Skip to main content

A07 — Full CTI Cycle (Gov): NDSA CTI Program

Mode: Full Cycle · Org: NDSA · PROJ-2025-007

Scenario

It is January 2026. NDSA has survived the biometric breach (A05), launched GovID 2.0 (A06), and received an INCD remediation directive: build a formal CTI program within 6 months. The CISO has ₪8.5M/year and a Knesset committee watching. Build it.

Your entry point: 5 existing SIEM rules, 15 detection backlog items, an informal CERT-IL relationship (no MOU), an empty MISP instance, and an INCD liaison who is simultaneously your primary intelligence source and your compliance auditor.

Organizational Starting Point

CapabilityHaveDon't Have
Detection rules5 Elastic rules (A05 response)Formal PIR framework
Threat reportsA05 post-incident assessment (1 document)Collection plan
CollectionINCD embedded liaison (Friedman)Intelligence production process
SharingInformal CERT-IL relationshipCERT-IL MOU; ITA MOU; ministry sharing agreements
ToolsMISP (empty); Elastic SIEMAny structured CTI workflow

The INCD Dual Role Problem

Lt. Col. Friedman is simultaneously:

  • NDSA's primary source for classified threat intelligence
  • INCD's compliance auditor for NDSA's remediation directive
  • A person with professional interest in NDSA not having another publicly embarrassing breach

This creates a structural tension: the CTI program Rotenberg builds will be audited by the person who controls access to the intelligence that program depends on. Every PIR, collection plan decision, and gap disclosure must be designed with this asymmetry in mind.

Stakeholder Complexity

StakeholderClassification TierIntelligence NeedSharing Constraint
DG Dr. ShamirUnclassified + SecretStrategic threat pictureCan receive sanitized products
CISO Col. NativTop SecretOperational threat-to-control mappingFull access
GovID 2.0 Ops (Shapiro)UnclassifiedGovID-specific threats; indicator tuningNo classification access
INCDTLP:RED via FriedmanNDSA feeds intelligence BACK to INCDBidirectional; Friedman controls the pipe
CERT-ILTLP:AMBER (via formal MOU)Sector threat sharing; collective defenseMOU required — not yet signed
Israel Tax AuthorityTLP:AMBER (proposed MOU)Same HavayaIT contractor riskNo MOU yet
Knesset Interior CommitteeUnclassified onlyBreach post-mortems; systemic riskPublic testimony

PIR Framework

The 6-month INCD remediation directive mandates:

  • PIR-driven collection plan
  • Quarterly intelligence products
  • Formal sharing agreements with CERT-IL + ≥2 other government agencies
PIRQuestionStakeholderRegulatory Driver
PIR-G7-001Which threat actors target Israeli government digital identity infrastructure and citizen data?CISO, INCDINCD-CID Art. 9(2)
PIR-G7-002Which contractor supply chain attack patterns are active against Israeli government agencies?CISO, IRINCD-CID Art. 21(2)(d)
PIR-G7-003Which CVEs in GovID 2.0, VRID, and NDSA infrastructure are actively exploited?IR, SOC
PIR-G7-004What TTPs are relevant to GovID 2.0's biometric API and vendor access patterns?Detection EngineeringINCD-CID Art. 21(2)(e)
PIR-G7-005What are peer government agency incidents in Israel and comparable democracies?DG, Legal, INCDINCD remediation directive

6-Month Implementation Milestones

MilestoneTargetDependenciesStatus at Assignment Start
M1PIR framework approved by CISOStakeholder interviewsNot started
M2CERT-IL MOU signedLegal + CISO approval9-month informal relationship; no MOU
M3ITA MOU signedLegal; ITA agreementNo MOU
M4MISP configured with 3 quality feedsMaya Dvir onboards Week 6MISP empty
M5First quarterly intelligence product publishedM1 completeNone produced
M6INCD remediation directive compliance milestoneAll milestonesNot started

Assignment Deliverables

  1. CTI Programme Charter — INCD remediation directive compliance; 6-month target state
  2. Stakeholder Map — classification tiers; INCD dual role tension documented
  3. PIR/SIR Framework — 5 PIRs; 2–3 SIRs each; government-specific constraints
  4. Collection Plan — classified vs. unclassified; Friedman asymmetry addressed
  5. Source Evaluation Matrix — Admiralty Scale; INCD/CERT-IL classified sources rated
  6. CERT-IL MOU draft — sharing protocol; TLP:AMBER scope; reciprocal obligations
  7. ITA MOU draft — HavayaIT contractor intelligence sharing; same vendor risk
  8. Quarterly Threat Actor Assessment (first issue)
  9. Tactical Intelligence Brief (for SOC / Detection Engineering)
  10. Metrics Framework — INCD remediation directive compliance evidence
  11. 90-day roadmap — Maya Dvir onboarding (Week 6) accounted for; Itai Ben-Levi (Week 10)
  12. 6-month program review deliverable — evidence package for INCD compliance milestone

Key Learning Objectives

  • Build a CTI program inside government constraints — classification tiers, change control, Knesset oversight
  • Design a collection plan that works when your primary intelligence source is also your compliance auditor
  • Navigate MOUs as intelligence infrastructure — CERT-IL MOU is not a formality; it enables TLP:AMBER sharing
  • Develop PIRs for a government identity platform that differ substantially from commercial CTI questions
  • Produce classified and unclassified versions of the same intelligence product for different audience tiers
  • Account for team build time (new hires starting weeks 6 and 10) in the program launch timeline