The ultimate audit guide to ISO 27001 Annex A 5.7 Threat intelligence – new
Table of contents
- 1. Threat Intelligence Process Formalisation Verified
- 2. Identification of Diverse Intelligence Sources Confirmed
- 3. Tactical Intelligence Implementation (IoCs) Validated
- 4. Operational Intelligence Application (TTPs) Verified
- 5. Strategic Intelligence for Executive Decision-Making Confirmed
- 6. Intelligence Analysis and Relevance Vetting Validated
- 7. Integration with Risk Management Framework Verified
- 8. Actionable Output and Mitigation Records Present
- 9. Internal Threat Data Contribution Confirmed
- 10. Intelligence Dissemination and Roles Verified
1. Threat Intelligence Process Formalisation Verified
Verification Criteria: A documented process or procedure exists that defines how threat intelligence is collected, processed, and disseminated across the organisation.
Required Evidence: Approved Threat Intelligence Policy or Standard Operating Procedure (SOP) detailing the intelligence lifecycle.
Pass/Fail Test: If the organisation cannot produce a documented methodology for handling threat data, mark as Non-Compliant.
2. Identification of Diverse Intelligence Sources Confirmed
Verification Criteria: The organisation has identified and formalised both internal and external sources of threat data, encompassing tactical, operational, and strategic levels.
Required Evidence: A register of intelligence sources, including subscription records to ISACs, commercial feeds, or government alerts (e.g., NCSC).
Pass/Fail Test: If the organisation relies solely on a single, generic news feed without technical or sector-specific sources, mark as Non-Compliant.
3. Tactical Intelligence Implementation (IoCs) Validated
Verification Criteria: Evidence exists that Indicators of Compromise (IoCs) such as malicious IPs, file hashes, and URLs are actively ingested and used for detection.
Required Evidence: Configuration logs from SIEM, EDR, or Firewall showing the automated or manual ingestion of threat feeds.
Pass/Fail Test: If IoCs are collected but not actively applied to blocking or monitoring tools, mark as Non-Compliant.
4. Operational Intelligence Application (TTPs) Verified
Verification Criteria: The organisation demonstrates the use of operational intelligence to understand the Tactics, Techniques, and Procedures (TTPs) of relevant threat actors.
Required Evidence: Internal threat reports or SOC documentation that maps observed behaviours to frameworks like MITRE ATT&CK.
Pass/Fail Test: If the threat intelligence function cannot describe the TTPs of the top three threat actors relevant to their sector, mark as Non-Compliant.
5. Strategic Intelligence for Executive Decision-Making Confirmed
Verification Criteria: High-level threat landscape trends are communicated to senior management to inform long-term security strategy and investment.
Required Evidence: Board-level security reports or Management Review Meeting (MRM) minutes showing discussions on evolving global threat trends.
Pass/Fail Test: If threat intelligence is treated purely as a technical “IT issue” with no executive-level visibility or strategic reporting, mark as Non-Compliant.
6. Intelligence Analysis and Relevance Vetting Validated
Verification Criteria: Collected data is vetted for relevance to the organisation’s specific technical environment and business context before action is taken.
Required Evidence: Analysis logs or ticket comments within a Threat Intelligence Platform (TIP) or Incident Management tool showing the dismissal of irrelevant alerts.
Pass/Fail Test: If every raw alert from a feed is treated as a high priority without context-based analysis, mark as Non-Compliant.
7. Integration with Risk Management Framework Verified
Verification Criteria: Insights gained from threat intelligence are used to update the Risk Register and adjust the likelihood of specific security scenarios.
Required Evidence: Updated Risk Assessment records citing specific threat intelligence reports as the justification for changed risk scores.
Pass/Fail Test: If the Risk Register is static and does not reflect changes in the real-world threat landscape, mark as Non-Compliant.
8. Actionable Output and Mitigation Records Present
Verification Criteria: The threat intelligence process produces tangible outputs that lead to defensive improvements or vulnerability patching prioritisation.
Required Evidence: Change requests, patching logs, or firewall rule updates that specifically reference a threat advisory.
Pass/Fail Test: If there is no audit trail showing a security control was modified in response to an intelligence alert, mark as Non-Compliant.
9. Internal Threat Data Contribution Confirmed
Verification Criteria: The organisation uses its own internal incident data and system logs as a source of “Internal Threat Intelligence” to identify patterns.
Required Evidence: Post-Incident Reviews (PIRs) or trend analysis reports derived from internal ticket data over the last 12 months.
Pass/Fail Test: If the organisation only looks at external threats and ignores patterns within their own historical incident data, mark as Non-Compliant.
10. Intelligence Dissemination and Roles Verified
Verification Criteria: Responsibilities for threat intelligence are assigned to specific roles, and information is shared with those who need it in a timely manner.
Required Evidence: Job descriptions or RACI matrix naming TI owners; evidence of internal alerts sent to System Administrators or Developers.
Pass/Fail Test: If critical threat information is received by the security team but not communicated to the technical teams responsible for remediation, mark as Non-Compliant.