Skip to main content

Source Reliability

Purpose

Provide a practical model for rating source reliability and information credibility without pretending the rating is absolute truth.

Practitioner-Level Explanation

Source reliability describes the historic trustworthiness, access, and discipline of the source. Information credibility describes how believable a specific claim is after considering corroboration, detail, consistency, and proximity to evidence. A strong CTI product tracks both.

The model in use is the Admiralty Code (NATO-style source evaluation), sometimes called the Admiralty System or the STANAG 2511 model. It is also codified in the MISP admiral taxonomy and widely used in law enforcement, military intelligence, and commercial CTI.

The notation is not mathematical. It is a review prompt that forces the analyst to explain why a claim deserves the weight assigned to it. Pair this with evidence labels for each claim and confidence language in the finished product.

Source Reliability: A through F

CodeLabelMeaning
AReliableNo doubt about authenticity, trustworthiness, or competence. History of reliability.
BUsually reliableMinor doubts. Most information has been correct in past assessments.
CFairly reliableSignificant doubts. Has provided valid information in the past but also erroneous.
DNot usually reliableSignificant doubts. More often proved wrong or inconsistent than right.
EUnreliableLacking in authenticity, trustworthiness, and competence; history of invalid information.
FReliability cannot be judgedNo basis for evaluating the source's reliability. New source or insufficient history.

Guidance:

  • Government advisories with attributed, publicly accountable authors typically qualify for A or B.
  • Established commercial CTI vendors with consistent methodology typically qualify for B or C.
  • Anonymous social media accounts, unverified personas, and first-use sources typically qualify for F until track record exists.
  • Source reliability changes over time. Reassess when new evidence about the source appears.

Source Reliability A–F — Admiralty Code Scale

Information Credibility: 1 through 6

CodeLabelMeaning
1ConfirmedConfirmed by other independent sources; consistent with established facts and behavior.
2Probably trueNot confirmed, but consistent with other reporting and past behavior of the actor or sector.
3Possibly trueNot confirmed; not inconsistent with other reporting. Basis exists for the information.
4DoubtfulNot confirmed; inconsistent with other reporting or with known patterns.
5ImprobableNot confirmed; contradicts other reliable reporting; inconsistent with logic and known facts.
6Cannot be judgedNo basis for evaluating whether the information is true or false.

Guidance:

  • Corroboration from independent primary sources is required for a rating of 1. Shared sourcing from the same secondary summary does not count as independent corroboration.
  • A claim rated 2 or 3 may still be operationally important. Low credibility rating does not mean ignore; it means collect more evidence before acting.
  • A claim rated 4 or 5 should not drive defensive action without explicit risk acceptance.

Information Credibility 1–6 — Admiralty Code Scale

Combined Notation and Examples

NotationSourceClaimMeaning
A1Government CISA advisory with documented forensicsSpecific CVE exploited in named campaignReliable source, confirmed by independent telemetry
A2Government advisoryActor uses phishing for initial accessReliable source, consistent with prior reporting but not independently confirmed with telemetry
B3Established vendor CTI reportSpecific tool variant observed in clusterUsually reliable source, possibly true but single-vendor reporting
C4Media summary of vendor blogAttribution to a named nation-stateFairly reliable intermediary; claim is doubtful because secondary summary with no forensics
F6Anonymous Telegram personaClaim of responsibility for an attackNew or unverified source; cannot judge claim truth

Source Reliability — Combined Notation and Examples

Common Mistakes

  • Rating a source once and never revisiting it.
  • Confusing source reputation with claim correctness. An A-rated source can report a 5-credibility claim.
  • Treating a vendor blog, government advisory, news article, and persona claim as equal.
  • Using A-F/1-6 notation without a written confidence reason.
  • Treating a secondary summary as independent corroboration.

Warning: Ratings Are Review Prompts, Not Mathematical Truth

An A-rated source can make a weak claim. A weak source can report something that later proves true. The Admiralty rating system is a structured way to force the analyst to explain the basis for the claim weight. It does not remove the analyst's judgment responsibility. Do not use ratings to automate trust decisions.

Practical Workflow

  1. Identify the source type and publisher.
  2. Record publication date, access date, and URL.
  3. Rate source reliability (A-F) based on track record, access, and accountability.
  4. Rate information credibility (1-6) for each claim, not only for the source overall.
  5. Record what corroborates, contradicts, or is missing.
  6. Revisit ratings when new evidence about the source or the claim appears.

Source Reliability — Practical Workflow

Example / Mini Case

A government advisory states that an actor exploited a specific appliance vulnerability. The source rates A because it is a primary government source with documented accountability and consistent past accuracy. The specific claim rates 2 rather than 1 because the advisory describes the technique but does not provide raw telemetry or forensic artifact details for independent verification. A commercial vendor blog summarizing that advisory may rate C or B depending on track record, and the claim rates no higher than 3 in the vendor summary because the advisory is now the primary source, not the blog. The blog should cite the advisory; if it does not, rate the claim 4.

Analyst Checklist

  • Is source reliability rated separately from information credibility?
  • Is the rating claim-specific, not only source-level?
  • Are publication and access dates recorded?
  • Are contradictions and corroboration visible?
  • Would a reviewer understand why the rating was assigned without asking the analyst?
  • Has the source been reassessed if new evidence about it appeared?

Output Artifact

Source ID:
Publisher:
Title:
URL:
Publication Date:
Accessed Date:
Source Type:
Source Reliability: [A-F] [Label]
Information Credibility: [1-6] [Label]
Rating Reason:
Corroboration:
Contradiction or Gap:
Downstream Use:

References