ISO27001:2022 – A5.7
Threat intelligence
Fastback your journey to ISO27001 and buy our Policies to get started TODAY!
Take a look at our “ISO 27001:2022 Policy Pack” and when coupled with our book you’ll have everything you need to succeed in achieving ISO 27001 certification!
Introduction
We often say that ISO27001 is all about risk management. In fact, it’s a risk-based management system. While Risk Management is discussed elsewhere, ISO 27001 – A5.7 focuses on what risk really is — threats that exploit a vulnerability. That’s why this new control is so important: it emphasises the need to develop threat intelligence.
What does ISO 27001 – A5.7 require?
The standard states that:
“Information relating to information security threats shall be collected and analysed to produce threat intelligence.” (A5.7 Threat Intelligence)
This means you must collect and analyse information to understand where your risks actually exist.
Why is this required?
You can’t fully understand risks unless you understand both your vulnerabilities (weaknesses) and the threats (what or who might cause harm).
Without knowing where threats are coming from, you can’t truly control your risks. Think of it this way: if you’re travelling to the South Pole, you’d prepare for weather — the obvious threat — but if you were worried about polar bears, you’d be misinformed. Polar bears live in the North Pole, not the South. So without the right threat intelligence, you’d be preparing for the wrong risks.
Threat intelligence helps you prepare for the real risks you may face.
What the auditor is looking for
This control pushes your organisation to collect threat information from multiple sources and analyse its relevance.
You should break your threat intelligence into three levels:
- Strategic
- Tactical
- Operational
Strategic Threats
These include macro-level risks like geopolitical tensions, political changes, environmental shifts (e.g., climate change), and financial instability. Consider whether such external events could affect your organisation, even indirectly.
Tactical Threats
What tactics are threat actors currently using? Are there new phishing techniques like “Qhishing” (QR code phishing)? Are certain platforms being newly targeted (e.g., Linux, Apple, mobile devices)? Your threat intelligence should help answer these questions.
Operational Threats
Are there increased attacks on your firewall? Is one department experiencing more errors or breaches than others? How are these issues tracked?
The auditor will expect you to address all three levels of threat intelligence. It should be:
- Relevant & Contextual – tailored to your sector and organisation
- Insightful & Actionable – capable of informing security decisions
The auditor is looking for evidence of a mult-layered approach (one might call it ‘strategic’) to threat intelligence. Although it is not mandatory, we would advise you to write a ‘Threat Intelligence Strategy’ document (in Word) that will outline your approach to this important control.
As before in A5.6 (Contact with Special Interest Groups), you should create a simple spreadsheet which create a simple spreadsheet that allows you to capture strategic, tactical and operational intelligence. You should add where this information comes from and who is the owner of that source of information.
You should also add ‘Threat Intelligence’ to your Management Review Team meeting agenda, to ensure that you are discussing Threat Intelligence in an open forum.
Q & A
Is this a mandatory control?
No control is truly ‘mandatory’, but it would be very difficult to explain why this control is ‘not applicable’ to your organisation.
All organisations face threats, and therefore having an approach to collect and analyse threat intelligence is applicable to you.
Is it possible to get this wrong?
Only if you ignore the control! You can also get it wrong by only focusing on operational threats. You need to consider the three levels of threats. We have also seen people try to collect too much information, which isn’t relevant or contextual for their organisation.
Want to fast track your ISO 27001 journey?
Our “ISO 27001:2022 Policy Pack” gives you everything you need to comply with this, and all ISO 27001 requirements.
We are ISO 27001 Consultants who provide ‘Compliance without Complexity’® and we know we can help you… we even wrote a book about it. For more information on how to implement ISO 27001, written by ISO 27001 consultants like us, you should buy our book..r “Real Easy Guide To ISO27001” book (available on Amazon).
