Threat intelligence is not just raw data — it is a structured process. The Intelligence Lifecycle has six phases: Direction (defining requirements), Collection (gathering data), Processing (normalizing data), Analysis (producing actionable insight), Dissemination (sharing intelligence), and Feedback (evaluating usefulness).
At the architect level, you must design data pipelines that continuously feed each phase. Splunk ingests raw indicator feeds (Collection), CIM normalizes them (Processing), and correlation searches operationalize them (Analysis). The goal is to reduce the time between indicator discovery and operationalization.