admiralty-system
Admiralty System for CTI
The Admiralty System (NATO AJP-2.1) is the gold standard for assessing intelligence. The British Royal Navy developed it in the early 20th century. NATO intelligence communities now use it worldwide, and it is gaining ground in cyber threat intelligence.
It rates two things, separately:
- Source Reliability (A to F): how trustworthy the origin is
- Information Credibility (1 to 6): how trustworthy the data is, independent of the source
The combined output is an alphanumeric code such as A1, B3, F6.
Core rule: assess source and information SEPARATELY
This is the single most common mistake. A source who is reliable on malware analysis is not automatically reliable on geopolitics. A piece of information can be true from a sketchy source, or false from a usually reliable one. Always rate them independently, never in lockstep.
Second common mistake: confusing "two vendors reported it" with two independent sources. If both vendors pull from the same original dataset (the same breach forum post, the same scan, the same leak), that is ONE source. Independent corroboration means independent collection.