Threat intelligence
Purpose
Build awareness of the organisation's threat environment so suitable mitigations can be chosen.
How to meet this control
In short: Collect and analyse information about threats to produce actionable threat intelligence.
- Step 01Subscribe to threat feeds appropriate to your size (ACSC alerts, vendor advisories, MITRE ATT&CK mappings, ISAC bulletins) and document the chosen sources
- Step 02Assign an owner to triage incoming intelligence weekly and assess relevance to your technology stack and sector
- Step 03Translate relevant intelligence into concrete actions such as new detection rules, firewall blocks or priority patches
- Step 04Distribute a short, plain-language threat summary to technical teams and, where relevant, to staff awareness channels
- Step 05Feed strategic threat trends into the periodic risk assessment so the risk register reflects the current threat picture
Tip: A feed subscription (e.g. a national CERT) is a solid start, but the control expects analysis and use: record how you assess each alert for relevance to your stack, and what you did about it, such as a patch, a firewall block or a risk register update.
What ISO 27002 says to cover
Reference points from the ISO/IEC 27002:2022 guidance for this control. Use them to check the steps above cover everything relevant to you.
- ›Collect and analyse information on existing and emerging threats to turn it into usable intelligence
- ›Cover strategic, tactical and operational layers of threat intelligence
- ›Make sure intelligence is relevant, insightful, contextual and actionable
- ›Set clear objectives and identify and vet trustworthy internal and external sources
- ›Process and analyse collected data so it is meaningful to the organisation
- ›Share the resulting intelligence with relevant people in an understandable format
- ›Feed intelligence into risk management and technical controls like firewalls and intrusion detection
- ›Exchange threat intelligence with other organisations on a mutual basis to improve coverage
Audit evidence to keep
- - List of subscribed threat intelligence sources and their assigned owner
- - Records of threat intelligence assessed and the relevance determination made
- - Evidence that intelligence drove action (updated detection rules, blocklists, patch priorities)
- - Risk register entries or updates traceable to threat intelligence
Common mistakes
- - Writing a policy but not operating the process
- - Keeping evidence in personal folders where auditors cannot trace it
- - Letting exceptions stay open with no owner or expiry date
Owner, cadence, and proof
Assign one accountable owner for A.5.7. Review this control at least annually, after related incidents, and whenever the underlying process, supplier, system, office, or legal obligation changes. The control is audit-ready when the owner can show the policy or procedure, the latest operating evidence, the latest review, and any open exceptions with due dates.
Policy templates for this control
Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.