ISO 27001 A.5.7 — Threat intelligence
A.5.7 is one of the eleven controls added in ISO 27001:2022. It asks you to collect and analyse information about threats so you can act on it — not to buy an expensive intelligence feed.
A.5.7 is one of the eleven controls added in ISO 27001:2022. It asks you to collect and analyse information about threats so you can act on it — not to buy an expensive intelligence feed.
Information relating to information security threats shall be collected and analysed to produce threat intelligence. The standard splits this into strategic (who is targeting your sector and why), tactical (attacker tooling and methods) and operational (specific, actionable indicators) intelligence.
Theme: Organisational · New in ISO 27001:2022
Without threat intelligence your risk assessment is a snapshot of last year's thinking. Auditors look for a feedback loop: intelligence in, risk register updated, controls adjusted. It is also the control that most cheaply demonstrates the continual improvement the standard demands under clause 10.
You do not need a threat intelligence platform. A small business can satisfy A.5.7 with free national sources, your existing security tooling's alerts, and a fifteen-minute monthly review that is minuted and linked to the risk register.
See the full list of all 93 Annex A controls or start from the Statement of Applicability template.
ISO-STANDARD.app ships all 93 Annex A controls pre-loaded, linked to your risks, evidence and owners — with an AI 'Fix this' plan for anything failing.
ISO-STANDARD.app ships a ready-to-adopt ISO 27001 workspace with the risk register, controls catalogue, policies and audit-ready exports already wired together — no spreadsheet sprawl, no consultant lock-in.
Prefer a conversation? Email hello@iso-standard.app — a real human responds within one business day.