The collection operation
Let's consider this idea. The threat intelligence life cycle is put into place to support an organization's ability to make strategic decisions about the security posture of the organization, the capability of a product, or as an actual product. This means that there is a constant and consistent feedback loop from the collection operation through the intelligence life cycle and into the hands of the decision-makers of an organization. Intelligence supports the decision-making process around security posture improvements, product improvement, and even just simply actionable and timely intelligence if your organization provides a threat intelligence product.
With this understanding in place, the collections team and the collection manager should establish an operational reporting cadence that cycles key takeaways from the collection operations upward for validation, evaluation, and strategic reporting during the collection operation and not just...