A.5.7 Threat intelligence
Collect and analyse threat information and turn it into decisions, not just unread feeds.
12
artefacts
3
held by a system
5
at each review
moderate
to go live
SIEM / log platform
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- Feed ingestion log excerpt from SIEM covering the last quarter · SIEM / log platform
- Risk treatment decision log referencing specific threat intel · SIEM / log platform
- Change request ticket implementing new controls based on intel findings · Ticketing / ITSM
periodic reviewEvidence produced at each review
- Configuration screenshot of automated feed parser · Cloud console / configuration management
- Monthly threat intelligence briefing (PDF) · Document repository
- Board meeting minutes where threat intel influenced strategic choices · Policy repository / GRC workspace
- Attendance record of ISAC sharing sessions for the past six months · SIEM / log platform
- Signed NDAs for intelligence exchange with third‑party organizations · SIEM / log platform
governing documentDocuments that govern the control
- Subscription contract for FeedProvider A · Vendor register / contract repository
- Ad‑hoc analysis report on ransomware trend (Word document) · Document repository
- Threat actor profile document with indicators of compromise · Document repository
- Email distribution list and archive of shared intel to external partners · Policy repository / GRC workspace
First move
Start with the 3 of 12 artefacts that already live in a system (SIEM / log platform); keep the periodic reviews but log each one as a dated record with a named reviewer.
Common gaps auditors find
- Collecting feeds without validation
- No documented process linking intel to decisions
- Reliance on a single source
- Failure to retain analysis artifacts
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetA.5.6 Contact with special interest groups · A.5.8 Information security in project management