cloud tenant before the report was even published. Acting on inaccurate intelligence produces false positives at best; at worst it blocks legitimate business traffic or triggers an incident response against a bystander. Accuracy is verified by cross-checking claims against independent sources and your own telemetry.
These three qualities interact multiplicatively, not additively. When comparing two reports about the same suspected campaign, the report that is fresh, verified against your own data, and applicable to software you actually run should be weighted far above one that is old, unverified, anonymous, and aimed at products you do not use — even before you consider the sources’ track records.
The Admiralty (NATO) rating system
The Admiralty system separates two questions that analysts often blur together: how much do I trust the source? and how believable is this specific claim? A historically excellent source can pass along a dubious rumor, and an unproven source can report something you can independently verify. Rating the two dimensions separately keeps each judgment honest — nowhere more so than with HUMINT from dark web sources, where deception is the baseline risk.
| Source reliability (letter) | Meaning | Information credibility (number) | Meaning |
|---|---|---|---|
| A | Completely reliable | 1 | Confirmed by other sources |
| B | Usually reliable | 2 | Probably true |
| C | Fairly reliable | 3 | Possibly true |
| D | Not usually reliable | 4 | Doubtful |
| E | Unreliable | 5 | Improbable |
| F | Reliability cannot be judged | 6 | Truth cannot be judged |
The letter reflects the source’s track record — how often its past reporting proved correct. The number reflects the specific item of information — how well this particular claim fits known facts and whether anything corroborates it. Combining the two produces a compact composite grade: a “usually reliable” source reporting “probably true” information yields B2, a strong rating that most teams treat as actionable with normal review. An F6 is not “false” — it means you simply cannot judge either dimension yet, which is itself useful to record.
Corroboration: how confidence moves
Confidence is not static; it moves as evidence arrives. The single most powerful driver is independent corroboration. If a fairly reliable source (C) reports an indicator with nothing backing it, and then a usually reliable source (B) independently reports the same indicator through unrelated collection, overall confidence in that indicator should increase — two unconnected observers seeing the same thing is far less likely to be coincidence or error. The key word is independent: two feeds that both repackage the same upstream report do not corroborate each other; they are one source wearing two hats.
The reverse situation — a single uncorroborated source with a disputed track record — is where discipline matters most. Suppose one analyst grades a source D (not usually reliable) because of past inaccuracies while another points out the same source correctly called the last two campaigns’ initial access vectors, and the indicator in question maps to a monitored high-value asset. The defensible move is not to argue the letter grade to a standstill or to block on a single shaky source. It is to record the low-confidence rating honestly, and simultaneously seek independent corroboration — increase monitoring on the affected asset, query internal telemetry for matches, and check whether any other source has seen the indicator. Confidence ratings drive proportional responses: low confidence plus high potential impact justifies cheap, reversible actions (watch, hunt, verify) rather than expensive or disruptive ones (block, escalate, declare an incident).
This grading discipline sits inside the broader threat intelligence lifecycle, in the analysis phase — after collection, before dissemination. Feeds that repeatedly earn poor grades should also feed back into collection planning: source quality is itself intelligence.
How the CS0-003 exam tests this
- A scenario describes intelligence that is correct and applicable but arrives long after the attacker infrastructure is gone, and asks which quality is deficient — the answer pattern keys on timeliness, and distractors will name accuracy or relevancy.
- A scenario describes prompt, accurate reporting about technology the organization does not own and asks which quality is lowest — testing that you separate relevancy from the other two.
- A question gives a source-reliability letter and an information-credibility number and asks what combining them produces — expect to assemble a composite grade like B2 and know which dimension each character represents.
- A scenario presents two sources independently reporting the same indicator, or two analysts disputing a single source’s grade, and asks how confidence should change or what the next step is — the exam rewards raising confidence on independent corroboration and seeking corroboration rather than acting unilaterally on a contested single source.
Confidence-rating questions are Security Operations territory — the full CS0-003 study guide maps all four domains and the exam format. Composite grades like B2 need to be assembled quickly on exam day, so drill them with practice questions until the letter-number split is reflexive.
Quick reference
- Timeliness, relevancy, and accuracy are the three qualities that determine whether intelligence is actionable; failing any one destroys operational value.
- Timeliness decays fastest — tactical indicators (IPs, domains, hashes) go stale as attacker infrastructure rotates.
- Relevancy is judged against your stack and industry; accurate, fresh intel about products you do not run is low-value to you.
- Accuracy failures include stale attribution, such as flagged IPs already reassigned to innocent parties.
- Admiralty/NATO ratings: letters A–F grade source reliability (track record); numbers 1–6 grade information credibility (this specific claim).
- B2 = usually reliable source + probably true information; F6 = neither dimension can be judged yet.
- Independent corroboration from an unrelated source raises confidence; repackaged copies of the same upstream report do not.
- Low confidence + high-value asset = cheap reversible actions (monitor, hunt, verify), not disruptive ones (block, escalate).