TINT — Threat Intelligence Assessment and Decision Record

Appendix A – Operational Intake & Control Framework

1. Assessment (Security Analysis)

To be completed by the security analyst to determine relevance, exposure, and potential impact.
Assessment FieldDetails & Findings
-
Asset Exposure Type (Vulnerability)
Exploitability (Vulnerability)
Requires Authentication (Vulnerability)
Patch / Fix Status (Vulnerability)
Source & Date
Select items:
Select items:
Exposure
Threat Level
Select items:
Select items:
Select items:

2. Decision Record (Governance)

To be completed by the CISO or Security Governance Lead to establish organizational posture.
Governance FieldDecision Details
Recommended Response
Priority
Select items:
Select items:
Select items:
Select items:
Select items:
Select items:

3. Action Record (Operational Tracking)

To be completed by operational owners for task tracking, execution, and validation.
Operational FieldAction Tracking Details
Select items:
Target Date
Select items:
Select items:
If applicable — e.g., a CISA KEV remediation due date or other externally mandated deadline, as distinct from the internally-set Target Date above.
Status