A.5.7New in 2022A.5 Organizational controls

Threat intelligence

A.5EVIDENCEA.6EVIDENCEA.7EVIDENCEA.8EVIDENCECONTROL MAPA.5.7 Evidence MapPOLICY / CONTROL / EVIDENCE / REVIEW

Purpose

Build awareness of the organisation's threat environment so suitable mitigations can be chosen.

How to meet this control

In short: Collect and analyse information about threats to produce actionable threat intelligence.

  1. Step 01Subscribe to threat feeds appropriate to your size (ACSC alerts, vendor advisories, MITRE ATT&CK mappings, ISAC bulletins) and document the chosen sources
  2. Step 02Assign an owner to triage incoming intelligence weekly and assess relevance to your technology stack and sector
  3. Step 03Translate relevant intelligence into concrete actions such as new detection rules, firewall blocks or priority patches
  4. Step 04Distribute a short, plain-language threat summary to technical teams and, where relevant, to staff awareness channels
  5. Step 05Feed strategic threat trends into the periodic risk assessment so the risk register reflects the current threat picture

Tip: A feed subscription (e.g. a national CERT) is a solid start, but the control expects analysis and use: record how you assess each alert for relevance to your stack, and what you did about it, such as a patch, a firewall block or a risk register update.

What ISO 27002 says to cover

Reference points from the ISO/IEC 27002:2022 guidance for this control. Use them to check the steps above cover everything relevant to you.

  • ›Collect and analyse information on existing and emerging threats to turn it into usable intelligence
  • ›Cover strategic, tactical and operational layers of threat intelligence
  • ›Make sure intelligence is relevant, insightful, contextual and actionable
  • ›Set clear objectives and identify and vet trustworthy internal and external sources
  • ›Process and analyse collected data so it is meaningful to the organisation
  • ›Share the resulting intelligence with relevant people in an understandable format
  • ›Feed intelligence into risk management and technical controls like firewalls and intrusion detection
  • ›Exchange threat intelligence with other organisations on a mutual basis to improve coverage

Audit evidence to keep

  • - List of subscribed threat intelligence sources and their assigned owner
  • - Records of threat intelligence assessed and the relevance determination made
  • - Evidence that intelligence drove action (updated detection rules, blocklists, patch priorities)
  • - Risk register entries or updates traceable to threat intelligence

Common mistakes

  • - Writing a policy but not operating the process
  • - Keeping evidence in personal folders where auditors cannot trace it
  • - Letting exceptions stay open with no owner or expiry date

Owner, cadence, and proof

Assign one accountable owner for A.5.7. Review this control at least annually, after related incidents, and whenever the underlying process, supplier, system, office, or legal obligation changes. The control is audit-ready when the owner can show the policy or procedure, the latest operating evidence, the latest review, and any open exceptions with due dates.

Policy templates for this control

Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.

Open the control-to-policy map
Back to all organizational controls or see the requirements (clauses 4 to 10). To run this control with automation, read how AI manages controls.