Cyber Intelligence Planner
Develops detailed intelligence plans to satisfy cyber operations requirements. Collaborates with cyber operations planners to identify, validate, and levy requirements for collection and analysis. Participates in targeting selection, validation, synchronization, and execution of cyber actions. Synchronizes intelligence activities to support organization objectives in cyberspace.
Tasks
The concrete work activities defined for this role in the DCWF v5.1 spreadsheet. Core tasks are required for the role; additional tasks are associated but not mandatory.
- T2009 additional Provide input to the analysis, design, development or acquisition of capabilities used for meeting objectives.
- T2043 additional Coordinate for intelligence support to operational planning activities.
- T2045 additional Assess all-source intelligence and recommend targets to support cyber operation objectives.
- T2052 additional Assess target vulnerabilities and/or operational capabilities to determine course of action.
- T2058 additional Assist and advise inter-agency partners in identifying and developing best practices for facilitating operational support to achievement of organization objectives.
- T2064 additional Assist in the development and refinement of priority information requirements.
- T2070 additional Enable synchronization of intelligence support plans across partner organizations as required.
- T2073 additional Provide input to the identification of cyber-related success criteria.
- T2091 additional Collaborate with other team members or partner organizations to develop a diverse program of information materials (e.g., web pages, briefings, print materials).
- T2159 additional Contribute to crisis action planning for cyber operations.
- T2160 additional Contribute to the development of the organization's decision support tools if necessary.
- T2163 additional Incorporate intelligence equities into the overall design of cyber operations plans.
- T2181 additional Coordinate with intelligence planners to ensure collection managers receive information requirements.
- T2185 additional Coordinate with the intelligence planning team to assess capability to satisfy assigned intelligence tasks.
- T2186 additional Coordinate, produce and track intelligence requirements.
- T2187 additional Coordinate, synchronize and draft applicable intelligence sections of cyber operations plans.
- T2192 additional Use intelligence estimates to counter potential target actions.
- T2237 additional Determine indicators (e.g., measures of effectiveness) that are best suited to specific cyber operation objectives.
- T2267 additional Develop and review intelligence guidance for integration into supporting cyber operations planning and execution.
- T2276 additional Develop detailed intelligence support to cyber operations requirements.
- T2310 additional Develop potential courses of action.
- T2327 additional Develop, implement, and recommend changes to appropriate planning procedures and policies.
- T2352 additional Draft cyber intelligence collection and production requirements.
- T2368 additional Ensure that intelligence planning activities are integrated and synchronized with operational planning timelines.
- T2386 additional Evaluate intelligence estimates to support the planning cycle.
- T2392 additional Evaluate the conditions that affect employment of available cyber intelligence capabilities.
- T2425 additional Incorporate intelligence and counterintelligence to support plan development.
- T2435 additional Identify all available partner intelligence capabilities and limitations supporting cyber operations.
- T2442 additional Identify, draft, evaluate, and prioritize relevant intelligence or information requirements.
- T2459A additional Identify cyber intelligence gaps and shortfalls.
- T2484 additional Identify the need, scope, and timeframe for applicable intelligence environment preparation derived production.
- T2509 additional Provide input to or develop courses of action based on threat factors.
- T2528 additional Interpret environment preparations assessments to determine a course of action.
- T2529 additional Issue requests for information.
- T2532 additional Lead and coordinate intelligence support to operational planning.
- T2558 additional Maintain relationships with internal and external partners involved in cyber planning or related areas.
- T2564 additional Maintain situational awareness to determine if changes to the operating environment require review of the plan.
- T2619 additional Provide subject matter expertise to planning teams, coordination groups, and task forces as necessary.
- T2624 additional Conduct long-range, strategic planning efforts with internal and external partners in cyber activities.
- T2702 additional Prepare for and provide subject matter expertise to exercises.
- T2736 additional Provide cyber focused guidance and advice on intelligence support plan inputs.
- T2778 additional Recommend refinement, adaption, termination, and execution of operational plans as appropriate.
- T2806 additional Review and comprehend organizational leadership objectives and guidance for planning.
- T2819 additional Scope the cyber intelligence planning effort.
- T2888 additional Document lessons learned that convey the results of events and/or exercises.
Knowledge, Skills, and Abilities
KSA statements define what a person filling this role knows or can do. "Knowledge" is what they must know, "Skill" is what they can perform, and "Ability" is a durable capacity they bring to the work.
- A3003 ability core Ability to adjust to and operate in a diverse, unpredictable, challenging, and fast-paced work environment.
- A3011 ability core Ability to apply critical reading/thinking skills.
- A3015 ability core Ability to apply approved planning development and staffing processes.
- A3021 ability core Ability to collaborate effectively with others.
- A3022 ability core Ability to communicate complex information, concepts, or ideas in a confident and well-organized manner through verbal, written, and/or visual means.
- A3033 ability core Ability to coordinate cyber operations with other organization functions or support activities.
- A3040 ability core Ability to develop or recommend planning solutions to problems and situations for which no precedent exists.
- A3041 ability core Ability to effectively collaborate via virtual teams.
- A3044 ability core Ability to exercise judgment when policies are not well-defined.
- A3048 ability core Ability to function in a collaborative environment, seeking continuous consultation with other analysts and experts—both internal and external to the organization—in order to leverage analytical and technical expertise.
- A3060 ability core Ability to interpret and understand complex and rapidly evolving concepts.
- A3066 ability core Ability to participate as a member of planning teams, coordination groups, and task forces as necessary.
- A3076 ability core Ability to tailor technical and planning information to a customer’s level of understanding.
- K0264 knowledge core Knowledge of basic physical computer components and architectures, including the functions of various components and peripherals (e.g., CPUs, Network Interface Cards, data storage).
- K1056 knowledge core Knowledge of operations security.
- K2530 knowledge core Knowledge and understanding of operational design.
- K2531 knowledge core Knowledge of organizational planning concepts.
- K3106 knowledge core Knowledge of a wide range of basic communications media concepts and terminology (e.g., computer and telephone networks, satellite, cable, wireless).
- K3107 knowledge core Knowledge of a wide range of concepts associated with websites (e.g., website types, administration, functions, software systems, etc.).
- K3114 knowledge core Knowledge of all forms of intelligence support needs, topics, and focus areas.
- K3117 knowledge core Knowledge of all-source reporting and dissemination procedures.
- K3129 knowledge core Knowledge of attack methods and techniques (DDoS, brute force, spoofing, etc.).
- K3154 knowledge core Knowledge of classification and control markings standards, policies and procedures.
- K3155 knowledge core Knowledge of client organizations, including information needs, objectives, structure, capabilities, etc.
- K3159 knowledge core Knowledge of cyber operations support or enabling processes.
- K3174 knowledge core Knowledge of the intelligence requirements development and request for information processes.
- K3177 knowledge core Knowledge of common computer/network infections (virus, Trojan, etc.) and methods of infection (ports, attachments, etc.).
- K3188 knowledge core Knowledge of computer networking fundamentals (i.e., basic computer components of a network, types of networks, etc.).
- K3194 knowledge core Knowledge of crisis action planning and time sensitive planning procedures.
- K3215 knowledge core Knowledge of cyber actions (i.e. cyber defense, information gathering, environment preparation, cyber attack) principles, capabilities, limitations, and effects.
- K3225 knowledge core Knowledge of data communications terminology (e.g., networking protocols, Ethernet, IP, encryption, optical devices, removable media).
- K3257 knowledge core Knowledge of target and threat organization structures, critical capabilities, and critical vulnerabilities.
- K3264 knowledge core Knowledge of existing, emerging, and long-range issues related to cyber operations strategy, policy, and organization.
- K3274 knowledge core Knowledge of fundamental cyber operations concepts, terminology/lexicon (i.e., environment preparation, cyber attack, cyber defense), principles, capabilities, limitations, and effects.
- K3275 knowledge core Knowledge of fundamental cyber concepts, principles, limitations, and effects.
- K3287 knowledge core Knowledge of how collection requirements and information needs are translated, tracked, and prioritized across the extended enterprise.
- K3311 knowledge core Knowledge of analytical standards and the purpose of intelligence confidence levels.
- K3336 knowledge core Knowledge of intelligence employment requirements (i.e., logistical, communications support, maneuverability, legal restrictions, etc.).
- K3340 knowledge core Knowledge of intelligence requirements tasking systems.
- K3342 knowledge core Knowledge of intelligence support to planning, execution, and assessment.
- K3388 knowledge core Knowledge of crisis action planning for cyber operations.
- K3397 knowledge core Knowledge of intelligence capabilities and limitations.
- K3443 knowledge core Knowledge of PIR approval process.
- K3444 knowledge core Knowledge of planning activity initiation.
- K3445 knowledge core Knowledge of planning timelines adaptive, crisis action, and time-sensitive planning.
- K3463 knowledge core Knowledge of required intelligence planning products associated with cyber operational planning.
- K3489 knowledge core Knowledge of organizational structures and associated intelligence capabilities.
- K3554 knowledge core Knowledge of the critical information requirements and how they're used in planning.
- K3560 knowledge core Knowledge of the production responsibilities and organic analysis and production capabilities.
- K3561 knowledge core Knowledge of the common networking and routing protocols(e.g. TCP/IP), services (e.g., web, mail, DNS), and how they interact to provide network communications.
- K3582 knowledge core Knowledge of the intelligence frameworks, processes, and related systems.
- K3584 knowledge core Knowledge of intelligence preparation of the environment and similar processes.
- K3585 knowledge core Knowledge of accepted organization planning systems.
- K3606 knowledge core Knowledge of the process used to assess the performance and impact of operations.
- K3609 knowledge core Knowledge of the range of cyber operations and their underlying intelligence support needs, topics, and focus areas.
- K3610 knowledge core Knowledge of the relationships between end states, objectives, effects, lines of operation, etc.
- K3611 knowledge core Knowledge of the relationships of operational objectives, intelligence requirements, and intelligence production tasks.
- K3629 knowledge core Knowledge of the various collection disciplines and capabilities.
- K3651 knowledge core Knowledge of what constitutes a “threat” to a network.
- K3659 knowledge core Knowledge of wireless technologies (e.g., cellular, satellite, GSM) to include the basic structure, architecture, and design of modern wireless communications systems.
- S3665 skill core Skill in administrative planning activities, to include preparation of functional and specific support plans, preparing and managing correspondence, and staffing procedures.
- S3681 skill core Skill in applying analytical methods typically employed to support planning and to justify recommended strategies and courses of action.
- S3685 skill core Skill in applying crisis planning procedures.
- S3724 skill core Skill in defining and characterizing all pertinent aspects of the operational environment.
- S3772 skill core Skill in evaluating information for reliability, validity, and relevance.
- S3844 skill core Skill in preparing and presenting briefings.
- S3845 skill core Skill in preparing plans and related correspondence.
- S3879 skill core Skill in reviewing and editing plans.
- S3938 skill core Skill in utilizing feedback in order to improve processes, products, and services.
- S3965 skill core Skill to analyze strategic guidance for issues requiring clarification and/or additional guidance.
- S3966 skill core Skill to anticipate intelligence capability employment requirements.
- S3967 skill core Skill to anticipate key target or threat activities which are likely to prompt a leadership decision.
- S3971 skill core Skill to apply analytical standards to evaluate intelligence products.
- S3976 skill core Skill to apply the process used to assess the performance and impact of cyber operations.
- S3978 skill core Skill to articulate the needs of joint planners to all-source analysts.
- S3979 skill core Skill to articulate intelligence capabilities available to support execution of the plan.
- S3987 skill core Skill to conceptualize the entirety of the intelligence process in the multiple domains and dimensions.
- S3990 skill core Skill to convert intelligence requirements into intelligence production tasks.
- S3992 skill core Skill to coordinate the development of tailored intelligence products.
- S3996 skill core Skill to correlate intelligence priorities to the allocation of intelligence resources/assets.
- S3998 skill core Skill to craft indicators of operational progress/success.
- S4000 skill core Skill to create and maintain up-to-date planning documents and tracking of services/production.
- S4018 skill core Skill to express orally and in writing the relationship between intelligence capability limitations and decision making risk and impacts on the overall operation.
- S4032 skill core Skill to interpret planning guidance to discern level of analytical support required.
- S4045 skill core Skill to orchestrate intelligence planning teams, coordinate collection and production support, and monitor status.
- S4053 skill core Skill to relate intelligence resources/assets to anticipated intelligence requirements.
- S4059 skill core Skill to synchronize planning activities and required intelligence support.
- A3001 ability additional Ability to accurately and completely source all data used in intelligence, assessment and/or planning products.
- A3054 ability additional Ability to identify external partners with common cyber operations interests.
- A3057 ability additional Ability to interpret and apply laws, regulations, policies, and guidance relevant to organization cyber objectives.
- K0052 knowledge additional Knowledge of human-computer interaction principles.
- K3095 knowledge additional Knowledge of internet network addressing (IP addresses, classless inter-domain routing, TCP/UDP port numbering).
- K3098 knowledge additional Knowledge of virtualization products (Vmware, Virtual PC).
- K3205 knowledge additional Knowledge of current computer-based intrusion sets.
- K3211 knowledge additional Knowledge of cyber laws and legal considerations and their effect on cyber planning.
- K3235 knowledge additional Knowledge of deconfliction processes and procedures.
- K3253 knowledge additional Knowledge of encryption algorithms and cyber capabilities/tools (e.g., SSL, PGP).
- K3262 knowledge additional Knowledge of evolving/emerging communications technologies.
- K3271 knowledge additional Knowledge of internal and external partner cyber operations capabilities and tools.
- K3286 knowledge additional Knowledge of host-based security products and how they affect exploitation and vulnerability.
- K3291 knowledge additional Knowledge of how internet applications work (SMTP email, web-based email, chat clients, VOIP).
- K3292 knowledge additional Knowledge of how modern digital and telephony networks impact cyber operations.
- K3293 knowledge additional Knowledge of how modern wireless communications systems impact cyber operations.
- K3326 knowledge additional Knowledge of information security concepts, facilitating technologies and methods.
- K3356 knowledge additional Knowledge of organization policies and planning concepts for partnering with internal and/or external organizations.
- K3358 knowledge additional Knowledge of organizational hierarchy and cyber decision making processes.
- K3374 knowledge additional Knowledge of malware.
- K3391 knowledge additional Knowledge of objectives, situation, operational environment, and the status and disposition of internal and external partner collection capabilities available to support planning.
- K3419 knowledge additional Knowledge of organization or partner exploitation of digital networks.
- K3459 knowledge additional Knowledge of the functions and capabilities of internal teams that emulate threat activities to benefit the organization.
- K3539 knowledge additional Knowledge of telecommunications fundamentals.
- K3543 knowledge additional Knowledge of the basic structure, architecture, and design of modern communication networks.
- K3545 knowledge additional Knowledge of the basics of network security (e.g., encryption, firewalls, authentication, honey pots, perimeter protection).
- K3570 knowledge additional Knowledge of the organizational structure as it pertains to full spectrum cyber operations, including the functions, responsibilities, and interrelationships among distinct internal elements.
- K3571 knowledge additional Knowledge of the organizational planning and staffing process.
- K3572 knowledge additional Knowledge of organization decision support tools and/or methods.
- K3578 knowledge additional Knowledge of the impacts of internal and external partner staffing estimates.
- K3591 knowledge additional Knowledge of organization objectives, leadership priorities, and decision-making risks.
- K3601 knowledge additional Knowledge of the outputs of course of action and exercise analysis.
- K3607 knowledge additional Knowledge of the processes to synchronize operational assessment procedures with the critical information requirement process.
- K3615 knowledge additional Knowledge of the structure and intent of organization specific plans, guidance and authorizations.
- K3616 knowledge additional Knowledge of the structure, architecture, and design of modern digital and telephony networks.
- K3627 knowledge additional Knowledge of cryptologic capabilities, limitations, and contributions to cyber operations.
- K3630 knowledge additional Knowledge of the ways in which targets or threats use the Internet.
- K3638 knowledge additional Knowledge of organization issues, objectives, and operations in cyber as well as regulations and policy directives governing cyber operations.
- K3639 knowledge additional Knowledge of organization cyber operations programs, strategies, and resources.
- S3766 skill additional Skill in documenting and communicating complex technical and programmatic information.
- S3877 skill additional Skill in reviewing and editing intelligence products from various sources for cyber operations.
- S3893 skill additional Skill in tailoring analysis to the necessary levels (e.g., classification and organizational).
- S3946 skill additional Skill in utilizing virtual collaborative workspaces and/or tools (e.g., IWS, VTCs, chat rooms, SharePoint).
- S3964 skill additional Skill to analyze target or threat sources of strength and morale.
- S4023 skill additional Skill to graphically depict decision support materials containing intelligence and partner capability estimates.
- S4041 skill additional Skill to monitor threat effects to partner capabilities and maintain a running estimate.
- S4042 skill additional Skill to monitor target or threat situation and environmental factors.